Premium Employer

i

This company page is being actively managed by BCG Team. If you also belong to the team, you can get access from here

BCG Verified Tick

Compare button icon Compare button icon Compare
3.8

based on 370 Reviews

filter salaries All Filters

61 BCG Jobs

Application Security Senior Manager

7-10 years

Gurgaon / Gurugram

1 vacancy

Application Security Senior Manager

BCG

posted 7hr ago

Job Description

Who We Are

Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact.

To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive.



What Youll Do

As the Senior Manager of Application Security, you will oversee all aspects of information security within the application development lifecycle. This role involves close collaboration with product and application teams to ensure that applications adhere to BCG security standards and incorporate robust, secure design and development practices. You will be actively involved in secure engineering, secure product design, and the use of application security tools, engaging with security champions across various levels of maturity.

Your responsibilities will also include developing and expanding the Application Security Assurance program. This involves scaling the program, integrating new application development teams, and enhancing the security of previously onboarded applications. Key focus areas will include managing application security testing tools (both commercial and open source), addressing vulnerabilities, refining scan policies and coverage, adopting new security tools as needed, and embedding these tools into the DevSecOps pipeline.

Following are key responsibilities for this role:

Serve as a subject matter expert in Application Assurance within Agile and DevSecOps environments, evolving application security processes in line with BCG security standards and industry best practices.

Conduct code reviews and automated static and dynamic security assessments of applications.

Promote the principle of "Secure By Design baked into CI/CD by automating test scenarios using both commercial and open-source tools, and enable development teams through a self-service model of security tooling and processes.

Lead the Security Champions network, disseminate relevant application security information to keep the network motivated and informed, and ensure balanced representation across all product and application teams.

Enhance Security Champions maturity by guiding them toward and facilitating adherence to the maturity model.

Collaborate with Security Champions to develop necessary templates, address issues, and manage artifacts.

Manage and enhance static, dynamic, and interactive application security testing tools; assist developers and architects in remediating security defects by providing coding guidance and remediation consultation.

Oversee, expand, and refine the Application Assurance program to integrate security and privacy from sprint zero, and implement the program across BCG.

Enable development teams to integrate security throughout the SDLC stages-planning, designing, development, and testing-and proactively engage with them on security best practices.

Coordinate with application developers, Security Champions, architects, and project managers to improve application security posture and achieve standard security conformance across the enterprise.

Support development teams in creating security unit and smoke test cases based on an applications threat model.



What Youll Bring

The desired candidate will have application security background with sound application development knowledge such as how developers work, what tools and technologies they use, and how they collaborate. Following are key skills for this role:

  • Proficiency in secure coding practices with expert-level knowledge of security defects, particularly those related to the OWASP TOP 10 and SANS 25, and the ability to fix defects at the code level.
  • Understanding of AI-generated code implications for security with the ability to assess and address security risks associated with AI-generated code, including identifying potential vulnerabilities that may not be evident through traditional code analysis methods.
  • Integration of security practices in AI code generation processes ensuring proficiency in integrating security measures into the AI code generation lifecycle to maintain adherence to secure coding standards and practices.
  • Strong automation mindset, capable of integrating security tools and processes into the DevSecOps cycle, including creating security requirements and value stream mapping to specific DevSecOps stages/tasks.
  • Proficient in AWS cloud security governance, Docker, Kubernetes, and the integration of security tooling into DevOps environments.
  • In-depth understanding of security within CI/CD processes, as well as security external to CI/CD.
  • Familiarity with Web Application and API Protection (WAAP) tooling, focusing on providing guidance to ensure effective security measures for web applications and APIs.
  • Expert-level capability in performing automated code and application scanning using both commercial and open-source tools across various frameworks and platforms, clearly understanding their advantages, challenges, and limitations.
  • Ability to write automation programs, preferably in platform-independent languages, to integrate security tools according to the security value stream or to write security tests within CI/CD pipelines.
  • Experience in evaluating, deploying, and managing best-in-class commercial and open-source application security testing tools at an enterprise scale.
  • Security source code review skills across multiple languages and frameworks (JavaScript, Java, .NET, Node.js, Angular, technologies supporting SPA), and the ability to advise teams on secure coding guidelines.


Who Youll Work With

You will work in a fast-paced, intellectually intense, service-oriented environment to protect our applications and information systems. You will be a part of a team of security architects, enterprise architects, and security professionals working in support of consultants delivering business and management strategy to our clients through these applications and systems. You will work with application developers, data analysts, and system owners providing information security for applications and systems.



