Overview
Vice President – Offensive Security Lead Jobs in Gurugram, Haryana, India at SBI Card
Title: Vice President – Offensive Security Lead
Company: SBI Card
Location: Gurugram, Haryana, India
Vice President – Offensive Security Lead
Role Purpose:
Responsible for ensuring development, implementation, and effectiveness of vulnerability management and security testing programs, initiatives, and capabilities
Role Accountability:
- Assist with strategic planning, providing input on capabilities and methods used for vulnerability management and security testing, and driving improvements
- Develop Vulnerability management framework, support compliance and risk management activities, recommending security controls and corrective actions to mitigate vulnerability risks
- Lead innovative research and stay updated on emerging threats, vulnerabilities, and exploits with the goal of developing new TTPs improving attack efficacy
- Partner with Security Operations team to develop tooling and instrumentation (including automation) to improve detection and response capabilities
- Design scenario-based / thematic security testing to identify vulnerabilities in the product and gaps in detection and response capabilities
- Engage with the developers in developing workarounds / mitigation plan and ensure they are implemented per policy
- Manage security testing related programs such as responsible disclosure / bug bounty
- Conduct vulnerability assessments and penetration testing, red teaming, blue teaming (application and/or infrastructure) and articulating security issues to technical and non-technical audience
- Provide expertise in security tools for vulnerability assessment, penetration testing & application security
- Perform vulnerability risk profiling and prioritization of vulnerabilities
- Provide security architecture and advice in support of application development, infrastructure, and enterprise technology projects
- Drive secure coding related training and awareness initiatives for software developers & architects at SBI Cards
- Oversee the development, implementation and maintenance of vendor standard operating procedures/ run book in line with SBI Card policies & standards
- Monitor offensive security vendor SLAs, perform regular review with vendor management and report to SBI Card leadership
- Ensure process documentation and compliance adherence
Measures of Success:
- Reduction in security vulnerabilities in SBI Card IT platforms
- Reduction in information leakage and exploitation from vulnerabilities
- Compliance with regulatory guidelines
- Timely and accurate vulnerability testing and remediation
- Vendor SLA Adherence
- No adverse observations in internal/external audits
- Process Adherence as per MOU
Technical Skills / Experience / Certifications:
- Strong knowledge of web development and programming languages e.g. Java, .NET, Python, etc.
- Strong knowledge of web application technology, e.g. Application Servers, Web Servers, Databases
- Ability to perform security testing on an app development project either using struts, spring much like java based frameworks
- Experience of performing manual code review and manual dynamic testing to find application vulnerabilities
- GIAC/GWAPT/GPEN/GXPN/OSCP/CISSP certification, or any other equivalent industry accredited certification
- Exposure to methodologies, such as OWASP preferred, Penetration, Host, Applications (Ethical Hacking tools such as Nessus, Qualys, Nexpose), Vulnerability Assessments – Network, Host, Applications, Security in SDLC (Application Security), Secure code review – .NET and J2EE technologies
- Experience of building, deploying, and managing offensive security operational infrastructure
- Knowledge of open source intelligence gathering and social engineering
- Knowledge of Commodity and advanced threat actor Tactics, Techniques and Procedures
- Expert-level knowledge and experience in identifying multiple classes of vulnerabilities that includes cross-site scripting, SQL Injection, CSRF, cryptographic related weakness, and code injection
Competencies critical to the role
- Analytical Ability
- Innovation & Problem Solving
- High Impact Communication
- Market Awareness
- Continuous Learning
Qualification:
Bachelor of Engineering in Computer Science / Engineering/ or any other relevant discipline, Masters in Computer Science /or any other relevant discipline
Preferred Industry:
BFSI, NBFC, E-Commerce, IT development and operations