Free cookie consent management tool by TermsFeed Sr Software Engineer - VM | Antal Tech Jobs
Back to Jobs
7 Weeks ago

Sr Software Engineer - VM

decor
Pune, Maharashtra, India
Information Technology
Full-Time
Houghton Mifflin Harcourt

Overview

HMH is a learning technology company committed to delivering connected solutions that engage learners, empower educators and improve student outcomes. As a leading provider of K–12 core curriculum, supplemental and intervention solutions, and professional learning services, HMH partners with educators and school districts to uncover solutions that unlock students’ potential and extend teachers’ capabilities.
HMH serves more than 50 million students and 4 million educators in 150 countries. HMH Technology India Pvt. Ltd. is our technology and innovation arm in India focused on developing novel products and solutions using cutting-edge technology to better serve our clients globally. HMH aims to help employees grow as people, and not just as professionals.
We are seeking a Senior Security Engineer who will be responsible for identifying and mitigating vulnerabilities in our codebase by leveraging static analysis tools and techniques. The ideal candidate will have a strong background in application security, a deep understanding of SAST tools, and a passion for ensuring secure software development practices. This role will lead the task of refining, managing and executing strategic product/application security roadmap that is based on industry standard software security frameworks. You will plan, implement and track key initiatives focused on product / application security strategy, metrics, compliance, policy, developer awareness, training and stakeholder engagement. You should be comfortable communicating security directives to all employees including but not limited to Team Members, Leadership and Executives when required. You will work closely with multiple teams that make up Information Security, Product Management, Engineering, Legal, Risk and Compliance to improve product / application security controls and drive impactful change to the team and its members.

Duties & Responsibilities include:
Work closely with Application, Systems and Network engineering teams on the design, development, and operation of secure online services
Proficient in analyzing ambiguous problems, compelling communicator with the ability to receive and analyze information, translating security risk to business risk to driving actionable decisions across multiple levels and departments
Work on leading application security remediation work, leading the mitigation initiative to accommodate the developer community priority
Address & mitigate exploits and attack vectors for vulnerabilities such as SQL injection, XSS, CSRF, session hijacking and other OWASP vulnerabilities.
Working knowledge of Identification and Validation of Security vulnerabilities in Application
Work on security incident response and forensics investigation activities
Work on Network/Application security vulnerability assessment and management
Work on regulatory requirements and ability to implement technical aspects and other compliance standards where applicable.
Review and monitoring of cloud infrastructure, physical infrastructure, and the full life cycle of security alerts etc. through incident response.
Work as an internal advocate to ensure securing data, systems, applications, and networks in accordance with security best practices
Perform various IT system support and tasks as needed specific to the areas of security
Work independently and efficiently to meet deadlines
Stay abreast of latest cyber security threats both internal and external
Support and implement controls and visibility to meet third party attestations (SOC2, ISO27001, GDPR, SOX)
Qualifications Experience of working in a collaborative, agile development environment as a team player Good communication (oral and written), interpersonal, organizational, and presentation skills with an ability to represent complex data in executive level graphical reporting dashboards. Highly organized in doing communication with multiple teams with strong organizational skills 2+ years of application architecture or development experience having familiarity and understanding of web application development framework [ React, NodeJS, Angular, Spring, MVC etc.] Strong knowledge of both cloud and on-premises platforms coupled with hands-on experience working with major cloud providers such as AWS, Azure, and GCP. Strong knowledge of both cloud and on-premises platforms, security, and tools (e.g., PaaS, IasS, SaaS) and support AWS shared services components 3+ years of hands-on experience with vulnerability assessment tools used as SAST, DAST, IAST, RASP and WAF. (e.g., Snyk, Orca, Rapid7, CrowdStrike, Mitiga, Imperva WAF) Familiarity and understanding of modern web application development with good experience in HTML/CSS/ React/AngularJS Working knowledge of Identification and Validation of Security vulnerabilities in Application, common web application attack vectors, understanding the risks, and developing mitigation plans. 3+ years of experience with security infrastructures within cloud environments Experience in leading application security remediation work, leading the mitigation initiative to accommodate the developer community priority. Knowledge of Scripting or programming experience in languages such as Python, Shell/BASH scripting etc. Understanding of encryption and authentication technologies. Spring/MVC and Spring filter development and J2EE design patterns and IOC 2+ years scripting or programming experience in Python, Shell/BASH scripting, or other languages. Having prior experience on any other languages (e.g., Java, C/C++, Perl) is nice to have Familiarity and understanding of some of modern web application development framework [ e.g., React, NodeJS, Angular, Spring, MVC etc.] is nice to have Experience with SIEM tools such as Splunk, Sumo Logic etc. is nice to have Have good experience with security infrastructures both cloud and non-cloud infrastructure (Traditional Data Centers) Understanding of CIS, NIST or ISO 27001 managed framework Understanding of encryption and authentication technologies Prior experience in Design, develop, and debug secure software for externally facing corporate web sites within Web Content Management framework is nice to have. Have Prior Experience on Kubernetes, microservice architecture is nice to have

