Application Security Analyst Lead
4 days ago
Who we are
NTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.
What you'll be doing
- Conduct security assessments for web apps, APIs, and mobile apps under limited supervision.
- Perform OWASP Top 10 and advanced penetration testing (authenticated/unauthenticated).
- Assess API security (REST, GraphQL, SOAP) and test auth, session management, and access controls.
- Identify business logic flaws and exploit vulnerabilities.
- Perform manual/automated secure code reviews across multiple languages.
- Identify vulnerabilities (injection, XSS, insecure dependencies) and review architecture for weaknesses.
- Analyze third-party libraries, cryptographic implementations, and secure data handling.
- Provide actionable remediation guidance and secure coding recommendations.
- Assess iOS/Android apps, including reverse engineering and binary analysis.
- Test data storage, transmission, backend APIs, and mobile authentication mechanisms.
- Evaluate permissions, intents, IPC, and mobile-specific vulnerabilities (e.g., insecure storage).
- Integrate security testing into CI/CD pipelines and DevOps workflows.
- Configure and optimize SAST, DAST, and SCA tools; develop automation scripts.
- Implement security gates, reusable test cases, and support shift-left security initiatives.
- Analyze findings, determine risk severity, and produce detailed reports with remediation guidance.
- Validate fixes post-remediation, track findings to closure, and maintain vulnerability metrics.
- Present results to development teams and management.
- Review application designs for weaknesses against OWASP ASVS and security standards.
- Evaluate authentication/authorization models, data flows, and threat models.
- Support secure design workshops and threat modeling sessions.
What you'll bring along
- Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field
- Minimum 5–10 years of experience in cybersecurity or IT security roles.
- Strong knowledge of OWASP Top 10, OWASP ASVS, and web application security principles
- Solid experience with web application penetration testing tools and methodologies
- Proficiency in identifying and exploiting common application vulnerabilities
- Understanding of API security testing for REST, GraphQL, SOAP, and microservices
- Knowledge of mobile application security testing for iOS and Android platforms
- Programming languages: Java, .NET (C#), Python, JavaScript, TypeScript, PHP
- Web frameworks: Spring, Django, Flask, , React, Angular,
- Mobile development: Swift, Kotlin, React Native, Flutter basics
- Scripting: Python, Bash, PowerShell for security automation
- Database security: SQL injection, NoSQL security, ORM security issues
- Web testing: Burp Suite Professional, OWASP ZAP, Postman, SQLMap
- Code analysis: SonarQube, Checkmarx, Fortify, Veracode, Semgrep
- Mobile testing: MobSF, Frida, Objection, APKTool, iOS security tools
- Dependency scanning: OWASP Dependency-Check, Snyk, WhiteSource
- Automation: Selenium, Jenkins, GitLab CI/CD, custom Python scripts
- Deep understanding of OWASP Testing Guide and Application Security Verification Standard
- Knowledge of PCI DSS application security requirements
- Familiarity with secure SDLC practices and DevSecOps principles
- Understanding of threat modeling methodologies (STRIDE, PASTA, LINDDUN)
- Awareness of privacy-by-design and secure coding standards
- Clear technical communication with developers and non-technical stakeholders
- Ability to explain complex vulnerabilities and provide practical remediation guidance
- Collaboration skills for working with development, DevOps, and product teams
- Analytical thinking and creative approach to finding security weaknesses
- Patience and persistence in thorough security testing activities
- OSCP (Offensive Security Certified Professional) or CEH (Certified Ethical Hacker) - Mandatory
- GWAPT (GIAC Web Application Penetration Tester) or equivalent web app security cert - Preferred
- Burp Suite Certified Practitioner
- Programming or development certification
- Excellent command of both spoken and written English.
-
Application Security Analyst Lead
4 days ago
Sibiu, Sibiu, Romania NTT DATA Full time 40,000 - 80,000 per yearLocation:Sibiu, RO Iasi, RO Timisoara, RO Cluj, RO Bucuresti, RO Brasov, ROWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingConduct security...
-
Application Security Analyst
4 days ago
Sibiu, Sibiu, Romania NTT DATA Full time 15,000 - 30,000 per yearLocation:Sibiu, RO Brasov, RO Timisoara, RO Cluj, RO Iasi, RO Bucuresti, ROWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingAssist in web app security...
-
Application Security Analyst
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time €15,000 - €30,000 per yearWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingAssist in web app security testing under supervision; perform automated scans and basic OWASP Top 10...
-
Application Security DevSecOps Specialist
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time 50,000 - 80,000 per yearWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingIncorporate security controls and standards into all phases of the software development lifecycle...
-
Security Analyst Junior
4 days ago
Sibiu, Sibiu, Romania NTT DATA Full time 20,000 - 25,000 per yearLocation:Sibiu, RO Cluj, RO Iasi, RO Timisoara, RO Brasov, RO Bucuresti, ROWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingAssist senior team members...
-
Security Analyst Junior
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time 15,000 - 30,000 per yearWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingAssist senior team members with basic web app security testing under close supervision.Execute...
-
Vulnerability Analyst
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time 45,000 - 60,000 per yearWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingConduct vulnerability assessments using tools like Nessus, Qualys, Rapid7, and OpenVAS.Perform manual...
-
Security Engineer
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time 55,200 - 104,800 per yearWho we areNTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.What you'll be doingOperate and maintain security platforms in accordance with agreed Service Level Agreements (SLAs) as...
-
Chief Security Officer
4 days ago
Sibiu, Sibiu, Romania NTT DATA Europe & Latam Full time 90,000 - 120,000 per yearWho We AreBy joining our project, you will be working on an initiative of the European Commission focused on creating a more efficient, modern and secure customs environment within the European Union. Being part of this initiative set on a 5 years' timeline, you will have the opportunity to work on topics such as digitalization of customs processes,...
-
Chief Security Officer
4 days ago
Sibiu, Sibiu, Romania NTT DATA Romania SA Full time €60,000 - €120,000 per yearWho we areBy joining our project, you will be working on an initiative of the European Commission focused on creating a more efficient, modern and secure customs environment within the European Union. Being part of this initiative set on a 5 years' timeline, you will have the opportunity to work on topics such as digitalization of customs processes,...