Assistant Manager - Global Information Security
Tata Communications · Chennai
- Experience5–10 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted21 Sept 2026
About Tata Communications
Tata Communications is hiring in Chennai in telecom. This role looks for around 5+ years of experience.
Skills
- Application Security
- SAST
- SCA
- DAST
- VAPT
- Penetration Testing
- Secure Code Review
- Threat Modeling
- API Security
- Secure SDLC
- CI/CD security integration
- OWASP Top 10
- OWASP ASVS
- SANS Top 25
- DevSecOps
- Cloud Security
- Vulnerability management
- Agile
- DevOps
- Cloud-native environments
- Java
- .NET
- Python
- JavaScript
- Node.js
- Go
- YAML
- Shell scripting
- Linux/Unix
- Black Duck
- Checkmarx
- Snyk
- Fortify
- Burp Suite Professional
- OWASP
- NIST
- ISO 27001
- PCI DSS
- Security architecture
- CSSLP
- GWAPT
- GWEB
- CASE
- OSCP
- eWPT
- CEH
- CISSP
- CCSP
- Security+
The role
An application security engineer at a telecommunications connectivity company embeds Application Security across the SDLC and secures web, mobile, API, microservices, and cloud-native applications through Threat Modeling, Secure Code Review, and DevSecOps, while applying OWASP Top 10 and CI/CD security integration.
Full job description
About The Company
Tata Communications Redefines Connectivity with Innovation and IntelligenceDriving the next level of intelligence powered by Cloud, Mobility, Internet of Things, Collaboration, Security, Media services and Network services, we at Tata Communications are envisaging a New World of Communications
Broad Outline of the Role
Responsible for embedding application security across the SDLC, identifying and mitigating vulnerabilities, conducting security assessments, and driving DevSecOps initiatives. The role requires hands-on expertise in SAST, SCA, DAST, VAPT/Penetration Testing, Secure Code Review, Threat Modeling, and Application Security governance across web, mobile, API, microservices, and cloud-native applications.
Minimum Qualifications & Experience
Bachelor’s/Master’s degree in Computer Science, Cyber Security, Information Security, IT, or related engineering discipline.5–10 years of cybersecurity experience, including minimum 5 years in Application Security.Hands-on experience in SAST, SCA, DAST, VAPT, Secure Code Review, Threat Modeling, API Security, Secure SDLC, and CI/CD security integration.Strong knowledge of OWASP Top 10, OWASP ASVS, SANS Top 25, DevSecOps, Cloud Security, and vulnerability management.Experience in large enterprise, Agile, DevOps, and cloud-native environments, including management of security testing and vulnerability remediation.Working knowledge of Java, .NET, Python, JavaScript, Node.js, Go, YAML, Shell scripting, and Linux/Unix.
Other Knowledge & Skills
Hands-on experience with Black Duck, Checkmarx, Snyk, Fortify, and Burp Suite Professional; exposure to Veracode, SonarQube, OWASP ZAP, GitHub Advanced Security, Prisma Cloud, Qualys, Tenable, and Acunetix is advantageous.Knowledge of OWASP, NIST, ISO 27001, PCI DSS, secure development frameworks, security architecture, and emerging threats/vulnerabilities.Strong analytical, problem-solving, communication, documentation, stakeholder management, and cross-functional collaboration skills.Ability to assess security findings, identify false positives, prioritize risk, and provide practical remediation guidance.Preferred certifications: CSSLP, GWAPT, GWEB, CASE, OSCP, eWPT, CEH, CISSP, CCSP, Security+, or equivalent.Self-driven, security-first mindset with continuous learning and ability to drive security adoption.Key ResponsibilitiesPerform manual and automated SAST, SCA, DAST, VAPT/Penetration Testing, and Secure Code Reviews across web, mobile, API, microservices, cloud-native, and enterprise applications.Identify, validate, prioritize, track, remediate, and retest vulnerabilities; provide secure coding and remediation guidance.Integrate and maintain security tools and security gates within CI/CD pipelines and drive shift-left/DevSecOps practices.Conduct/support Threat Modeling, Security Architecture Reviews, Application Risk Assessments, and secure design reviews.Collaborate with Development, QA, DevOps, Architecture, Cloud, and Security teams to embed security throughout the SDLC.Administer and optimize Application Security tools, onboard applications/repositories, improve scan coverage, and reduce false positives.Develop and maintain Application Security policies, standards, procedures, baselines, and developer secure coding awareness/training.Ensure compliance with organizational requirements and OWASP, NIST, ISO 27001, PCI DSS, and applicable secure development standards.Track and report security posture, vulnerability aging/remediation, exceptions, trends, dashboards, and management metrics.Drive KPIs including Critical/High vulnerability reduction, remediation closure, assessment coverage, CI/CD security-gate adoption, SLA compliance, and secure coding compliance.