Perform security assessments and code reviews to identify vulnerabilities in applications.
Develop and implement security standards, procedures, and guidelines for application development.
Collaborate with development teams to integrate security tools and best practices into the software development lifecycle (SDLC).
Conduct regular security testing, including penetration testing, to proactively identify and address security weaknesses.
Investigate security incidents, analyze root causes, and recommend corrective actions.
Stay updated with the latest security threats, vulnerabilities, and industry best practices to continuously improve security measures.
Provide technical guidance and mentorship to development teams on secure coding practices and security-related matters.
Participate in the design and architecture review processes to ensure security considerations are integrated from the initial stages of development.
Work closely with cross-functional teams to prioritize and remediate identified security issues.
Contribute to the development and maintenance of security policies, standards, and documentation.
Desired Candidate Profile:
Bachelor s degree in Computer Science, Information Security, or related field.
In-depth knowledge of application security concepts, including OWASP Top 10, secure coding practices, and common attack vectors.
Experience with security testing tools such as Burp Suite, OWASP ZAP, or similar tools.
Strong understanding of software development principles and programming languages (e.g., Java, Python, JavaScript).
Hands-on experience with threat modeling, risk assessment, and security architecture reviews.
Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or related certifications are a plus.
Excellent analytical and problem-solving skills.
Strong communication and collaboration abilities to work effectively across teams.
Ability to thrive in a fast-paced, dynamic environment and manage multiple priorities effectively.