← к выдаче
безопасность

Senior Security Lead / Security Architect

ZensarIN10 дн. назад

Коротко

Leads security testing team; defines strategies for Web, Mobile, API, and MCP applications; performs assessments, threat modeling, and secure code review. · Needs: Hands-on MCP security testing experience; knowledge of OWASP Top 10 for LLM applications; experience with Burp Suite, OWASP ZAP, MobSF, Snyk.

Описание от работодателя

Key Responsibilities Lead and manage a team of security testers across multiple projects. Define and implement security testing strategies for Web, Mobile, APIs, and MCP-based applications. Perform and oversee security assessments including: MCP Security Testing Web Application Penetration Testing Mobile Application Security Testing (Android & iOS) API Security Testing Secure Code Review Threat Modeling Review MCP architecture, connector integrations, tool invocation mechanisms, and AI-agent interactions for security risks. Identify vulnerabilities related to: Prompt Injection Tool Poisoning Unauthorized Tool Access Data Leakage Excessive Permissions Authentication & Authorization Flaws Insecure Context Sharing AI Agent Abuse Scenarios Conduct security reviews for AI/LLM-enabled applications and MCP ecosystems. Provide remediation recommendations and work closely with development and architecture teams. Prepare security assessment reports and executive-level risk summaries. Participate in customer discussions, audits, and security governance meetings. Mentor and guide junior security testers and security engineers. Required Skills MCP & AI Security Strong hands-on experience in MCP (Model Context Protocol) Security Testing. Understanding of MCP architecture, MCP servers, clients, tools, prompts, and resources. Experience identifying AI and MCP-specific security risks. Experience testing AI Agents, Copilot solutions, Agentic workflows, RAG systems, and LLM integrations. Knowledge of OWASP Top 10 for LLM Applications and AI Security best practices. Application Security Web Application Security Testing. Mobile Application Security Testing (Android/iOS). API Security Testing. Secure Code Review. Threat Modeling and Risk Assessment. Authentication, Authorization, SSO, OAuth2, OpenID Connect, SAML. Security Tools Burp Suite Enterprise/Professional. OWASP ZAP. MobSF. Appknox Snyk, Checkmarx, Veracode, Fortify or equivalent SAST tools. Postman, Swagger. SIEM and vulnerability management platforms. Security Standards OWASP Top 10. OWASP API Security Top 10. OWASP Mobile Top 10. OWASP LLM Top 10. NIST Secure Development Framework. PCI-DSS, SOC2, ISO 27001 awareness. Leadership Responsibilities Manage and mentor a team of 4–5 security professionals. Drive resource planning, estimations, and project execution. Establish security testing frameworks, processes, and governance. Conduct technical reviews and support practice development initiatives. Support presales, solutioning, and client presentations. Preferred Qualifications Bachelor's or Master's degree in Computer Science, Cyber Security, or related field. Security certifications such as: CISSP OSCP CEH GWAPT CompTIA Security+ GIAC Certifications Experience working with enterprise AI solutions, Microsoft Copilot ecosystem, and MCP-based platforms is highly preferred. Key Competencies Strong leadership and stakeholder management skills. Excellent client-facing communication. Security architecture and consulting mindset. Problem-solving and analytical thinking. Ability to drive multiple security engagements simultaneously.