Appllication security-Vulnerability management
KeySkills
Company Name
Infosys Ltd ( Bangalore )
Job Description
About the Role:
As an Application Security / Vulnerability Management Consultant at Infosys, you will lead security architecture design and threat modeling efforts across modern software systems ? including web, mobile, thick clients, and cloud platforms. You will work closely with development and architecture teams to identify security risks, define secure design principles, and ensure secure application delivery across the CI/CD pipeline.
Key Responsibilities:
-
Architect, design, and review application security architecture for distributed web applications, mobile apps, thick clients, and cloud-based systems.
-
Perform Attack Surface Analysis and Threat Modeling using frameworks such as STRIDE and PASTA to identify risks, threats, and vulnerabilities.
-
Recommend and implement remediation and compensatory controls based on threat assessments.
-
Conduct Application Security and Threat Assessments with or without tools, providing actionable security recommendations.
-
Collaborate with development and architecture teams to ensure secure software design and adherence to security best practices.
-
Provide technical leadership to development teams during the design and build phases.
-
Leverage tools such as:
-
Microsoft Threat Modeling Tool
-
Threat Modeler
-
OWASP Threat Dragon or similar threat modeling solutions
-
Technical and Professional Requirements:
-
Proven experience in application security architecture and vulnerability management.
-
Strong knowledge of threat modeling frameworks (STRIDE, PASTA, etc.).
-
Hands-on experience with threat modeling tools.
-
Solid programming skills in:
-
Java, C++, Python, Ruby, .NET, JavaScript, HTML
-
-
Deep understanding of:
-
CI/CD pipelines
-
DevSecOps principles
-
Software development lifecycle (SDLC)
-
Preferred Qualifications:
-
Experience with cloud security and securing containerized/web applications.
-
Exposure to CAN Bus or embedded system security is a plus.
-
Familiarity with vulnerability management platforms and automated security tools.
-
Industry certifications such as CSSLP, OSCP, CISSP, or CEH are desirable.
-