Full-Time

Application & API Security Professional

Confirmed live in the last 24 hours

Marvell

Marvell

5,001-10,000 employees

Develops semiconductor solutions for data infrastructure

No salary listed

Expert

Company Historically Provides H1B Sponsorship

Hyderabad, Telangana, India + 1 more

More locations: Bengaluru, Karnataka, India

Category
Cybersecurity
IT & Security
Required Skills
PowerShell
Bash
REST APIs
Linux/Unix
Requirements
  • 8+ years of experience with Bachelor’s or Master’s degree in Information Technology or related field.
  • Knowledge and working experience in application threat modeling and remediation of OWASP API Top 10, CIS Top 10, SANS Top 25, etc.
  • Experience conducting risk assessments and performing threat modeling of applications.
  • Strong understanding of security vulnerabilities, web application security, and secure coding practices.
  • Hands-on experience performing application and API security assessments, static and dynamic security assessments with tools such as Burpsuite, OWASP ZAP, AppScan, WebInspect, Fortify, Veracode, Checkmarx, etc.
  • Knowledge of the SSDLC process and its components; Rest API technology and the API Gateway concept.
  • Being familiar with issues related to authorization, authentication, or session management (SAML, OAuth, SSO, etc.).
  • Experience with API management platforms, security tools, and security frameworks.
  • Experience with service-oriented architectures and web services security.
  • Has practical experience in auditing various OS, DB, Network, and Security technologies.
  • Strong understanding of Unix/Linux/Mac/Windows, operating systems, including bash and Powershell.
Responsibilities
  • Provide application security guidance to the IT teams and third parties involved in application development and maintenance.
  • Embed security practices into the Software Development Life Cycle (SDLC) and CI/CD pipelines.
  • Design Application and API security standards for Marvell, based on OWASP Top 10, OWASP API Top 10 and CIS Top 20.
  • Perform ongoing governance and follow-through with applications and API owners to ensure implementation of threat-based requirements.
  • Establish External web applications and API inventory management and governance at Marvell.
  • Develop and implement ongoing monitoring and incident response procedures for the existing and new APIs.
  • Validate implementation of application and API security controls against outputs of vulnerability testing tools to enable auditability and verifiability.
  • Collaborate with internal development teams to build/advocate security controls in Application Programming Interface (API), performing Threat Modeling, Static Application Security Testing (SAST), Software Composition Analysis(SCA).
  • Perform security risk assessments and audits for web applications and APIs.
  • Provide recommendations around security measures to protect applications and APIs from threats such as SQL injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.
  • Perform vulnerability risk profiling and prioritization of vulnerabilities.
  • Provide insight to management on common API misconfigurations, identify gaps in API development processes.
  • Support and consult with development and IT support teams in the areas of application and API security. Work with application and IT teams to review the application and API security architecture, API Gateway, WAF, and Firewall policies to block threat actors.
  • Educates development team on application and API security procedures and standards.
  • Stay up to date with the latest security threats, vulnerabilities, and industry best practices.
Desired Qualifications
  • Relevant certifications (OSCP, CISSP, CSSLP, GIAC GWAPT, CASP) will be an added advantage.

Marvell Technology, Inc. specializes in semiconductor solutions that support data infrastructure for various clients, including telecommunications operators and data centers. Their products focus on high-performance capabilities for computing, storage, and networking, which are essential for handling the increasing demands of mobile data and the shift to 5G networks. Marvell's offerings include programmable and scalable platforms that enhance network capacity and performance while reducing costs for telecommunications operators upgrading their infrastructure. Unlike many competitors, Marvell emphasizes a B2B model, selling their semiconductor products directly to businesses that integrate them into their own services. The company's goal is to provide efficient and secure data transmission, storage, and processing solutions to support the modern digital economy.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

Santa Clara, California

Founded

1995

Simplify Jobs

Simplify's Take

What believers are saying

  • Sale of Automotive Ethernet business provides $2.5 billion for core investments.
  • Growing demand for PCIe Gen 6 and Gen 7 in AI data centers.
  • Strategic focus on AI infrastructure aligns with expanding AI workloads.

