Open Source Technology Application Security Specialist - Vulnerability Management
BYLD Group
Date: 13 hours ago
City: Kolkāta, West Bengal
Contract type: Full time
Description
Job Title : Open Source Technology Application Security Specialist
Location : Kolkata , Bangalore
Position Overview
We are seeking a highly skilled Application Security Specialist with strong expertise in open-source technologies and modern web development frameworks such as React, Node.js, Python, and Angular. The ideal candidate will have a deep understanding of application-level vulnerabilities, secure coding practices, and penetration testing methodologies.
You will be responsible for identifying, mitigating, and preventing security risks across our front-end and back- end applications, ensuring that robust security controls are embedded throughout the Software Development
Lifecycle (SDLC). The successful candidate will collaborate closely with engineering, DevOps, and infrastructure
teams to strengthen the overall security posture of applications hosted across cloud and on-premise environments.
You will be responsible for identifying, mitigating, and preventing security risks across our cloud and applications while collaborating closely with development and infrastructure teams. The successful candidate will be responsible for implementing robust security practices throughout the application development lifecycle, conducting vulnerability assessments, and performing penetration testing to safeguard our applications built on diverse technological stacks, including .NET, ASP.NET, IIS, Windows OS etc.
Key Responsibilities
Secure Coding Governance :
Web Application Firewalls (WAF) And Cloud Security
Technical Proficiency :
Job Title : Open Source Technology Application Security Specialist
Location : Kolkata , Bangalore
Position Overview
We are seeking a highly skilled Application Security Specialist with strong expertise in open-source technologies and modern web development frameworks such as React, Node.js, Python, and Angular. The ideal candidate will have a deep understanding of application-level vulnerabilities, secure coding practices, and penetration testing methodologies.
You will be responsible for identifying, mitigating, and preventing security risks across our front-end and back- end applications, ensuring that robust security controls are embedded throughout the Software Development
Lifecycle (SDLC). The successful candidate will collaborate closely with engineering, DevOps, and infrastructure
teams to strengthen the overall security posture of applications hosted across cloud and on-premise environments.
You will be responsible for identifying, mitigating, and preventing security risks across our cloud and applications while collaborating closely with development and infrastructure teams. The successful candidate will be responsible for implementing robust security practices throughout the application development lifecycle, conducting vulnerability assessments, and performing penetration testing to safeguard our applications built on diverse technological stacks, including .NET, ASP.NET, IIS, Windows OS etc.
Key Responsibilities
Secure Coding Governance :
- Establish, enforce, and monitor secure coding standards across all open-source technology stacks (React, Node.js, Python, Angular, etc.) to minimize application security risks.
- Identify, analyze, and remediate security vulnerabilities within codebases, APIs, and cloud applications. Focus areas include injection attacks, cross-site scripting (XSS), insecure deserialization, and related OWASP Top 10 issues.
- Plan and execute penetration tests and dynamic security assessments to uncover application weaknesses and
Web Application Firewalls (WAF) And Cloud Security
- Configure, tune, and monitor WAFs, API gateways, and cloud-native security tools (AWS/Azure/GCP) to protect open-source applications and services.
- Provide technical guidance on secure design and implementation for open-source frameworks and tools.
- Leverage expertise in React, Node.js, Python, Angular, and related libraries to support secure architecture decisions.
- Work closely with product engineering, QA, and operations teams to embed security best practices across all stages of development. Conduct developer training and knowledge sessions to strengthen security awareness.
- Perform threat modeling and design reviews for new and existing applications.
- Develop and automate security validation tools and scripts to identify vulnerabilities early in the SDLC.
- Monitor and respond to application-level security incidents and provide root-cause analysis.
- Continuously research emerging security threats, tools, and frameworks relevant to open-source ecosystems.
- Monitor, investigate, and respond to security incidents and intrusion attempts. Stay abreast of the latest security threats, trends, and technologies, and continuously improve security policies, tools, processes frameworks, and compliance standards. Support and mentor developers on secure design and architecture. Stay abreast of the latest security threats, trends, and technologies, and continuously improve security policies, tools, and processes.
Technical Proficiency :
- Strong hands-on experience in React, Node.js, Python, Angular, and related open-source technologies.
- Solid understanding of RESTful APIs, OAuth2/OpenID Connect, JWT, and microservices architectures.
- Comprehensive understanding of application security principles, OWASP Top 10, and secure SDLC methodologies.
- Experience performing static and dynamic code analysis (SAST/DAST) and API security testing.
- Proficient in open-source and commercial security tools such as Burp Suite, OWASP ZAP, SonarQube, Checkmarx, or similar vulnerability scanners.
- Strong analytical and problem-solving skills to assess complex application security issues and implement effective mitigation strategies.
- Excellent interpersonal and communication skills with the ability to collaborate effectively with engineering teams and key stakeholders.
- Security certifications such as OSCP, CEH, CSSLP, GIAC GWAPT, or equivalent.
- Experience in Agile and DevSecOps environments.
- Familiarity with container security (Docker, Kubernetes) and cloud-native security practices (AWS/GCP/Azure).
- Experience integrating security automation in CI/CD pipelines.
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
FS-RC-BT INS-Life and Annuity
EY,
Kolkāta, West Bengal
3 days ago
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working...
Advisory - Deals - Forensic - Associate 2 - Kolkata
PwC Acceleration Center India,
Kolkāta, West Bengal
4 days ago
At PwC, our people in deals focus on providing strategic advice and support to clients in areas such as mergers and acquisitions, divestitures, and restructuring. They help clients navigate complex transactions and maximise value in their business deals. Those in deal integration and valuation realisation at PwC will focus on assisting clients in successfully integrating acquisitions and maximising the value...
Associate-SAP ABAP-RDC-Kolkata
PwC India,
Kolkāta, West Bengal
1 week ago
Line of ServiceAdvisoryIndustry/SectorNot ApplicableSpecialismOperationsManagement LevelAssociateJob Description & SummaryA career within SAP Consulting services, will provide you with the opportunity to help our clients maximise the value of their SAP investment with offerings that address sales, finance, supply chain, engineering, and human capital. We provide comprehensive consulting, system integration and implementation services across multiple SAP applications, products and technologies. Simply put,...