Risk Consulting - Protect Tech - Senior (IT Risk - Application Security)
Ernst & Young (EY)
3 - 5 years
Bengaluru
Posted: 3/6/2025
Job Description
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.
Risk Consulting - Protect Tech - Senior (IT Risk – Application Security)
Key responsibilities
The purpose of this role will be to supervise delivery, provide technical and project leadership to your team members, as well as build relationships with clients. While delivering quality client services and enabling high-performing teams, you will drive high-value work products within expected timeframes and budget. You will monitor progress, manage risks and ensure key stakeholders are kept informed about progress and expected outcomes. Additionally, you should have following skills added below.
- Perform comprehensive security assessments and collaborate with developers to mitigate vulnerabilities.
- Evaluate software architectures to detect potential threats, craft threat models to illustrate possible attack paths, and prioritize security measures.
- Scrutinize developer-written code for security weaknesses, compliance with coding standards, and alignment with best practices, integrating security throughout the development process.
- Execute a suite of security tests, including static (SAST), dynamic (DAST), and interactive (IAST) analyses, to discover and address application vulnerabilities.
- In critical security incidents, you'll be instrumental in the investigation, containment, and resolution efforts, working alongside incident response teams.
- Guide application onboarding and support developers through the review process, ensuring a smooth integration into our security framework.
- Develop and refine roadmaps and priorities for our Assurance program, focusing on the security of tools and services.
- Partner with engineering teams and tool owners to proactively embed the Assurance function earlier in the development cycle.
- Innovate and enhance the Application Risk Assessment program, ensuring continuous improvement.
- Evaluate tools and technologies to identify gaps in data protection and compliance, ensuring adherence to regulatory standards.
To qualify for the role, you must have
- A bachelor’s degree in information technology, Cybersecurity, or Business Management with at least 3 years of experience in product/technical program management, data analysis, or product development, or an equivalent combination of education and experience.
- At least 3 years of work experience in technology administration/management, technical risk management, technical risk consulting, and/or software development/engineering.
- Proficiency in coordinating complex process reviews, interpreting results, and clearly articulating findings.
- Good to have at least one relevant industry certification, such as CISA, CISM, CISSP, CRISC, CCSK, ISO 27001, among others.
- Prior experience working on an application or service development team is advantageous.
- A self-starter who is motivated to work autonomously with minimal supervision.
- Strong analytical skills with the capacity to think creatively, communicate recommendations, influence change, and introduce process and structure in a dynamic environment.
- A comprehensive understanding of various technologies, including cloud computing, networking, cloud application design, development tools/processes, and common cloud-based application architectures.
- Knowledge of data security concepts, such as Application Security Testing, Vulnerability Assessment, or Information Systems Audit.
EY | Building a better working world
_x000d_ EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
_x000d_ Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
_x000d_ Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
About Company
Ernst & Young (EY) is a global professional services firm specializing in audit, consulting, tax, and advisory services. Headquartered in London, EY operates in 150+ countries, serving businesses across various industries. The firm is known for helping clients navigate financial regulations, optimize operations, and implement innovative technologies. EY is also a leader in risk management, mergers & acquisitions, and sustainability consulting. With a strong focus on digital transformation and AI-driven solutions, EY continues to be a trusted partner for corporations worldwide.
Services you might be interested in
One-Shot Campaign
Reach out to ideal employees in one shot!
The intelligent campaign for reaching out to the ideal audience to whom you can ask for help (guidance or referral).