Lead Assistant Manager - Application Security at EXL Talent Acquisition Team
Noida, Uttar Pradesh, India -
Full Time


Start Date

Immediate

Expiry Date

17 Sep, 26

Salary

0.0

Posted On

19 Jun, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Web Application Penetration Testing, Mobile Application Security, Source Code Review, DevSecOps, SAST, DAST, SCA, OWASP Top 10, Burp Suite Pro, Python, Bash, CI/CD Pipelines, Threat Modelling, API Security, Vulnerability Management, Container Security

Industry

Business Consulting and Services

Description
Key Responsibilities Application Security Testing * Conduct manual and tool-assisted web application penetration testing (OWASP Top 10, business logic flaws, API vulnerabilities). * Perform mobile application security assessments for Android and iOS (static & dynamic analysis, reverse engineering, OWASP MASVS/MSTG). * Execute source code security reviews—both SAST-assisted and manual—across languages such as Java, Python, JavaScript/TypeScript, and others. * Participate in grey-box assessments and targeted red-team exercises against internal and client-facing applications. DevSecOps Integration * Integrate and operate SAST, DAST, SCA, and container security tools within CI/CD pipelines (Jenkins, GitHub Actions). * Configure and tune security tooling to reduce false positives and enforce actionable pipeline quality gates. * Support IaC security reviews (Terraform, CloudFormation) and secrets management practices. * Collaborate with platform engineering to embed security controls in build and deployment workflows. Vulnerability Management & Remediation * Triage, prioritise, and track vulnerabilities from discovery through verified closure. * Produce clear, developer-friendly reports with reproducibility steps, severity ratings, and remediation guidance. * Support development teams in understanding and fixing identified issues; re-test post-remediation. * Maintain internal vulnerability registers and risk-tracking artefacts. Secure SDLC * Assist in threat modelling and secure design reviews for new features and services. * Promote secure coding standards and OWASP best practices across development teams. * Contribute to security champions programmes and developer awareness initiatives. * Assist in securing AI/GenAI applications and APIs following defined security patterns.
Responsibilities
The role involves identifying and remediating security vulnerabilities across web, mobile, and source code through penetration testing and security reviews. It also focuses on integrating security tools into CI/CD pipelines and promoting secure SDLC practices.
Loading...