Application Security - Web/Mobile API - Assistant Manager
Summary
An Assistant Manager focused on application security for web and mobile APIs, performing annual/ad-hoc source code reviews and security assessments (OWASP/NIST) on internal/external apps, managing security tools, and supporting vulnerability remediation. Ensures hardware/firmware compliance with OEMs and generates security dashboards.
· Source Code Review (SCR). Annually and Adhoc as per requirement.
· Maintenance and management SCR tool and manage the user creation/deletion/dormant user removal.
· Application Security (Web/Mobile). Conduct application security (Appsec) assessment for all in-scope internal and external web, android and iOS applications once annually or when the change in modules/UI has been made (whichever applicable first).
· Maintenance and management Appsec tools and manage the user creation/deletion/dormant user removal.
· Follow up with OEM in case of hardware failure, firmware upgrade, raised ticket, and ensure oem is met
Requirements
Key skills required
· 4-7 years of experience.
· Conduct Appsec on Production Environment.
· Provide external closure report (in PDF) with findings, impact, recommendations and POC’s.
· Assist & Support team for closing the vulnerability (if any)
· External Assessment (Onsite & Offsite) quarterly, monthly rescan should be performed.
· Assessment should be performed based on security standards such as OWASP Top 10, NIST.
· Detailed Management level MIS and Dashboard creation to be captured on fortnight basis.
· Master's or Bachelor’s degree in Cybersecurity, Information Technology, or related field.
· Location: Mumbai