Key Result Areas | Supporting Actions |
Application Security Governance | Ensure Security test is conducted as per the scope agreed in timely fashion and deploy compensatory controls for all open risk from zero day of identification and closure of all vulnerabilities as per agreed timeline |
VAPT and Security Config Audit of Network Devices, DMZ Assets, MZ Assets | Vulnerability Assessment (Automated), Security Config Audit and Penetration Testing (Manually) of all the systems Governance- Assistance in vulnerabilities closure to respective technical SPOCs. |
Implementation of ASLC and DevSecOps Framework for ABCD and Application Security- Advisory | Governance of ASLC, DevSecOps at ABCD level. Conducting Seminars/Workshops/Training session on Application Security. Design and deploy framework to measure the effectiveness of these trainings. 100 % ASLC Documentation for all new & old Apps of ABCD. Monthly Reporting on the same to the CISO |
Web Application Firewall- Technical Advisories and Governance | WAF evaluation, fine tuning of Web Apps, Technical governance at ABC level. On boarding 100 % current Internet facing applications of ABC and 100 % new Internet facing applications of ABC from Day 1. Configure it on preventive mode within 2 weeks and monitor the logs and action the same. |
Red Teaming Activity- Red Teaming activity (Blackbox) across all businesses of ABC | Red Team Assessments focus on giving your security team practical experience combating real cyber attacks. While avoiding business damaging tactics, these assessments use conventional and advanced attacker TTPs to target agreed-upon objectives. The objectives are to compromise the Organization’s email boxes, critical information/data and the ultimate goal is to compromise the Active Directory which is considered as a critical component of any organization which stores data, ID and email, mailbox, login related information, etc. An Attacker/Hacker who gets success in compromising the Active Directory can further breach into the entire Network and Infrastructure of the Organization. To Conduct 4 Blackbox Red Team Assessments in a year and ensure closure of the same within 2 weeks or process risk sign off by the businesses. |
Evaluation of Security Products (EDRs, WAFs, etc) | To conduct the POCs for Security products by Attacking applications/devices/products on real time basis by adapting Red Teaming approach. Submission of POC results/reports to the Group CISO. This shall help ABC in good decision-making of buying the precise Security product. |
Conducting AD Security Assessment for ABC | To conduct the AD Security Assessment across ABC once in a year. Submission of POC results/reports to the Group CISO, work closely with stakeholders on the closure of findings. Validate the same to provide the signoff... |
Certifications | Certified Mobile and Web Application Penetration Tester (CMWAPT) or Offensive Security Certified Professional (OSCP) or Certified Penetration Tester (CPT |
Eligibility typically includes the qualifications and experience outlined in the job description above, with around 6-9 Years years of relevant experience expected for this role.
The key responsibilities for this role are detailed in the Key Responsibilities section above, covering the core duties expected of a Senior Application Security Manager at Aditya Birla Group.
This role requires around 6-9 Years years of relevant experience, as specified in the job listing. Please refer to the Qualifications & Experience section above for full details.
Skills relevant to this position are outlined in the Qualifications & Experience section above. In general, strong communication, domain knowledge, and the ability to meet role-specific targets are valued across similar BFSI positions.
You can apply directly using the Apply Now button on this page, which will take you to Aditya Birla Group's application process for this role.