SME - Web App firewall, Cloud Security, Palo Alto Firewalls
HCLTech
Greater Noida, Uttar Pradesh, IndiaPosted 23 days agoDiscoveredMatch locked
About the role
jobColumnOne" role="region" aria-labelledby="jobColumnOneRegion" style="width:50%;">
Job Description
SME - Web App firewall, Cloud Security, Palo Alto Firewalls
Greater Noida, Uttar Pradesh
Job Summary
Application Security Engineer The Application Security Engineer (Threat Modeling) operates as a mid-level individual contributor focused on securing our business-standard web applications. In this role, you will own the day-to-day security-by-design initiatives by systematically applying the STRIDE methodology to identify architectural flaws before code deployment. You will collaborate directly with product engineering teams to uncover and mitigate Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege risks.
Job Description
Professional Skills\\\\r\\\\n• Independent Execution: Ability to manage multiple threat modeling projects concurrently with guidance only on highly complex architectures.\\\\r\\\\n• Engineering Empathy: Skill in collaborating constructively with software engineers, offering practical remediation advice rather than just pointing out flaws.\\\\r\\\\n• Clear Communication: Ability to articulate technical security risks and their direct business impacts clearly in both written reports and verbal discussions.\\\\r\\\\n
Job Responsibilities
Key Responsibilities • Conduct STRIDE Assessments: Independently perform threat modeling on core web applications, APIs, and microservices using the STRIDE framework. • Deconstruct Web Architecture: Analyze data flow diagrams (DFDs), component architecture, and trust boundaries to map out potential attack paths. • Define Actionable Requirements: Translate STRIDE findings into clear, developer-friendly user stories and acceptance criteria within Jira or engineering backlogs. • Track Mitigation Lifecycles: Monitor the implementation of security controls (e.g., proper encryption, secure session handling, robust logging) and verify remediation. • Maintain Threat Repositories: Keep threat models up to date as application features evolve, maintaining a clear picture of the application\'s risk posture.
Skill Requirement
- Web App Security Expertise: Solid understanding of web technologies, HTTP protocols, browser security (CORS, CSP, SameSite cookies), and the OWASP Top 10. • Practical STRIDE Skills: Demonstrated experience breaking down functional application designs into STRIDE categories to catch flaws early. • Modern Development Stack: Familiarity with standard web stacks (e.g., React, Node.js, Java, .NET) and modern CI/CD software pipelines. • Threat Modeling Tooling: Hands-on experience with tools like the Microsoft Threat Modeling Tool, OWASP Threat Dragon, IriusRisk, or similar diagramming solutions.
Other Requirement
Technical Qualifications • Experience: 3 to 5 years of experience in Application Security, Product Security, or software development with a heavy focus on security design. • Web App Security Expertise: Solid understanding of web technologies, HTTP protocols, browser security (CORS, CSP, SameSite cookies), and the OWASP Top 10. • Practical STRIDE Skills: Demonstrated experience breaking down functional application designs into STRIDE categories to catch flaws early. • Modern Development Stack: Familiarity with standard web stacks (e.g., React, Node.js, Java, .NET) and modern CI/CD software pipelines. • Threat Modeling Tooling: Hands-on experience with tools like the Microsoft Threat Modeling Tool, OWASP Threat Dragon, IriusRisk, or similar diagramming solutions.
Apply now
<div class="
Not included in the source posting: about the role, benefits.
Skills
node-jsapplication-securityci-cdjavajavascriptnetreactjira
Who can apply
The employer didn't state any visa, work authorization, citizenship or clearance requirements in this posting. Confirm with the employer before applying.
Read automatically from the employer's posting text. Always confirm with the employer — requirements can change after a job is published.