The role will be responsible for operationalizing and delivering security engineering requirements as directed by the Global Head of Security Architecture & Engineering. Partnering with the broader Digital Business Solutions (DBS) organization, you will play a crucial role in ensuring the security and integrity of our organizations applications and software systems.
You will work closely with development teams, architects, and other collaborators to identify and mitigate security vulnerabilities, conduct security assessments, and implement standard processes to protect our applications from potential threats.
Your expertise in secure coding practices, vulnerability assessments, and secure design principles will be essential in maintaining the security posture of our applications.
responsibilities :
Conducting security assessments and penetration testing to identify vulnerabilities, weaknesses, and risks. Using tools and techniques to analyze security posture and provide remediation recommendations.
Reviewing application source code for security flaws and coding standard processes, addressing issues like input validation, authentication, and insecure data storage.
Monitoring and managing application vulnerabilities by staying updated on patches, upgrades, and fixes. Collaborating with development teams for timely remediation.
Working with development teams to integrate security requirements and standard methodologies into design and development. Providing guidance on secure architecture and coding techniques.
Assisting in incident response for security breaches, identifying root causes, containing impact, and facilitating recovery.
Promoting security awareness by training development teams on secure coding practices, policies, and procedures.
Ensuring compliance with security standards, industry regulations, and legal requirements. Keeping up with evolving standard methodologies and integrating them into development.
Evaluating, implementing, and managing security tools like static code analysis, DAST, and SCA tools. Automating security testing where applicable.
Collaborating with developers, architects, QA, and operations teams to address security concerns and integrate measures throughout the application lifecycle. Communicating risks effectively to technical and non-technical partners.
requirements-expected :
Application Development: Experience in software development with knowledge of various programming languages, frameworks, and methodologies.
Security Testing & Assessments: Hands-on experience with security testing, including static code analysis, DAST, and IAST. Experience in security assessments and vulnerability scanning.
Secure Coding Practices: Practical experience in secure coding and applying security controls throughout the software development lifecycle.
Incident Response: Exposure to security incident response and experience in handling and mitigating application security incidents.
Threat Modelling: Ability to perform threat modelling to identify potential security risks and vulnerabilities.
Vulnerability Management: Proficiency in identifying, analysing, and mitigating application vulnerabilities.
Secure Code Review: Strong ability to review source code for security flaws using manual and automated techniques.
Security Tools: Familiarity with security testing tools like SAST, DAST, and security scanning tools.
Security Standards & Frameworks: Knowledge of industry standards like OWASP, NIST SP 800-53, and CERT Coding Standards.
offered :
We offer a market leading annual performance bonus (subject to eligibility).
Our range of benefits varies by country and includes diverse health plans, initiatives for work-life balance, transportation support, and a flexible holiday plan with additional incentives.
Your journey with us isnt limited by boundaries; its propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isnt just a statement – its a reality were eager to build together. Seize the opportunity and own your development; your next chapter starts here.
Youll have access to online learning platforms and personalized growth programs to nurture your leadership skills.
We prioritise continuous improvement within a transformative environment, preparing for ongoing changes.