Full-time
Job Purpose:
The mission consists in filling the role of Application Security Office and Vulnerability Expert for regular qualification of application vulnerability, timely monitoring, collecting, analysing application vulnerability data and delivering vulnerability mitigation recommendation to the IT Teams.
The sources of information include but are not limited to Web Application Firewall (WAF) alerts, security scanner reports, published vulnerabilities from vendors and internal/external threat intelligence sources. The position will also support incident handling for application vulnerabilities.
Job Scope:
- Lead the application security function in Asia and work closely with Global CyberDefense teams across the world.
- Identify the vulnerability severity on our applications from Various automated tools like Qualys (DAST) and SCA - J-Frog XRAY
- Analyze the impact of Security bulletins on our applications (using the application component inventory)
- Prioritize the patches required and Coordinate with other security team members [Qualys Scan Execution team and Center of Excellence / WAF] to run further scans and WAF patches
- Track and record decisions made on how to treat the vulnerabilities
- Oversight and coordinate all work related to application vulnerability management in Asia
- Analyzing structured and unstructured datasets from various sources to analyses vulnerabilities and produce remediation recommendations
- Prioritize the emergency of vulnerability remediation activities
- Provide technical advisory to IT Production or Development Teams to effectively remediate vulnerabilities
- Ensure timely follow up for remediation of vulnerabilities
- Recommend compensatory measures when remediation takes time and the vulnerability exposure windows is not acceptable in regard to the threat level
- Report on mitigation status and threat exposure
- Own the application vulnerability management process and strive to optimize it
- Assist in investigation of security issues by reviewing the results of WAF alerts and other vulnerability identification (vulnerability scanning, penetration testing, etc.)
- Consult on incident handling which includes implementation of containment, protection and remediation activities
- Perform manual testing using tool such as Burp suite
- Flexible in supporting stream lining application security process and SSDLC and
- Support initiative for improving overall application security maturity
- Coordinate with Infra Security team for SCA vulnerabilities, identified through Qualys VM process.
- Supporting Cloud migration project from application security standpoint and setting up the new process