The Job logo

What

Where

Senior Advisor, Cybersecurity Consulting {Product Security Engineer– Web and API}

ApplyJoin for More Updates

You must Sign In before continuing to the company website to apply.

Smart SummaryPowered by Roshi
We are currently seeking a Senior Advisor, Cybersecurity Consulting to join our team. As a Product Security Engineer specializing in Web and API, you will have the opportunity to work with cutting-edge technology and protect millions of users around the world. Your responsibilities will include building strong partnerships, performing security assessments, communicating security risks, researching new technologies, and securing IT applications. We require expertise in penetration testing, API security, threat modeling, and cloud technologies. If you are a customer-focused individual with a growth mindset and a passion for cybersecurity, we would love to hear from you.

RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced attacks; manage user access control; and reduce business risk, fraud and cybercrime. RSA protects millions of users around the world and helps more than 90 percent of the Fortune 500 companies, and every branch of the U.S. federal government, thrive and continuously adapt to transformational change. For more information, go to rsa.com.


Key Responsibilities

• Building strong partnerships with internal teams influencing to incorporate “Security by Design” principle at all levels of software and product lifecycle management.
• Perform security assessment on web applications and services and help application teams solve complex technical problems and design issues.
• Communicates security risks and solutions to business partners and technology teams across the organization.
• Research, design, and advocate new technologies, standards, or methodologies that will strengthen our security posture, reduce our risk exposure, and improve our overall user experience.
• Review and update relevant polices, standards and procedures to raise the maturity of the program.
• Securing IT Applications and third-party SaaS services


Requirements
• Expertise in penetration testing Web, Mobile application (both iOS and Android), API and SaaS application. Expertise in performing Threat Modeling, generating security architectural requirements to software development and product teams.
• In-depth understanding of API security vulnerabilities and proven experience in securing API. Experience in writing proof of concepts, exploits and performing in-depth exploitation is desired.
• Ability to code/ script using any languages like PowerShell/Python/Perl/Ruby is desired.
• Familiarity with advanced threat detection techniques and the ability to detect and respond to high alert attacks effectively.
• Experience in cloud technologies, cloud-native application architecture, 12 factor(SaaS)(SaaS), containers and related technologies preferred.
• Customer focused mindset and is capable of flexing and delivering security solutions to meet the business needs by still achieving the high security standards.
• Growth mindset who is passionate to learn and use new/emerging technologies.
Desired Skills
• 8+ years of experience with various application security tools including SAST, SCA, DAST, Penetration testing, API Security, and fuzzing techniques.
• Conduct in-depth assessments of API to identify potential weaknesses and security flaws that may expose our systems to risks.
• Responsible for assessing risk of vulnerabilities and documenting them with proper proof of concepts, as necessary.
• Work closely with the development team to communicate findings and ensure timely resolution of identified findings.
• Experience working with Cloud and SaaS platform vendors to conduct responsible penetration tests and security scanning
• Understanding of Industry trends in security solutions related to securing and governing APIs.
• A bachelor’s degree in computer science, Engineering, Mathematics, related field, or equivalent experience
• One or More technical security certifications is a plus (examples below – but others are acceptable as well):

  • CISSP – Certified Information Systems Security Professional
  • CCSP – Certified Cloud Security Professional
  • CSSLP – Certified Secure Software Lifecycle Professional
  • CSEC- SANS CIAC Security Essentials
Set alert for similar jobsSenior Advisor, Cybersecurity Consulting {Product Security Engineer– Web and API} role in Bengaluru, India
RSA Logo

Company

RSA

Job Posted

9 months ago

Job Type

Full-time

WorkMode

On-site

Experience Level

8-12 Years

Category

Cyber Security

Locations

Bengaluru, Karnataka, India

Qualification

Bachelor

Applicants

Be an early applicant

Related Jobs

ABB Logo

Product Cyber Security Advisor

ABB

Dundalk, Leinster, Ireland

+1 more

Posted: 9 months ago

Join ABB as a Product Cyber Security Advisor in Dundalk, Ireland or Bengaluru, India. As a cyber security expert, you will be responsible for implementing and ensuring cyber security requirements for industrial applications and products. You will work with development teams, monitor threats, assess security risks, and collaborate with global teams. This is a full-time job opportunity in the on-site mode.

Baker Hughes Logo

Staff Cybersecurity IAM Engineer

Baker Hughes

Bengaluru, Karnataka, India

Posted: a year ago

Staff Cybersecurity IAM Engineer   Do you enjoy creating innovative solutions?   Would you like to take ownership of Identity and Access Management Strategy?   Join our cutting-edge Security team   We operate at the heart of the digital transformation of our business. Our team is responsible for the cyber-security architecture and data protection for our global organization. We focus on ensuring the security and improvement of our Identity and Access Management tools and policies across the business.   Partner with the best   As part of the Baker Hughes Cybersecurity Identity & Access Management team, this individual will contribute to the definition and implementation of the next generation of Identity & Access Management tools and policies across Baker Hughes. This individual will integrate with new and existing initiatives across Baker Hughes to drive the Cybersecurity requirements and policies from design through implementation.   As a Staff Cybersecurity IAM Engineer, you will be responsible for: Designing, implementing, enhancing, and support on-prem and on cloud implementation of Radiant Logic VDS. Acting as a technical expert on initiatives involving directory services with an emphasis on virtual directory services. Supporting leadership strategy by engineering and providing architectural input in IAM domains, including user lifecycle management, provisioning/de-provisioning, and access certification. Leading and influence technical direction for large-scale, highly complex technical initiatives and/or projects requiring integration of cross-functional systems. Coordinating and support major and minor incident response. Researching, implement, and scale innovative solutions. Working with management to define and operationalize Cybersecurity strategy & policies for Identity & Access Management. Identifying and drive the mitigation of existing risks in the Identity & Access management space Developing automation to manage corporate and customer-facing identity applications. Collaborating with Cybersecurity Architects and Engineers to implement new solutions. Responsibilities include rotational, 24/7 on call support.   Fuel your passion To be successful in this role you will: Bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Math). A minimum 9 years of relevant professional experience. 3+ years of experience on implementing and supporting Radiant Logic Virtual Directory Services (VDS) platform. 9+ years of LDAP (Lightweight Directory Access Protocol), Active Directory, other IAM Application, PKI, and DNS experience Experience in IAM integration of AD, webservices, and LDAP based application connectors. Advanced understanding of permission delegation and least-privileged principle. Advanced knowledge of user account provisioning and lifecycle best practices. Troubleshooting IAM products and integrated application issues such as applications connectivity, Password Sync and so on. Use Radiant Logic solution to virtualize, correlate and aggregate user identities from different identity silos into a single source of identities. In-depth understanding of Windows Servers, its Cluster, monitoring and maintaining them. Experience in working and supporting large organization with 70,000 LDAP users. Well-informed with VDS infrastructure governance best practices, user incident/Request, KPI, and KRI Knowledge of Microsoft SQL server and other RDBMS platforms and PowerShell scripting. Experience with cybersecurity frameworks (i.e., NIST, CSA CCM) Knowledge of identity data flows, security roles, certification/attestation, entitlement management, and access governance Experience with directory services, active directory, azure ad, relational database schema, LDAP schema