Take your next career step at NeSL with an amazing team that is energizing the transformation of Financial Institutions.
Requirements
- Hands-on experience in source code reviews, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and API security.
- 8+ years of experience out of which minimum 3+ years of experience in designing and implementing security solutions for Java-based applications and APIs.
- Understanding of Cryptography and implementation experience of the same.
- Deep understanding of secure coding standards and vulnerability remediation.
- Should have exposure toJava (Full Stack) based Software Development, Spring MVC, Spring Boot, Spring Security, Hibernate including secure software development practices.
Key Responsibilities:
- Ensure the security robustness of applications by promoting integration ofsecurity into the software development lifecycle (SDLC) by providing necessary inputs to the development team.
- Participate with SW Development teamin threat modelling, risk assessment and security design reviews.
- Work closely with SW development team for Implementing secure coding practices, tools, and DevSecOps processes.
- Act as a bridge between security and development, focusing on preventing breaches, not just reacting to them.
- Conduct manual and automated source code reviews to identify security vulnerabilities and coding issues.
- Integrate and manage SAST tools (e.g., SonarQube, Fortify, Checkmarx) within CI/CD pipelines.
- Analyse the Application Security Test reports and identify and eliminate possible false positives reported. If required coordinate with development team to confirm before elimination.
- Collaborate with Development teams to remediate vulnerabilities and implement secure coding practices.
- Ensure API security through proper authentication, authorization, rate limiting, and input validation.
- Coordinate withSoftware Developers in validating and mitigating observations in DAST assessments using tools like WebInspect, Burp Suite, OWASP ZAP, etc.
- Stay updated with the latest security trends, vulnerabilities, and mitigation techniques.
Required Qualifications:
- B.E./B.Tech. in CS/ IT/ ECE, MCA, M.Sc. CS/IT fulltime course from a reputed institute with a good academic track record.
- 8+ years of experience in Application security with exposure to SW development with a focus on secure coding.
- Experience with SAST/DAST tools and interpreting their results.
- Familiarity with API security standards (e.g., OAuth2, JWT, OpenAPI).
- Experience with DevSecOps practices and CI/CD integration.
- Understanding of OWASP Top 10, CWE, and other security frameworks.
- Understanding of secure authentication, authorization, and session management.
Preferred Qualifications:
- Certifications such as OCJP, CSSLP (ISC2), OSCP(OffSec).
- Exposure to secure SDLC frameworks and governance, such as OWASP SAMM and the NIST SSDF.
- Exposure to microservices deployments in east-west and north-south traffic preferred.
- Exposure containerization and orchestration technologies, including Docker and Kubernetes, for deploying and managing scalable, secure, and resilient applications in distributed environments.
- Exposure to the ISMS environment preferred
What we offer
An exciting work experience in a class apart company and industry leader whose mission is to provide a fully digital and superior experience in documentation, authentication, storage and access of financial and operational debt obligations in the country, held as evidence, through its entire journey starting from contract execution and to be the most complete and current information repository in the country for loans and debt obligations.
More About us
NeSL is India’s first Information Utility and is registered with the Insolvency and Bankruptcy Board of India (IBBI) under the aegis of the Insolvency and Bankruptcy Code, 2016 (IBC). The company has been set up by leading banks and public institutions. The primary role of NeSL is to serve as a repository of legal evidence holding the information pertaining to any debt/claim, as submitted by the financial or operational creditor and verified and authenticated by the parties to the debt.
We Value Diversity
At NeSL, we have the clear goal of driving diversity and inclusion across all dimensions: gender, abilities, ethnicity and generations. We welcome applications for employment from all qualified candidates, regardless of race, colour, gender, ethnic origin, age, disability, religion, gender identity or any other status projected by applicable law. We comply with all applicable laws in every jurisdiction in where we operate.
To Apply: Email your resume to hr@nesl.co.in with Subject line “Chief Manager – AppSec & Secure Development”
Last date to apply: 20 July 2026