Additional info

YOU RE GOOD AT

This role will serve various teams and functions at the enterprise level, overseeing teams responsible for developing applications and products, with Information Security Risk Management (ISRM) as a major stakeholder. This position will be intensive in terms of change and communication, requiring both short-term and long-term engagement with business and technology owners across BCG. The following key attributes will help you succeed in this job:

  • Strong belief in application security as a means to enhance product speed to market.
  • Ability to articulate complex security topics in both business and plain language.
  • Persuasive skills and the ability to negotiate in support of the program.
  • Strong reasoning and analytical abilities, capable of creating mental visuals and comfortable handling ambiguity.
  • A proactive attitude in removing roadblocks and enabling teams to achieve their objectives
  • Providing guidance and mentorship to team members, fostering a culture of continuous learning and growth in application security practices.


Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws.
BCG is an E - Verify Employer. Click here for more information on E-Verify.

",

Employment Type: Full Time, Permanent

Read full job description

Prepare for Senior Manager roles with real interview advice

What people at BCG are saying

4.3
 Rating based on 6 Senior Manager reviews

Likes

Best in class perks

  • Salary - Excellent
  • +4 more
Dislikes

Bonuses and work profile

  • Promotions - Poor
  • +1 more
Read 6 Senior Manager reviews

Senior Manager salary at BCG

reported by 58 employees with 10-18 years exp.
₹22.4 L/yr - ₹71.6 L/yr
103% more than the average Senior Manager Salary in India
View more details

What BCG employees are saying about work life

based on 370 employees
75%
93%
45%
89%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

BCG Benefits

Free Food
Team Outings
Cafeteria
Health Insurance
Work From Home
Soft Skill Training +6 more
View more benefits

Compare BCG with

McKinsey & Company

3.9
Compare

PwC

3.4
Compare

Bain & Company

3.8
Compare

Deloitte

3.8
Compare

KPMG India

3.5
Compare

Accenture

3.9
Compare

Ernst & Young

3.4
Compare

IBM

4.0
Compare

Capgemini

3.7
Compare

Infosys

3.6
Compare

ZS

3.4
Compare

Mercer

3.7
Compare

Citco

3.1
Compare

Willis Towers Watson

3.8
Compare

Guidehouse

3.8
Compare

WSP

4.3
Compare

Mott MacDonald

4.2
Compare

Nexdigm

3.6
Compare

Gartner

4.2
Compare

Blackrock

3.8
Compare

Similar Jobs for you

Security Engineer at Boston Consulting Group

Gurgaon / Gurugram

7-8 Yrs

₹ 13-15 LPA

Software Python Engineer at Trimble

Chennai

8-13 Yrs

₹ 25-30 LPA

Software Python Engineer at Applanix

Chennai

8-15 Yrs

₹ 25-30 LPA

Security Engineer at Barco Electronic System Pvt Ltd

Noida

5-10 Yrs

₹ 20-35 LPA

Mobile App Developer at UST

Bangalore / Bengaluru

7-9 Yrs

₹ 11-18 LPA

Cyber Security at RSM DELIVERY CENTER (INDIA) PRIVATE LIMITED

Hyderabad / Secunderabad, Gurgaon / Gurugram + 1

8-13 Yrs

₹ 25-40 LPA

Lead QA at Refinitiv

Bangalore / Bengaluru

9-12 Yrs

₹ 12-15 LPA

Applications Engineer at Transco A Marmon Rail Company

Hubli, Mangaluru + 3

6-8 Yrs

₹ 15-20 LPA

Senior Security Manager at CASHFREE HOLIDAY PLANNERS

Bangalore / Bengaluru

7-15 Yrs

₹ 9-17 LPA

Product Security Engineer at Atlassian

Remote

10-15 Yrs

₹ 20-27.5 LPA

BCG Gurgaon / Gurugram Office Location

View all
Gurgaon Office
The Boston Consulting Group, 19th Floor, Tower C, Building No 10, DLF Cyber City, Phase-II Gurgaon
Haryana 122002

Application Security Senior Manager

7-10 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

HR Shared Services Senior Manager

15-22 Yrs

Gurgaon / Gurugram, Delhi/Ncr

1d ago·via naukri.com

Global Security Engineer

7-8 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Global Data Analyst Manager

6-8 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Global Data Scientist Manager

5-9 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Principal Architect, Banking & Insurance, Platinion

15-17 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Global IT Solution Architect Manager

12-13 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Global IT Endpoint Engineer Manager

9-12 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

Global UX Designer Senior Specialist

3-6 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com

ERP, Principal Architect, Platinion

15-17 Yrs

Gurgaon / Gurugram

1d ago·via naukri.com
write
Share an Interview