More jobs:
Job Description & How to Apply Below
Key Responsibilities & Core Scope
Web & Mobile Application Security (App Sec)
Web Application Security:
Conduct comprehensive manual and automated vulnerability assessments (VAPT) across web platforms and microservice APIs based on OWASP Top 10 and OWASP API Security Top 10.
Mobile Application Security (iOS & Android):
Perform static and dynamic security assessments aligned with OWASP Mobile Application Security (MASVS) — auditing secure data storage, certificate pinning, biometric authentication, deep linking, reverse-engineering resistance, and third-party SDK security.
Secure SDLC & Dev Sec Ops Automation:
Integrate, tune, and scale SAST, DAST, and SCA tools (e.g., Semgrep, Checkmarx, Veracode, Snyk, Sonar Qube, OWASP ZAP, Burp Suite) inside Git Hub Actions / Git Lab CI pipelines with minimal developer friction.
Threat Modeling:
Lead collaborative threat modeling sessions (STRIDE / MITRE ATT&CK) with developers and architects during sprint planning and architectural design phases.
Vulnerability Remediation:
Work directly with product engineering teams to provide code-level remediation guidance, root-cause analysis, and verification testing.
AWS Security Hardening:
Architect and maintain hardened AWS multi-account structures (AWS Organizations, Control Tower, SCPs) aligned with CIS AWS Foundations Benchmarks.
IAM & Secrets Management:
Design least-privilege IAM policies, role-based access controls, automated credential rotation, and secure key management via AWS KMS and Secrets Manager.
Container & Kubernetes Security:
Enforce runtime protection, image scanning, and network policies for Docker containers and Kubernetes (EKS/ECS) workloads.
Infrastructure as Code (IaC) Security:
Automate Terraform security auditing using tools such as Checkov, tfsec, and Trivy before deployments hit production.
Perimeter Defense & WAF Customization
AWS WAF Engineering:
Architect, deploy, and fine-tune AWS WAF and Amazon Cloud Front security configurations across all edge endpoints.
Custom Rule Development:
Write custom regex rules, rate-limiting policies, IP set filtering, and bot control rules to mitigate Layer 7 DDoS, credential stuffing, scraping, and zero-day vulnerabilities.
Security Observability Platforms:
Monitor security telemetry across platforms such as Elastic/Open Search, AWS Cloud Watch, or Coralogix.
Threat Detection & Alerting:
Aggregate and correlate security logs (VPC Flow Logs, Cloud Trail, ALB logs, WAF logs, Guard Duty findings) to build high-fidelity detection rules and actionable alert dashboards.
Incident Response Support:
Assist in triaging security events, performing log forensics, and automating alert escalations to reduce Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR).
Compliance Alignment:
Provide technical evidence and enforce controls for SOC 2 Type II, ISO 27001, and CIS Benchmarks.
Tooling & Cost Efficiency:
Optimize security tool utilization, eliminate redundancy, and identify cloud architecture cost savings.
Mandatory Qualifications (Must-Haves):
Experience:
6–9 years in Application Security, Cloud Security, and Dev Sec Ops .
App Sec Mastery:
In-depth knowledge of Web & Mobile (Android/iOS) security testing, API penetration testing, and secure code review.
AW…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×