HCLTechActive opening

Tower Lead (Support & Operations)

MH, INOn-siteLeadFound 4 days ago
Apply to this job

Free credits included. Sign up to start applying with Jobfinder.

appsecsdlcdevsecopsvulnerability-managementowaspjavajavascriptcloud-security

| Pune, MaharashtraBengaluru, Karnataka

Job Summary

Years of Experience

14+ years of experience in Application Security, secure SDLC, DevSecOps, application-security architecture, and vulnerability management.

General Description

Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, and operating-model improvement.

Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.

Mentor L2 engineers and coordinate with security architecture, engineering, risk, external testing providers, and application owners.

Key Responsibilities

Years of Experience

14+ years of experience in Application Security, secure SDLC, DevSecOps, application-security architecture, and vulnerability management.

General Description

Serve as AppSec L3 SME, providing advanced finding validation, remediation advisory, secure-SDLC guidance, technical governance, and operating-model improvement.

Lead complex vulnerability analysis, application onboarding patterns, policy-driven security gates, exception analysis, and developer enablement.

Mentor L2 engineers and coordinate with security architecture, engineering, risk, external testing providers, and application owners.

Skill Requirements

Technical Requirements

Hands-on experience with SAST, SCA, DAST, API security testing, secrets scanning, container/image scanning, and cloud-code security tools such as Wiz Code or equivalent.

Strong understanding of OWASP Top 10, CWE, CVSS, secure coding practices, vulnerability lifecycle, and risk-based prioritization.

Experience triaging application-security findings, validating false positives, assigning severity, and providing remediation guidance.

Experience supporting application onboarding into AppSec tools and secure-SDLC workflows.

Knowledge of Java, JavaScript, Angular, APIs, cloud services, containers, and open-source dependency risks.

Experience with Jira/ServiceNow, finding backlogs, exception workflows, evidence preparation, and AppSec reporting.

Understanding of CI/CD security integration and policy-driven security gates.

Deep expertise in advanced web, API, cloud-native, container, microservices, authentication, authorization, cryptography, and business-logic vulnerabilities.

Experience defining AppSec standards, threat-modeling approaches, secure-design reviews, testing strategies, and risk-based remediation models.

Ability to review complex Java/Spring Boot, Angular, Python, API, AWS, and Kubernetes/EKS application architectures.

Experience designing and integrating AppSec controls into CI/CD pipelines, including policy-as-code and release-security gates.

Ability to lead tool tuning, false-positive reduction, coverage analysis, AppSec metrics, exception governance, and maturity improvement.

Experience supporting regulatory/audit evidence and communicating application risk to senior stakeholders.

Soft Skills

Excellent communication and presentation skills.

Strong problem-solving and critical thinking skills.

Exceptional project management and organizational abilities.

Team collaboration and leadership skills.

Client-focused approach with a commitment to delivering exceptional customer service.

Certifications (Good to have)

Good to have relevant certificates like (any of the below):

CSSLP, OSWE, GWAPT, GWEB, CISSP, or equivalent advanced application-security certification.

Cloud-security or DevSecOps certification is preferred.

Educational Qualifications

University degree in IT or/and IT Security.

Bachelor’s degree in computer science/ IT or any relevant fields.

Other Requirements

#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-

HCLTechTower Lead (Support & Operations)
Apply to this job