Cutshort logo
OWASP Jobs in Bangalore (Bengaluru)

7+ OWASP Jobs in Bangalore (Bengaluru) | OWASP Job openings in Bangalore (Bengaluru)

Apply to 7+ OWASP Jobs in Bangalore (Bengaluru) on CutShort.io. Explore the latest OWASP Job opportunities across top companies like Google, Amazon & Adobe.

icon
Hashone Careers

at Hashone Careers

2 candid answers
Madhavan I
Posted by Madhavan I
Bengaluru (Bangalore), Pune
5 - 8 yrs
₹12L - ₹20L / yr
OWASP
SANS
DevOps

Job Description:

Experience - 5 to 8 years

Role - Senior consultant

Work mode - Hybrid (3 days WFO)

Location - Bangalore / Pune


JOB DESCRIPTION :

Application Security Specialists are instrumental in fortifying the security framework that underpins the software delivery processes of our clients. These experts thrive in collaborative settings, engaging with diverse teams across various disciplines to pinpoint and mitigate vulnerabilities in code, systems architecture, and infrastructure. With a profound technical acumen rooted in security practices and a keen understanding of agile methodologies, they advocate for security integration as a fundamental aspect of software development. Their work transcends mere compliance; it is about embedding a culture of security that aligns with agile and DevOps philosophies, ensuring that security measures enhance, rather than hinder, organizational objectives. By guiding teams and clients through the nuances of security

Automation and best practices, Application Security Specialists not only safeguard digital assets but also champion a mindset where security and development go hand in hand towards achieving superior outcomes.


Job Responsibilities:

As an Application Security Specialist , you will play a crucial role in enhancing our software delivery process's security posture.

Embed security throughout the software delivery lifecycle, ensuring secure application development from start to finish.

Build and define comprehensive security practices tailored to our delivery methodologies.

Automate and optimize security measures in line with the application lifecycle, ensuring efficient and effective security protocols.

Serve as a consultant and advisor to both the delivery team and clients, providing expert guidance on security best practices and risk mitigation strategies.

Work closely with delivery, DevOps and Cloud teams to identify and reduce risks associated with code development, system architecture, and infrastructure.


Job Qualifications:

Preferred to have BFSI experience

Experience as a security engineer with direct involvement in working with delivery teams to identify vulnerabilities in code and systems architecture.

Demonstrated experience with implementing security automation and familiarity with agile development methodologies.

Ability to collaborate effectively with software product delivery teams, speaking their language and working towards common goals.


Technical Skills:

In-depth knowledge and experience with OWASP and SANS standards.

Proficiency in manual and automated penetration testing tools and techniques.

Experience with SAST, DAST, Dependency checking, and container vulnerability

assessment tools such as Checkmarx, Burp, ZAP, Fortify, Trivy, etc.

Knowledge and experience in password/secret management tools and techniques.

Understanding of DevSecOps and experience in security automation.

Comprehensive understanding of web technologies, common web frameworks, their vulnerabilities, and mitigations.

Basic understanding of firewall, virtualization, container, networking, and OS security.

Knowledge of cloud security best practices and basic knowledge of cloud providers like AWS, Azure and GCP.


Professional Skills:

Excellent communication and interpersonal skills, with the ability to manage relationships at senior levels of leadership.

Strong consulting skills, including the ability to promote security awareness and influence

decision-making.

Ability to anticipate problems and understand the long-term implications of decisions and

actions. Experience in developing security testing plans and integrating them into the software development lifecycle.


Preferred Skills:

Experience with manual and automated security code review.

Basic knowledge of security policies and standards such as PCI-DSS, ISO 27001 (ISMS), and GDPR.

Read more
Mphasis
Agency job
via VY SYSTEMS PRIVATE LIMITED by Renuga Renu
Bengaluru (Bangalore), Hyderabad, Pune
5 - 10 yrs
₹10L - ₹27L / yr
Cyber Security
Cloud Computing
Artificial Intelligence (AI)
skill iconMachine Learning (ML)
sonarqube
+6 more

 

3+ years of experience in cybersecurity, with a focus on application and cloud security.

· Proficiency in security tools such as Burp Suite, Metasploit, Nessus, OWASP ZAP, and SonarQube.

· Familiarity with data privacy regulations (GDPR, CCPA) and best practices.

· Basic knowledge of AI/ML security frameworks and tools.

