Now hiring

Risk Consulting - Digital Risk - Senior - Application Security (Noida, UP, IN, 201301) @ EY Global Services

Noida, UP, IN, 201301OnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px">At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. </span></span></p> <p> </p> <p> </p> <p> </p> <p> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job description - Senior – Risk Consulting</strong></span></p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Job Title: Application Security Reviewer</strong></span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Overview:</strong> We are seeking an experienced Application Security Reviewer to join our team. The candidate is responsible for conducting application security assessments to identify and mitigate potential security risks in our applications and systems. This role requires a deep understanding of security principles, threat modelling methodologies, and the ability to communicate findings effectively to technical and non-technical stakeholders.</span></p> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Key Responsibilities:</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Threat Modelling: </strong>Must Have</span> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Analyse software systems to identify potential threats and vulnerabilities.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Create and maintain threat models that outline potential attack vectors and prioritize security efforts (leveraging established Threat Model frameworks like STRIDE)</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Collaborate with development teams to remediate identified vulnerabilities through code reviews and dynamic testing.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Validate threat models against industry standards and best practices, ensuring alignment with organizational security policies.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Document findings from threat modelling assessments, including identified risks, recommended mitigations, and action plans.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Prepare and present reports to stakeholders, summarizing assessments and providing actionable insights.</span></li> </ul> </li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Secure Code Review</strong>:</span> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Review code written by developers to identify security flaws and ensure adherence to coding standards and best practices.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Integrate security into the software development lifecycle.</span></li> </ul> </li> </ul> <p style="line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Security Testing:</strong></span></li> <li style="list-style-type:none;font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Perform various security tests, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Interactive Application Security Testing (IAST).</span></li> </ul> </li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Application Onboarding Support:</strong> Must Have</span> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Provide technical guidance for application onboarding activities and assist developers in navigating the security review process.</span></li> </ul> </li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Stakeholder Engagement: Must Have</strong></span> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Work closely with development teams, product managers, and other stakeholders to gather information and understand application architecture.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Build and nurture positive working relationships with stakeholders and leadership, acting as a trusted advisor for the clients.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Support app teams in drawing Threat Models and Data Flow Diagrams</span></li> </ul> </li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Process Improvement:</strong></span> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Stay up to date with the latest security threats, vulnerabilities, and trends in threat modelling methodologies.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Design and implement process improvements for the Application Security program.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Assist in the review and assessment of tools and technologies leveraged and identify opportunities for automating application security review and tracking workflows, enhancing threat model review tools, etc.</span></li> </ul> </li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Education Qualifications:</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Education:</strong> Bachelor’s degree in information technology, Cybersecurity, Business Management, or a related field.</span></li> </ul> <p style="line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif;font-weight:bold"> </p> <p style="line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif;font-weight:bold"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong> Experience: Must Have</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">4+ years of experience with various threat modelling tools and methodologies.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">4+ years of experience in engineering, product/technical program management, data analysis, or product development.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">4+ years of experience working in cross-functional and/or cross-team projects.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">4+ years of combined experience in technology administration/management, technical risk management, and software development/engineering.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong exposure working in client facing roles.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Preferred Qualifications:</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Certifications such as Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) are a plus.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Basic to moderate coding skills and experience working on application or service development teams.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong written and oral communication skills, with the ability to tailor communications based on the audience.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Self-motivated with the ability to work independently.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Strong analytical skills with the ability to think creatively and influence change.</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p> <p style="margin:0.0in 0.0in 8.0pt 0.25in;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"><strong>Technical Skills:</strong></span></p> <ul> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Understanding of cloud computing, networking, and common cloud-based application architectures.</span></li> <li style="line-height:115%;font-size:10.0pt;font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Familiarity with application security concepts, software development processes, and security frameworks (e.g., OWASP, NIST).</span></li> </ul> <p style="margin:0.0in 0.0in 8.0pt;line-height:115%;font-size:12.0pt;font-family:Aptos, sans-serif"> </p><p> </p> <p><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"><b>EY | Building a better working world </b></span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. </span></span></p> <p><br> <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-size:11.0px"> <br> Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. </span></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores