
Application Security Engineer
- Pune, Maharashtra
- Permanent
- Full-time
- Analysis of UML diagrams and DFDs/Threat Models for security flaws and detailing specific recommendations in software and system setup to address them
- Mentoring of developers on security topics and coding
- Develop and deliver trainings to developers and management on security topics
- Analyzing requirements and performing code review for security flaws
- Establish direction for security requirements in our custom hardware and software
- Collaborate with other internal security groups across multiple divisions, at different levels, and in multiple international locations, as well as 3rd parties
- Continuous improvement of security processes via observation and measurement of project performance, and making updates to improve accuracy, reduce overhead, while maintaining compliance with IEC 62443 3-3 and 4-1 standards
- Participate in audits for standards compliance
- Bachelor's degree in Computer Science, Computer Engineering, or a related engineering field with a minimum of 8 years of relevant experience OR Master's degree in Computer Science, Computer Engineering, or a related engineering field with a minimum of 7 years of relevant experience
- Candidate must have hands-on, professional coding experience, C/C++ or C# preferred
- Understanding of SDL/secure software development lifecycle practices
- Practical experience in software and security design principles
- Experience performing application-level threat modeling and code review
- Excellent interpersonal skills
- Excellent written and verbal communication skills
- Ability to clearly communicate technical information to a wide range of audiences
- Current knowledge of malware trends and current cybersecurity issues
- Experience with PKI/Certificates, Cryptography
- Current knowledge of trends in security specific to control systems
- Experience in the ICS or Automotive Industry
- Experience with other OT network technologies and Cloud
- Experience working with geographically distributed teams in a 100+ developer organization.
- Certifications such as CISSP, CEH, GSSP, GSEC, CSSLP, GIAC, ISA Cybersecurity, etc..