Read more
HappyFox

at HappyFox

1 video
6 products
Lindsey A
Posted by Lindsey A
Chennai, Bengaluru (Bangalore)
5 - 12 yrs
₹10L - ₹15L / yr
IT security
Network Security
OWASP
Threat modeling
Exploratory testing
+4 more

About us:

HappyFox is a software-as-a-service (SaaS) support platform. We offer an enterprise-grade help desk ticketing system and intuitively designed live chat software.

 

We serve over 12,000 companies in 70+ countries. HappyFox is used by companies that span across education, media, e-commerce, retail, information technology, manufacturing, non-profit, government and many other verticals that have an internal or external support function.

 

To know more, Visit! - https://www.happyfox.com/

 

Responsibilities:

  • Perform manual and automated application penetration tests and provide suggestions to harden our products
  • Participate regularly in the development and release process to identify and report security vulnerabilities in the code being shipped
  • Conduct regular audits on all Features/APIs of the product and reports vulnerabilities to the development team
  • Keep up with industry trends in the security space
  • Triage inbound vulnerability reports with an appropriate level of urgency and track them until they are resolved by Engineering teams
  • Should be able to understand different elements of our NodeJS, Python and similar stacks and provide guidance on secure software development practices to the team
  • Scale our application security engineering team

 

Requirements:

  • Strong verbal and written communication skills
  • Has worked on Web Application Security Testing for a reasonably complex application. The mobile experience is a plus
  • Good knowledge of secure software development guidelines from authoritative bodies like NIST, OWASP, SANS
  • Hands-on experience in performing manual/automated security assessments with open-source/commercial security tools

 

Read more
Top IT MNC

Top IT MNC

Agency job
Chennai, Mumbai, Bengaluru (Bangalore), Pune, Coimbatore, Kochi (Cochin), Navi Mumbai, Gurugram, Noida, Kolkata, Delhi, Ghaziabad, Faridabad
6 - 15 yrs
₹10L - ₹25L / yr
OWASP
Web application security
Network Security
Nessus
Burp suite
+6 more
Experience: 6-8 years & 10+ years
  • OWASP Secure Code review,• Basic programing knowledge in any programming language and knowledge on secure development practices.
  • OWASP TOP 10 vulnerabilities and their mitigations
  • Hands on experience in Web Application Security Testing tools (SAST & DAST) and Penetration testing tools such as HP Fortify, Checkmarx, Acunetix, Nessus, Burp Suite, Metasploit., Qualys Guard, Kali Linux , etc.
  • Understand/modify exploit code and find logical security flaws in applications
  • Should have knowledge and experience on Network Security, Application Security, Internet Security, attack vectors.
  • To carry out technical vulnerability assessments, identify potential vulnerabilities and provide recommended controls and support to mitigate them.
Read more
An American digital consulting company

An American digital consulting company

Agency job
via Jobdost by Sathish Kumar
Noida, Gurugram, Bengaluru (Bangalore)
1 - 6 yrs
₹1L - ₹13L / yr
skill iconJava
skill iconAmazon Web Services (AWS)
OWASP
CI/CD
skill iconNodeJS (Node.js)
+6 more

Your Impact:

•                 Implements Digital Consumer experiences based on a foundation of SFCC (Salesforce commerce cloud) to meet expected quality standards

•                 Ensures functional requirements and high-level solution designs are understood and are translated into detailed technical design

•                 Implement proofs of concept to prove any new technologies, application flows or integration scenarios and identify customizations needed to SFCC platform for meeting client requirements

•                 Guides the performance tuning and scalability of the ecommerce solution

•                 Diagnose and solve technical problems during implementation and support phases

 

Your Skills & Experience:

•                 4-8 Years with 2+ years of implementing commerce application on any eCommerce platform in last 3 years

•                 If you have not worked in eCommerce platform, we can still discuss with you if you are expert in Java/.Net and understand REST/SOAP webservices.

•                 Demonstrate proficiency in build and release management using CI/CD strategies (leveraging tools like Jenkins and DevOps practices), implement Mocha/Chai unit and functional test cases in order to reduce costs while ensuring quality

•                 Contributes to designing, implementing and documenting the build release process as well as system configuration and deployment characteristics of the applications

•                 Participates in technical walkthroughs/ code reviews of other team members’ components, test plans and results and help them with gaps

•                 Collaborate with architect to define implementation processes and quality gates and standards

•                 Identifies risks and issues, and help monitor them

•                 Guides the development of reference and resource materials

•                 Mentors developers in improving their platform knowledge and development skills

•                 Communicate technical design to the developers and help/guide them in the implementation

•                 Participates in Agile sprints

 

 

Set Yourself Apart With:

•                 eCommerce platform certification

•                 Security considerations – OWASP, CSRF, reCAPTCHA etc. – Basic knowledge or experience

•                 Git Development workflow – Proficient

•                 Visual Studio Code IDE or Eclipse IDE - Proficient

•                 Knowledge on Agile methodology and desired tools like Jira, confluence etc.

