Expoint - all jobs in one place

המקום בו המומחים והחברות הטובות ביותר נפגשים

Limitless High-tech career opportunities - Expoint

Citi Group Senior Application Security Analyst VP 
India, Maharashtra, Pune 
498923357

Yesterday

Responsibilities:

  • Perform Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).
  • Review and validate automated testing results and prioritize actions that resolve issues based on overall risk. Perform application binary analysis when source code is not available.
  • Identify opportunities to automate, develop custom rules and standardize information security controls. Participate in conference calls with engineering team to ensure proper scan coverage and effective results.
  • Write formal security assessment report for each application, using our company's standard reporting format.
  • Direct the development and delivery of secure solutions by coordinating with business and technical teams. Collaborate with application teams to ensure that any identified security vulnerabilities are remediated in a timely manner.
  • Manage and execute security assessments for multiple projects simultaneously and ensure project timelines are met.
  • Research and explore new testing tools and methodologies. Act as a mentor to the junior team members.
  • Appropriately assess risk when business decisions are made, demonstrating particular consideration for the firm's reputation and safeguarding Citigroup, its clients and assets, by driving compliance with applicable laws, rules and regulations, adhering to Policy, applying sound ethical judgment regarding personal behavior, conduct and business practices, and escalating, managing and reporting control issues with transparency.

Qualifications:

  • At least 7 years of relevant experience in web development, source code review, or application security testing.
  • Basic understanding of application security and associated vulnerabilities.
  • Development background in Java/J2EE, C#, .NET in an enterprise environment.
  • Good understanding of the DevSecOps, Pipeline, Software Development Life Cycle – including unit testing, code scanning.
  • Experience using commercial enterprise automated security testing tools such as Burp, Fortify, Checkmarx, Blackduck, Snyk.
  • Professional certifications, such as CISSP, CSSLP, GIAC, CEH or willingness to obtain.

Education:

  • At least Bachelor’s degree/University degree or equivalent experience

This job description provides a high-level review of the types of work performed. Other job-related duties may be assigned as required.

Information Security


Time Type:

Full time

View the " " poster. View the .

View the .

View the