Senior Application Security Analyst
Cencora
- Location
- Pune, India
- Work model
- On-Site
- Level
- Senior
- Posted
- 8h ago
Skills
About this role
Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!
Job Details
The primary responsibility of the individual will be to create a collection of application-tier security-controls and build top-of-the-line tools and applications that will aid in further securing IT assets for Cencora’s Technical-Administration organization. The candidate will exhibit proficiency in the following core requirements: · Operating System Skills: Linux (SUSE, RHEL, CentOS, Ubuntu) & Windows · Application-Tier security-architecture and administration for one of the following applications: o Middleware (such as IBM MQ and WebSphere Application Server) o EDI (such as Sterling B2B Integrator) o SAP Basis (Netweaver ABAP & Java) and S/4HANA · Proven track-record of o securing and hardening of platform-tier and application-tier o securing configuration of application-tier, deployments and integration o maintaining & remediating security algorithms and protocols (TLS, ciphers, ssh) o SAML and OAUTH solutions o LDAP/Active-Directory & ACL o encryption-at-rest & encryption-at-transit o automating Application-Security Testing (SCA, IAST, SAST, DAST, et cetera) o researching of vendor-provided (IBM or SAP) product-release notes, security-release notes, CVE/CVSS3 impact-assessments for applications o leadership in collaboration, with excellent verbal and written skills The candidate will have the following peripheral skills and knowledge: · Two or more of these skills: SecOps, Threat-Intelligence, Disaster-Recovery and Incident-Response, Vulnerability-Assessment, Pen-Testing & reporting · Web-building skills, or more of the following: Javascript, JSP, Ruby · Automation skills, one or more of the following: Python, bash shell, Perl, Ansible/AWX, Chef, Terraform PRIMARY DUTIES AND RESPONSIBILITIES: · Security Lead security-strengthening requirements for the business applications Pro-actively adhere to strict security standards & Best Practices set forth by various vendors (SAP & IBM) Pro-actively monitor & report application-impact due to security-vulnerabilities Make recommendations to improve security for Application-Tier · Information Security Administration Strategize and execute security-roadmap for business applications Lead initiatives for reports & tools on security updates & violations Continually assess and investigate threats to business applications Work with Information Security, where needed, in investigations and/or audits/assessments of systems · Design/Develop Lead & orchestrate the design & develop of tools to securely integrate in to business applications Automated application-tier validations after regular maintenance tasks Automated load & stress-tests · Policies, Procedures, and Standards Ensure compliance with policies, procedures and standards · Operating System Administration – procedural Generate processes to ensure appropriate user privileges and access are granted, ensuring data-integrity and security is met Work across teams to ensure OS system upgrades and service pack deployments are implemented with minimal impact to production operation Recommend updates to operating systems to deliver cost benefits without reducing production performance and availability Analyze data from monitoring activities and define comprehensive, system wide improvements Monitor performance and proactively identifies uptime issues, making recommendations for eliminating those issues Develop plans to adopt new technology EXPERIENCE