Product Security Analyst

Company: OneTrust
Company: OneTrust
Location: Bangalore
Posted on: 2024-02-03 01:15
Strength in Trust  OneTrust is the trust intelligence cloud platform organizations use to transform trust from an abstract concept into a measurable competitive advantage. Organizations globally use OneTrust to enable the responsible use of data while protecting the privacy rights of individuals, implement and report on their cyber security program, make their social impact goals a reality, and create a speak up culture of trust. Over 14,000 customers use OneTrust's technology, including half of the Global 2,000. OneTrust currently ranks #24 on the Forbes Cloud 100 list of top private cloud companies in the world and employs over 2,000 people in regions across North America, South America, Asia, Europe, and Australia. The Challenge  As a Product Security Analyst, you will ensure the security and protection of our company's applications and systems .   You will work closely with our development teams to provide support on remediating vulnerabilities and to assess the security of new and existing applications. This is a critical role that is responsible for ensuring the security and integrity of our company's applications and systems.   Your Mission  Develop and maintain security testing plans   Execute and automate application testing using scripts, as well as open source and professional tools    Generate clear reports that outline the flaws detected during application testing     Conduct Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), and Software Composition Analysis (SCA) to identify vulnerabilities and security risks in the Software Development Life Cycle (SDLC)   Collaborate with development teams to remediate vulnerabilities, implement security improvements, and to integrate security into the Software Development Life Cycle (SDLC)   Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation   Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk   Maintain security documentation, including standards and procedures   You Are/Have   Self-motivated, curious, can learn on your own with little guidance and oversight     A good communicator, verbally and in writing   Strong analytical skills with a structured problem-solving approach   Your Experience Includes   Bachelor's degree in computer science, Information Systems, or related field   At least 3 years of experience in application security, with a focus on manual penetration testing and security testing tools   Experience working with security tools such as Burp Suite, Snyk, and Qualys   Good understanding of network protocols   Knowledge of security concepts such as network security, access controls, encryption, and vulnerability management   Strong understanding of web application security concepts, OWASP Top 10, SANS Top 25, OWASP API Top 10 and security standards such as PCI-DSS and ISO 27001   Knowledge of scripting languages such as Python and BASH is beneficial   Strong interpersonal and communication skills, with the ability to explain technical security concepts to non-technical stakeholders   Self-motivated, with the ability to work as part of a team   Demonstrated creativity in complex problem solving and ability to work under pressure   Benefits As an employee at  OneTrust , you will be part of the OneTeam . That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, remote or hybrid workplace flexibility, flexible PTO, equity stock options, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers. Resources   Check out the following to learn more about OneTrust and its people:  OneTrust Careers on YouTube @LifeatOneTrust on Instagram Your Data You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our  Privacy Overview .  You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the  Data Subject Request Form . Our Commitment to You   When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career   OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.
View Original Job Posting