What critics are saying

  • Increased competition from Infineon in automotive semiconductors post-division sale.
  • Departure of key executive Hussain may lead to leadership gaps.
  • Pressure to accelerate PCIe Gen 7 development to stay competitive.

What makes Marvell unique

  • Marvell leads in PCIe Gen 6 over optics for AI-driven data centers.
  • The company focuses on high-performance, scalable semiconductor solutions for 5G infrastructure.
  • Marvell collaborates with industry leaders like TeraHop for optical networking innovations.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Retirement Plan

401(k) Company Match

Flexible Work Hours

Paid Vacation

Hybrid Work Options

Company News

Financial Post
Apr 14th, 2025
Silver Lake Lines Up $2 Billion Debt Financing for Altera Deal

Hussain will join from Marvell Technology Inc., where he's president of products and technologies.

MarketScreener
Apr 8th, 2025
Infineon acquires automotive supplier business in the USA for 2.5 billion dollars

The Munich-based chip group Infineon wants to strengthen its business with the automotive industry with an acquisition worth billions in the USA. Infineon is taking over the car-related...

Handelsblatt
Apr 7th, 2025
Infineon Acquires Marvell's Automotive Division

Infineon, Germany's largest chip manufacturer, is strengthening its automotive business by acquiring a division of its US rival, Marvell Technology. This strategic move by the Munich-based company is aimed at preparing for the future of vehicles.

Markets Gone Wild
Apr 7th, 2025
Marvell Announces $2.5 Billion Cash Sale of Automotive Ethernet Business to Infineon

On April 7, 2025, the company revealed that it had entered into a definitive agreement under which Infineon Technologies AG, a leading global semiconductor manufacturer headquartered in Germany, will acquire Marvell's Automotive Ethernet business for a total cash consideration of $2.5 billion.

PR Newswire
Apr 6th, 2025
Marvell Demonstrates Industry'S First End-To-End Pcie Gen 6 Over Optics For Accelerated Infrastructure At Ofc 2025

Protocol-level PCIe Gen 6 Over 10m Optical Cable and PCIe Gen 7 SerDes Over Optics in Collaboration with TeraHop for AI Server Scale UpSANTA CLARA, Calif., March 27, 2025 /PRNewswire/ -- Marvell Technology, Inc. (NASDAQ: MRVL), a leader in data infrastructure semiconductor solutions, today announced in collaboration with TeraHop, a global optical solutions provider for AI driven data centers, the demonstration of the industry's first end-to-end PCIe Gen 6 over optics in the Marvell booth #2129 at OFC 2025. The demonstration will showcase the extension of PCIe reach beyond traditional electrical limits to enable low-latency, standards-based AI scale-up infrastructure.As AI workloads drive exponential data growth, PCIe connectivity must evolve to support higher bandwidth and longer reach. The Marvell® Alaska® P PCIe Gen 6 retimer and its PCIe Gen 7 SerDes technology enable low-latency, low bit-error-rate transmission over optical fiber, delivering the scalability, power efficiency, and high performance required for next-generation accelerated infrastructure. With PCIe over optics, system designers will be able to take advantage of longer links between devices that feature the low latency of PCIe technology.Marvell and TeraHop will demonstrate the industry's first successful transmission of PCIe Gen 6 signals between the root complex and endpoint across 10 meters of TeraHop OSFP-XD active optical cable using the Alaska P PCIe Gen 6 retimer integrated into a TeraHop-developed PCIe Gen 6 retimed riser card. By retiming and converting PCIe Gen 6 electrical signals into optical data, this solution ensures reliable high-speed connectivity between AI accelerators, CPUs, CXL-pooled memory, SSDs, and NICs, unlocking new possibilities for AI-driven data centers.Driven by an ever-increasing demand for AI, the industry is expecting the PCIe Gen 7 standard to be finalized this year