We are seeking a motivated candidate to join our dynamic security team. The ideal candidate will have a strong background in managing Snyk, conducting code reviews, hands-on coding, and experience with Kubernetes, FOSS (Free and Open Source Software), and Black Duck. This role is crucial for ensuring the security and integrity of our software development lifecycle. Key Responsibilities: Snyk Management: Configure, maintain, and optimize Snyk within the organization to identify and remediate vulnerabilities in dependencies and code. Develop and enforce Snyk policies and best practices. Provide training and support to development teams on using Snyk effectively. Code Review: Perform thorough code reviews to identify security vulnerabilities and provide actionable feedback. Establish and maintain code review guidelines and standards. Collaborate with developers to ensure secure coding practices are followed. Hands-On Coding: Engage in hands-on coding to demonstrate secure coding practices and provide examples. Contribute to the development of security-related tools and scripts. Assist in the implementation of security features within applications. Kubernetes Security: Ensure the secure deployment and management of applications in Kubernetes environments. Implement security best practices for Kubernetes clusters, including namespaces, RBAC, and network policies. Monitor and respond to security incidents within Kubernetes environments. FOSS Management: Manage the use of FOSS within the organization, ensuring compliance with licenses and security standards. Conduct regular audits of FOSS components for vulnerabilities and license compliance. Collaborate with legal and procurement teams to mitigate risks associated with FOSS. Black Duck Integration: Integrate and manage Black Duck within the development pipeline to identify and manage open source vulnerabilities. Generate and analyze reports on open source usage and vulnerabilities. Work with development teams to remediate identified vulnerabilities. Security Advocacy: Promote a culture of security awareness within the organization. Conduct training sessions and workshops on security topics. Stay current with emerging threats and security trends, and advocate for appropriate changes within the organization. Education: Bachelor’s degree in Computer Science, Information Security, or a related field. Experience: 2-5 years of experience in a similar role, with a focus on SAST tools and practices. Technical Skills: Proficiency in Snyk, Black Duck, and other SAST tools. Strong understanding of secure coding practices and principles. Experience with Kubernetes and container orchestration. Knowledge of FOSS licenses and management. Familiarity with CI/CD pipelines and integration of security tools. Soft Skills: Excellent communication and interpersonal skills. Ability to work collaboratively with development and operations teams. Strong problem-solving skills and attention to detail.
IN_Senior Associate_Guidewire - BC_OC Guidewire_Advisory_Bangalore
Pwc
Renewable Energy Market Research Analyst (HE/SHE/THEY)
Hrcg
IN-Associate_ Python Developer_Intelligent power _Advisory_Gurgaon
Pwc
Domain Consultant I
Hcltech
Kinaxis
Careers Inc
Cloud Engineer
Careers Inc