Your browser does not support javascript! Please enable it, otherwise web will not work for you.

Sr. Security Engineer-Application Security @ Flipkart

Home > IT Security

 Sr. Security Engineer-Application Security

Job Description

Senior Security Engineer


The role of the Application Security Analyst is to perform activities related to security and privacy by design in the application developed by Flipkart and integrate security controls throughout the SDLC life cycle. The engineer is responsible for establishing, implementing, monitoring, reviewing, and improving a suitable set of controls for the prevention of threats to the security of Myntras applications and information assets, ensuring the business objectives of the organization.


NOTE - CODING/SCRIPTING EXPERIENCE IS NECESSARY


Responsibilities and Scope:

The candidate should have 6 of experience in web application and mobile application security vulnerability assessment and penetration testing

Perform Static, Dynamic security testing (SAST and DAST) including penetration testing for thin & thick client-based applications

Exploit security flaws and vulnerabilities with attack simulations on multiple applications in the Android and IOS platforms

Develop PoC/exploits for vulnerabilities identified

Provide remediation guidance to identified vulnerabilities

Manual and automated security testing of Web applications, APIs, and mobile Apps

Use automated and manual code review techniques to identify application security vulnerabilities

Perform software applications reviews for potential security vulnerabilities by conducting application security reviews

Perform requirements review, design review, code review, and perform code review across multiple programming languages

Identify complex vulnerabilities such as business logic flaws and articulate to both technical and non-technical partners

Document vulnerabilities and work on vulnerability mitigation analyze application security policies for effectiveness, make suggestions on security policy improvements, and work to enhance methodology material

Develop and maintain security testing plans and automate penetration and other security testing on the application, systems, networks, and data layers

Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make decisions based on risk

Produce actionable, threat-based, reports on security testing results

Build and maintain relationships with key stakeholders and business partners Must-Have:

The candidate should be a team player with good interpersonal skills and should be able to work independently with minimum supervision in a complex Infrastructure environment Ability to clearly communicate needs and requirements and influence stakeholders with minimal supervision

Ability to accurately estimate effort, set and meet deadlines

Development experience in one or more of the technologies; Node/JavaScript, Java, Python, PHP

Experience in research and development in - red team exercises, threat hunting, OSINT, Threat Modeling and building security tools

Good understanding in DevSecOps, security architecture review and network security assessments

Good experience in developing and/or maintaining multi-tier applications and hands-on development using Java / J2EE or .NET Technologies or any Web.

Good understanding of any application web servers. Well versed with OWASP standards. Unix / Linux / Debian

Hands-on experience with technology and to contribute to the design, development, and support of projects with the security recommendations


Nice to Have:

Good problem-solving skills. good communications and documentation skills

Ability to anticipate needs and provide creative input that ensures the success of the broader team

Aptitude for learning software vulnerabilities, exploits, countermeasures, and operational monitoring

Proficient in reading modern programming languages with the ability to quickly learn to read and interpret scripts written by others


Job Classification

Industry: Internet (E-Commerce)
Functional Area:
Role Category: IT Security
Role: IT Security
Employement Type: Full time

Education

Under Graduation: B.Tech/B.E. in Any Specialization
Post Graduation: Any Postgraduate

Contact Details:

Company: Flipkart
Location(s): Bengaluru

+ View Contactajax loader


Keyskills:   PENETRATION TESTING CODING WEB APPLICATION SCRIPTIN MOBILE APPLICATION

 Job seems aged, it may have been expired!
 Fraud Alert to job seekers!

₹ -18 Lacs P.A

Similar positions

Associate Architect - Security Testing - Pune

  • Icertis
  • 9 - 14 years
  • Pune
  • 1 month ago
₹ 4-9 Lacs P.A.

Cybersecurity Advisor - Senior - Pune

  • Cummins
  • 5 - 10 years
  • Pune
  • 1 month ago
₹ 16-20 Lacs P.A.

Cyber Security Lead - Hyderabad / Secunderabad

  • Capgemini
  • 14 - 18 years
  • Hyderabad
  • 1 month ago
₹ Not Disclosed

Security Architect - Chennai - Accenture - 2

  • Accenture
  • 2 - 4 years
  • Chennai
  • 1 month ago
₹ Not Disclosed

Flipkart

Flipkart Flipkart Internet Private Limited