Company

Cnh IndustrialSee more

addressAddressGurgaon, Haryana
type Form of work  Full Time
CategorySecurity

Job description

CNH is building the next generation of connected vehicles and equipment, which will create new experiences and make our products smarter. To defend and secure our broad technical environment we are seeking an experienced and passionate Off Board Security Architect (Application Security).

In this role you will:

·Serve as a Subject Matter Expert (SME) in Application Security and CI/CD best practices and contribute as a member of the technical solutions team

·Identify potential security risks and vulnerabilities and work proactively to mitigate risks and enhance end to end security posture across the CNH Application landscape

·Create and maintain software Application Security policies and procedures, including secure software development guidelines, vulnerability management program and risk mitigation guidelines

·Enhance Application Security activities such as Vulnerability Scanning, Certificate Management, Data Analysis of security monitoring outputs, coordination of Remediation Patching,

...

CNH is building the next generation of connected vehicles and equipment, which will create new experiences and make our products smarter. To defend and secure our broad technical environment we are seeking an experienced and passionate Off Board Security Architect (Application Security).

In this role you will:

·Serve as a Subject Matter Expert (SME) in Application Security and CI/CD best practices and contribute as a member of the technical solutions team

·Identify potential security risks and vulnerabilities and work proactively to mitigate risks and enhance end to end security posture across the CNH Application landscape

·Create and maintain software Application Security policies and procedures, including secure software development guidelines, vulnerability management program and risk mitigation guidelines

·Enhance Application Security activities such as Vulnerability Scanning, Certificate Management, Data Analysis of security monitoring outputs, coordination of Remediation Patching, and other daily Security and Compliance efforts[VV(I1]

·Design, implement, and maintain CI/CD pipelines for DevSecOps projects

·Support the operationalization of cloud hosted applications, while pursuing maturation of the delivery tech stack with a flexible framework to ensure easy changes in the future

·Work within cross-functional teams and apply diverse AppSec skill sets to support successful performance across operations and projects

·Work with software developers and software engineers to ensure that development follows established security processes and works as intended

·Generate and maintain programmatic and technical security documentation

·Monitor current and proposed laws, regulations, industry standards and ethical requirements related to privacy and information security for CNH products and services

·Drive work effort estimation & story pointing that aligns user/business goals through an Agile project

·Provide business and technical advice on a wide variety of risk issues, concerns, and problems, making sure all business processes incorporate adequate information security

Requirements and Qualifications:

·Degree in computer science, computer engineering, or technology-related field

·Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or other similar credentials

·3+ years of experience in cyber security roles, with background in software security or development

·3+ years experience with CI/CD Automation tools such as Azure DevOps, Jenkins and GitLab

·3+ years experience with API Security, Container Security, or Microsoft Azure Cloud Security

·3+ years experience working with Developers, DevOps, and Engineering teams in a dynamic environment to promote/implement the DevSecOps program throughout the organization

·3+ years experience coordinating and performing vulnerability assessments using automated or manual tools (Rapid7, NMAP, Fortify, etc.).

·2+ years experience with Information Security frameworks/standards (i.e. CIS, NIST, OWASP, etc.).

·2+ years experience with Windows and Linux patch management and related information security functions (authentication, encryption, iptables, SSL, Ciphers, etc.)

·2+ years experience and demonstrated hands-on experience in using SAFe Project Management tools (such as Jira), value streams, and Lean-Agile metrics

·1+ year experience with Go Programming and Bash, Python, or other scripting languages.

Jfrog XRAY, SonarCloud, SonarQube, Dashboarding tools, Risk Analysis, “Securization” process – Bringing a non- secure team into the security framework i.e. transitioning from a DevOps to a DevSecOps environment

Refer code: 949867. Cnh Industrial - The previous day - 2024-03-11 01:12

Cnh Industrial

Gurgaon, Haryana
Popular Security Architect jobs in top cities

Share jobs with friends

Related jobs

Off Board Security Architect - Application Security

Security Technical Architect

Ntt Data Inc.

Gurgaon, Haryana

2 months ago - seen

Manager - Security Architect (5-10 yrs)

Vanshika Munshi

Gurgaon, Haryana

2 months ago - seen

Security Architecture Design-Security Architect

Mygwork

Gurgaon, Haryana

4 months ago - seen