HMH Technology Private Limited is an Equal Opportunity Employer and considers applicants for all positions without regard to race, colour, religion or belief, sex, age, national origin, citizenship status, marital status, military/veteran status, genetic information, sexual orientation, gender identity, physical or mental disability or any other characteristic protected by applicable laws. We are committed to creating a dynamic work environment that values diversity and inclusion, respect and integrity, customer focus, and innovation.

Share job
Similar Jobs
View All
1 Day ago
TrueFan - Senior Machine Learning Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
About UsTrueFan is at the forefront of AI-driven content generation, leveraging cutting-edge generative models to build next-generation products. Our mission is to redefine content generation space through advanced AI technologies, including deep ge...
decor
1 Day ago
Salesforce commerce cloud consultant
Information Technology
  • Thiruvananthapuram, Kerala, India
Salesforce Commerce Cloud consultant  5+ Years of Experience 6 to 12 months Mode - Remote 1.1LPM - 1.2LPM Max Key Responsibilities Translate business requirements into scalable Salesforce Service Cloud solutions, in collaboration with CAE's technic...
decor
1 Day ago
Cloud Infrastructure Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
DescriptionInvent the future with us. Recognized by Fast Company’s 2023 100 Best Workplaces for Innovators List, Ampere is a semiconductor design company for a new era, leading the future of computing with an innovative approach to CPU design focuse...
decor
1 Day ago
Devops Engineer- Intermetiate
Information Technology
  • Thiruvananthapuram, Kerala, India
BackJD: Dev ops Engineer:As a DevOps Specialist- should be able to take ownership of the entire DevOps process, including Automated CI/CD pipelines and deployment to production.They should also be comfortable with risk analysis and prioritization.Le...
decor
1 Day ago
Sr Data Scientist (London)
Information Technology
  • Thiruvananthapuram, Kerala, India
AryaXAI stands at the forefront of AI innovation, revolutionizing AI for mission-critical, highly regulated industries by building explainable, safe, and aligned systems that scale responsibly. Our mission is to create AI tools that empower research...
decor
1 Day ago
Software Test Engineer
Information Technology
  • Thiruvananthapuram, Kerala, India
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further att...
decor
1 Day ago
Software Developer 5 (Java Fullstack)
Information Technology
  • Thiruvananthapuram, Kerala, India
Job DescriptionBuilding off our Cloud momentum, Oracle has formed a new organization - Oracle Health Applications & Infrastructure. This team focuses on product development and product strategy for Oracle Health, while building out a complete platfo...
decor
1 Day ago
Java Developer - Spring Frameworks
Information Technology
  • Thiruvananthapuram, Kerala, India
Java DescriptionWe are looking for a passionate and talented Java Developer with 2-3 years of hands-on experience to join our growing development team.The ideal candidate should have a strong foundation in Java technologies and the ability to develo...
decor

Talk to us

Feel free to call, email, or hit us up on our social media accounts.
Social media