Home
/
Comprehensive
/
Senior Application Security Engineer
Senior Application Security Engineer-April 2024
Bangalore
Apr 18, 2025
About Senior Application Security Engineer

  Senior Application Security Engineer

  Role Purpose

  The Enterprise Application Security team is responsible for protecting Pearson’s commercial digital products and data, our learner’s data, and Pearson’s internal applications. By employing a blend of technology, developer training, test integration, and process automation, the Application Security team’s goal is to reduce our risks and provide ongoing Internet safe-havens for our learners.

  Within this team, the Senior Application Security Engineer is responsible for executing application-level security assessment (SAST/DAST/SCA/Manual Review/Threat Modeling) against various, complex applications which are developed inhouse and third parties, assess the risk of each application and communicate findings to wider business stakeholder audience.

  Responsibilities

  As a direct report to the Head of Application Security, you will have the following accountabilities:

  Closely working with the software development community and based on their own strong development background with prominent web or mobile development languages and frameworks; provide advanced security remediation advice directly to development and testing teams.

  Provide expert-level guidance to security analysts, testers, and development teams during application security assessments. Must be able to identify, re-create, and remediate security defects.

  Work with SAST/DAST/SCA/RASV tools and support Application Security BAU operations

  Flexibility to cross-skill and engage in other security domains such as Cyber Threat Management, Identity and Access Management, Cyber Transformation, Business Resilience and Data Loss Prevention and Privacy.

  Working knowledge of automated application security-related commercial and opensource tools

  Experience using and testing REST and/or SOAP APIs;

  Ability to prioritize and track security issues and work with the necessary teams to ensure remediation;

  Serve as a leader by promoting security awareness, mentoring other team members, and staying up to date on current development methodologies (Agile/DevOps);

  Embrace a culture of continuous service improvement and service excellence; and

  Stay up to date on security industry trends.

  Skills and Experience

  6+ years in the Information Security space.

  Strong software development background (Java, JavaScript, Python or any Microsoft technology)

  Strong experience with modern scripting languages

  In-depth understanding of OWASP framework and its practical usage

  Hands-on experience with Application-level penetration testing and tooling

  Strong experience with SDLC, modern development languages and frameworks, with a passion to make security realistic, achievable, and interwoven with the business fabric.

  Understanding of Cloud (AWS and Azure) platforms

  Strong oral, written, and presentation abilities - able to convey risk to all levels of the business, from C-level executives to operations and development teams.

  Strong understanding of web applications and architectures, relational and non-relational databases, and hardware architectures, and effectively applying the principles of information security to IT environments

  Experience with SAST/DAST/SCA/RASP tools

  Current understanding of Industry trends and emerging threats

  Basic understanding of Threat Modeling

  What to expect from Pearson

  Did you know Pearson is one of the 10 most innovative education companies of 2022?

  At Pearson, we add life to a lifetime of learning so everyone can realize the life they imagine. We do this by creating vibrant and enriching learning experiences designed for real-life impact. We are on a journey to be 100 percent digital to meet the changing needs of the global population by developing a new strategy with ambitious targets. To deliver on our strategic vision, we have five business divisions that are the foundation for the long-term growth of the company: Assessment & Qualifications, Virtual Learning, English Language Learning, Workforce Skills and Higher Education. Alongside these, we have our corporate divisions: Digital & Technology, Finance, Global Corporate Marketing & Communications, Human Resources, Legal, Strategy and Direct to Consumer. Learn more at We are Pearson.

  We value the power of an inclusive culture and also a strong sense of belonging. We promote a culture where differences are embraced, opportunities are accessible, consideration and respect are the norm and all individuals are supported in reaching their full potential. Through our talent, we believe that diversity, equity and inclusion make us a more innovative and vibrant place to work. People are at the center, and we are committed to building a workplace where talent can learn, grow and thrive.

  Pearson is an Affirmative Action and Equal Opportunity Employer and a member of E-Verify. We want a team that represents a variety of backgrounds, perspectives and skills. The more inclusive we are, the better our work will be. All employment decisions are based on qualifications, merit and business need. All qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, sexual orientation, gender identity, gender expression, age, national origin, protected veteran status, disability status or any other group protected by law. We strive for a workforce that reflects the diversity of our communities.

  To learn more about Pearson’s commitment to a diverse and inclusive workforce, navigate to: Diversity, Equity & Inclusion at Pearson.

  If you are an individual with a disability and are unable or limited in your ability to use or access our career site as a result of your disability, you may request reasonable accommodations by emailing [email protected].

  Note that the information you provide will stay confidential and will be stored securely. It will not be seen by those involved in making decisions as part of the recruitment process.

  Job: ENGINEERING

  Organization: Corporate Strategy & Technology

  Schedule: FULL_TIME

  Req ID: 14384

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Corporate Military Program
Description Please note that applications are for our April 2024 in-take (exact date TBC). Applications for our September in-take will open in Spring 2024 Amazon is excited to offer military service
Senior Manager, APJ Sales Planning, WW Commercial Sales
Description Amazon Web Services (AWS) is the leading cloud provider, offering virtualized infrastructure, storage, networking, messaging, analytics, and other web computing services to customers all
Koordinator*in für Arbeitssicherheit (m/w/d)
Description Unser fortwährendes Wachstum erfordert Jahr für Jahr ein intelligentes Arbeiten, das dazu beiträgt, Sicherheit, Zufriedenheit, Motivation und Engagement unserer Teammitglieder zu erhalten
Systems Development Manager, Managed Operations
Description Does the challenge that comes from leading and driving large, cross-organizational projects and initiatives for one of the largest Cloud providers excite you? Do you enjoy working in an e
Senior Software QA Engineer, Device OS
Description Amazon Lab126 is an inventive research and development company that designs and engineers high-profile consumer electronics. Lab126 began in 2004 as a subsidiary of Amazon.com, Inc., orig
Outside Sales Rep Construction Industry Exp
Job Description OverviewThe Outside Sales Representative (OSR) will customarily and regularly sell products and services offered by 84 Lumber to current and new clientele away from 84 Lumber stores a
Principal Technical Program Manager
Description Come build the future as a Principal Technical Program Manager at Amazon, where you will be inspired working alongside best-in-class inventors and innovators! You will have the opportunit
Pharmacy Technician
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced
Network Deployment Engineer II, Amazon Dedicated Cloud
Description Amazon Web Services (AWS) is looking for a Network Deployment Engineer to build Amazon Dedicated Cloud regions as part of our Infrastructure Operations team. As dedicated cloud regions co
Restaurant Manager
Overview A Restaurant Manager is generally responsible for providing strong, positive leadership to his/her team to deliver great and friendly guest experiences, operational excellence and for helpin
Copyright 2023-2025 - www.zdrecruit.com All Rights Reserved