Description
Join a high-performing engineering team developing secure, large-scale IoT and cloud-native software platforms for the energy and utilities domain. The team is responsible for designing, building and securing enterprise applications deployed across distributed environments. This role focuses on driving secure-by-design principles, threat modeling, DevSecOps, vulnerability management and security automation while working closely with architects, developers and product teams. The ideal candidate is hands-on with modern application security practices, cloud-native technologies, Kubernetes, Docker and Linux environments, and is comfortable using Linux shell scripting and command-line tools to support security analysis, automation and troubleshooting.
Requirements
– BS/MS/PhD in Computer Science or equivalent technical experience.
– 8+ years of experience in Application Security, Product Security or Information Security.
– 3–5 years of hands-on experience configuring, analyzing and troubleshooting Dynamic Application Security Testing (DAST) scans.
– Strong understanding of Secure SDLC, OWASP Top 10, NIST, ISO, PCI and industry security best practices.
– Hands-on experience performing Threat Modeling and security risk assessments using methodologies such as STRIDE, PASTA, TRIKE or ATT&CK.
– Experience conducting security architecture reviews and driving secure-by-design principles for both new and legacy applications.
– Strong knowledge of authentication, authorization, input validation, output encoding, session management, cryptography and secure coding practices.
– Experience with SAST, DAST, IAST and Software Composition Analysis (SCA) tools such as Burp Suite, OWASP ZAP, Checkmarx, Tenable or equivalent.
– Experience implementing DevSecOps practices by integrating security scanning tools into CI/CD pipelines.
– Experience securing cloud-native applications, microservices, serverless architectures, Kubernetes, Docker and AWS environments.
– Hands-on experience working in Linux environments with proficiency in Linux shell scripting and command-line tools for security analysis, automation and troubleshooting.
– Experience with vulnerability management, penetration testing, security scanning and remediation.
– Experience with anomaly detection and observability platforms such as ELK, Prometheus, Grafana and InfluxDB.
– Strong understanding of operating system, application, network and database security architectures.
– Experience working with Agile development methodologies and tools such as Jira, GitHub and Confluence.
– Excellent communication skills with the ability to work independently and collaborate with developers, architects, product teams and senior leadership to define security requirements, technical designs and product strategy.
Job responsibilities
– Drive strategic product security initiatives to ensure new and legacy applications and infrastructure comply with organizational security policies and industry frameworks such as ISO, PCI, OWASP and NIST.
– Perform threat modeling of applications and technology designs to identify security risks early and mature threat modeling practices across engineering teams.
– Act as the security subject matter expert for architects and engineering teams by conducting security architecture reviews, assessing risks and recommending appropriate security controls and mitigations.
– Lead strategic security initiatives including security automation, continuous improvement and implementation of internal security policies and procedures.
– Identify, analyze and remediate security vulnerabilities through static analysis, dynamic analysis, Software Composition Analysis (SCA), penetration testing and security scanning.
– Prevent attack exposure through threat modeling, system audits, system hardening and security policy compliance.
– Lead application security reviews for smart IIoT devices, web applications and cloud infrastructure.
– Contribute to the secure implementation and deployment of enterprise software solutions.
– Develop and enhance DevSecOps capabilities by integrating SAST, DAST, IAST and SCA tools into SDLC and CI/CD pipelines.
– Build security tooling, automation, dashboards and observability capabilities to improve operational efficiency and visibility into the organization’s security posture.
– Work closely with development, architecture and operations teams to secure microservices, serverless applications, containers, Kubernetes platforms and cloud-native environments.
– Work in Linux environments using shell scripting and command-line tools to automate security tasks, analyze findings and support security investigations.
– Utilize anomaly detection and observability platforms such as ELK, Prometheus, Grafana and InfluxDB to improve security monitoring and analysis.
– Define, track and own security metrics and KPIs to measure the effectiveness of the application security and security automation programs.
What we offer
Exciting Projects: We focus on industries like High-Tech, communication, media, healthcare, retail and telecom. Our customer list is full of fantastic global brands and leaders who love what we build for them.
Collaborative Environment: You Can expand your skills by collaborating with a diverse team of highly talented people in an open, laidback environment — or even abroad in one of our global centers or client facilities!
Work-Life Balance: GlobalLogic prioritizes work-life balance, which is why we offer flexible work schedules, opportunities to work from home, and paid time off and holidays.
Professional Development: Our dedicated Learning & Development team regularly organizes Communication skills training(GL Vantage, Toast Master),Stress Management program, professional certifications, and technical and soft skill trainings.
Excellent Benefits: We provide our employees with competitive salaries, family medical insurance, Group Term Life Insurance, Group Personal Accident Insurance , NPS(National Pension Scheme ), Periodic health awareness program, extended maternity leave, annual performance bonuses, and referral bonuses.
Fun Perks: We want you to love where you work, which is why we host sports events, cultural activities, offer food on subsidies rates, Corporate parties. Our vibrant offices also include dedicated GL Zones, rooftop decks and GL Club where you can drink coffee or tea with your colleagues over a game of table and offer discounts for popular stores and restaurants!
About GlobalLogic
GlobalLogic, a Hitachi Group Company, is a trusted digital engineering partner to the world’s largest and most forward-thinking companies. Since 2000, we’ve been at the forefront of the digital revolution – helping create some of the most innovative and widely used digital products and experiences. Today we continue to collaborate with clients in transforming businesses and redefining industries through intelligent products, platforms, and services.