포지션 소개
Job Description
Required Qualifications:
-
Bachelor’s degree in computer engineering OR related engineering degree and/or practical experience
-
Ability to demonstrate knowledge of OWASP Top 10 and CWE Top 25
-
Knowledge of application-layer security controls, including authentication and authorization methods, input/output validation and sanitization, and defenses against injection attacks such as SQL or command injection
-
Understanding of secure cryptographic practices, including appropriate use of encryption algorithms, hashing functions, and protection of data at rest and in motion
-
Secure coding in Java or .NET web and service development, backed by 7+ years of practical, hands-on programming and IT experience
-
Experience participating as a member of a team in an agile environment
-
Experience with the Secure Development Lifecycle
-
Experience with security tools including SAST, DAST, IDE plugins, decompilers, and threat modeling platforms
Advanced people skills:
-
Ability to conceptualize an application security finding and the best tactical approach for a team to remediate
-
Excellent communication skills and proven ability to communicate threats and facilitate progress towards long-term remediation
-
To effectively communicate complex security findings to both technical and non-technical audiences
-
Ability to demonstrate proven analytical and problem-solving skills, as well as desire to assist others
-
Effective relationship builder: ability to partner cross-functionally, cross-enterprise and work effectively with various levels of the organization
Preferred Qualifications:
-
Experience with enterprise platforms such as Struts, Spring, J2EE/Jakarta EE (Java) or .NET, with awareness of how their structure impact authentication, authorization, and secure service design
-
Intermediate understanding of web technologies and data formats, including XML, JSON, AJAX, with attention to the security implications of JavaScript-driven UIs and asynchronous communication
-
Familiarity with service protocols and architectures such as SOAP and REST, with working knowledge of secure data handling and integration patterns
-
Experience with source code repository tools such as Bit
Bucket and GitHub:
-
Master’s degree in Cybersecurity a plus
-
Web application penetration testing, ethical hacking, red/blue teaming, or capture-the-flag experience a plus
-
Serve as a trusted partner to developers, product owners, and stakeholders, translating company security policies into actionable, non-functional application security controls.
-
Be thought leader – drive secure code reviews, identify context-specific vulnerabilities, align teams with security objectives, and eliminate process inefficiencies.
-
Communicate emerging application security weaknesses, exploit patterns, and risk scenarios in clear, business-relevant terms.
-
Assist teams in mitigation and remediation efforts while operating within agile delivery environments.
-
Apply insight and initiative to raise the standard of secure development and streamline the path from policy to implementation.
͏
͏
͏
͏
복지 및 혜택
•교육비 지원
•의료보험
•스톡옵션
필수 스킬
Cybersecurity
Risk management
Incident response
Wipro 소개
Bengaluru
본사 위치
