We’re looking for an experienced security consultant for our offices. This is indeed a hands-on tech oriented position. You need to know about the standard security practices, have some demonstrable experience with implementing security automation, but it is critical you are able to work with delivery teams as well as networks and infrastructure support teams.
We want someone who can talk the language of software product delivery teams and work collaboratively with them to reduce risks related to code development, system architecture and infrastructure.
It will help if you have experience working in delivery teams using agile development methodologies and practices.
4-8 years experience working as a security engineer which includes responsibilities working directly with delivery teams to review code and systems architecture for vulnerabilities.
In-depth knowledge and experience with OWASP and SANS standards
Experience in manual and automation penetration testing tools and techniques.
Demonstrable experience in secure coding practices in common programming languages such as Java, .NET and C#.
Experience of conducting Security Code Reviews for applications with at least standard tech-stack such as Java, .NET, Java development frameworks, etc.
Should have experience with and good exposure to various application testing tools such as ZAP, Burp suite, Scout2, HP fortify,Checkmarx, Veracode or any other open source tools.
Experience in password / secret management tools and techniques
In-depth understanding of web technologies, common web frameworks, their vulnerabilities and mitigations
Basic understanding of firewall, virtualisation, container, networking and OS security.
Excellent communication and interpersonal skills
As an Application Security Specialist, you will have an opportunity to
Embed security throughout the lifecycle of software delivery
Building and defining security practices
Play a consultant and advisory role to delivery team and clients
Regardless of what you do at ThoughtWorks, you’ll always have the opportunity to
Think through hard problems, and work with a team to make them reality.
Learn something new every day.
Work in a dynamic, collaborative, transparent, non-hierarchical, and ego-free culture where your talent is valued over a role title.
Speak at conferences.
Write blogs and books.
Develop your career outside of the confinements of a traditional career path by focusing on what you’re passionate about rather than a predetermined one-size-fits-all plan.
Be part of a company with Social and Economic Justice at the heart of its mission.
To more about us : Please visit through our websites :