•                 Scripting/development experience with Node.js, Mocha/Chai

•                 Experience working in any Salesforce cloud environment like SFMC, SFSC etc.

•                 Excellent written, verbal communication and articulation skills & Good team player

•                 Self-starter and self-learner with keen interest to grow

•                 Process orientation and the ability to define and setup processes

•                 Ability to provide necessary coaching to bring team members up to speed on the technology

•                 Ability to prioritize and manage multiple tasks

•                 Excellent and innovative approach to problem solving and finding solutions

•                 Flexible and proactive/self-motivated working style with excellent personal ownership of problem resolution

Read more
AMBC Technologies Pvt Ltd
Ponmuthumari Mohan
Posted by Ponmuthumari Mohan
Bengaluru (Bangalore)
3 - 9 yrs
₹8L - ₹12L / yr
Web application security
oscp
vapt
Fortify
OWASP

Requirements:

  • Overall experience in the field of Information risk and security related initiatives/ projects.
  • Experience in the areas of Infrastructure Security Audit, IT Security, Vulnerability Assessment, Risk Assessment, Web Application Security, Network Security Review, Network Architecture Review, Mobile Application Security Testing, Configuration Review, Source Code Review, Wireless Pentest, Process Review etc.
  • Ability to understand business concepts and integrate business risk elements into security operations.
  • Experience in conducting VAPT.
  • Experience with web application vulnerability scanning tools (e.g., IBM AppScan, HP Web inspect, Acunetix, NTO Spider, BurpSuite Pro).
  • Strong ethics and understanding of ethics in business and information security.
  • Should have exposure to Code review, Network VA/PT and App VA/PT work.
  • Understanding and familiarity with common code review methods and standards.
  • Experience with code scanning toolsets such as Fortify and Ounce.
  • Understanding of HTTP and web programming.
  • Knowledge of OWASP tools and methodologies, common security requirements within ASP.NET application, standard SDLC practices.
  • Knowledge of Network Security technology in areas of Firewall, IPS, VPN, Gateway security solutions (proxy, web filtering).
  • In-depth understanding on Common Vulnerability Exposure (CVE)/ Cert advisory database.
Read more
Swiggy

at Swiggy

1 video
13 recruiters
Suresh Kaushik
Posted by Suresh Kaushik
Bengaluru (Bangalore)
3 - 12 yrs
₹25L - ₹60L / yr
Network Security
Penetration testing
skill iconProgramming
Security architecture
Computer Security
+2 more
Job Description Roles and Responsibilities: • Exploit security flaws and vulnerabilities with attack simulations on multiple application platforms like Android, iOS and Web. • Ability to flow from black box to grey box to white box tests. • Ability to effectively work with the engineering teams to provide technical risk. assessment of technologies in networks, applications, code reviews in the release management cycle. • Ability to perform vulnerability assessments and penetration testing, utilizing tools - commercial and open source. • Perform, review and analyze security vulnerability data to identify applicability and false-positives. • Conduct penetration testing in line with Open Web Application Security Project (OWASP) • Write technical reports that include suggested resolution for identified problem areas and perform operational risk assessment. Required Skills and Abilities: • OWASP top 10 • Security Pen Testing methodologies including automated scans and manual methods • Tools including Burp, Nexpose, NMap, Whois etc. is a plus • Good Hands-On with Linux Debian Flavors and security hardening of the same • Understanding of Web Servers and HTTP 1.0/1.1 Protocol • Troubleshooting web servers like Apache, Nginx and other reverse proxy platforms • Basic understanding of NodeJS, Python and JAVA • TCP/IP networking including IP classes, subnets, NAT • SSL Handshake and Certificates - Understanding • DNS, and DHCP, Network troubleshooting • Remote access methods • Backup and disaster recovery methodologies • Network analysis tools • Good Hands-on using Linux Debian Flavors • Experience with security issues in Cloud Technologies (AWS) is a plus • Ability to grasp new technology concepts quickly • Good documentation skills • Ability to work in a team environment and interact with people • Knowledge and understanding of basic information security principles • Should be aware of the latest Major Application Zero-day vulnerabilities • Should be able to understand security alerts and take necessary actions accordingly Education and Experience: • Bachelor’s degree in information technology related field
Read more
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Why apply via Cutshort?
Connect with actual hiring teams and get their fast response. No spam.
Find more jobs
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort