Security Engineer - GCP, AWS,Azure - Chennai

Posted 24 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Agency • Information Technology
The Role
Lead software security for web and mobile applications: perform vulnerability assessments and pentests, manage remediation, prepare teams for PCI-DSS audits, embed security into SDLC/DevOps, develop controls, run training, and lead incident response.
Summary Generated by Built In

Job description 

We are seeking a highly skilled and experienced Software Security Lead to join the web and mobile application development and engineering team for a leading name in the food and beverage market with 500+ stores worldwide. This person will play a crucial role in ensuring that the software and development processes adhere to those industry security standards and those defined by the company. The role requires a blend of both hands-on technical expertise in vulnerability assessment and penetration testing, as well as experience in defining and implementing new security controls and processes and ensuring that cross-functional team members are fully aware of these processes and how to comply with them.


Key Responsibilities 

  • Perform periodic vulnerability assessments across web and mobile applications; define the scope, prepare a test plan with timelines, create test cases for business logic testing, and obtain sign-off for deliverables. 
  • Assist with scoping, co-ordination and operation of routine third-party penetration testing activities.
  • Validate and prepare vulnerability assessment and penetration testing results for remediation, ensuring the development team are aware of their significance.
  • Manage the remediation of security vulnerabilities with the relevant development teams, following through from notification and support to completion.
  • Prepare development teams for annual PCI-DSS audit, collecting relevant documentation and evidence as necessary
  • Provide training sessions and workshops to educate cross-functional development teams on security standards and processes that must be followed.
  • Establish and maintain security processes throughout the software development lifecycle, and ensure that these are well implemented into DevOps security practices and CI/CD pipelines. 
  • Assist with development and implementation of new security controls to protect software systems from threats.
  • Lead the response to any security incidents that may arise within the software development environment.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, or a related field
  • Having a certification background in any one of GCIH, GCIA, GPEN, OSCP or other relevant certifications within Cyber Security is highly advantageous.
  • Several years of experience in software security and experience of securing cloud-based services/environments (GCP, AWS, Azure), technologies, and providers (e.g. SaaS, IaaS, PaaS) that expand at a rapid scale.
  • Demonstrated experience using a variety of security tools and processes to perform vulnerability assessments such as Nmap, Metasploit, Kali Linux, Burp Suite. 
  • Ability to perform vulnerability assessments against iOS and Android applications and when new product designs are implemented. Experience in iOS and Android development is advantageous.
  • Must have knowledge of detecting attacks through jailbreaking, resource encryption, check-summing, debugger detection, swizzle detection, hook detection and other means.
  • Experience identifying application attack vectors and strong knowledge of common vulnerabilities (e.g. OWASP Top 10).
  • Strong understanding of defending applications against compromise via a range of techniques including advanced obfuscation, pre-damage, string encryption, symbol stripping, renaming, debug Info, call hiding.
  • Proficiency with security tools and technologies such as web application firewalls, intrusion detection systems, encryption and vulnerability scanning tools
  • Good understanding of security operations, network security, threat intelligence, and incident response.
  • Strong technical knowledge across a range of server and gateway platforms, including Linux/ Unix/Windows/ Mac
  • Demonstrable knowledge and experience of scripting/programming tools such as PowerShell, Python, SQL.
  • Ability to perform analysis of log files from multiple devices and environments and identify indicators of security threats. Strong understanding of parsing and analyzing web, system and security logs is desired.
  • Familiarity with security frameworks and standards (e.g. NIST, ISO 27001, OWASP and PCI DSS)
  • Experience in defining and implementing security controls and processes, ideally within application and software development. Experience in proactive issue detection, tool creation, development of best practices and procedures and policy development.
  • Excellent verbal and written communication skills; able to explain the significance of technical vulnerability assessment and penetration testing findings to non-security team members; experience in documenting new process and policies.
  • Ability to offer security guidance to product teams as they build new mobile products and features.
  • Must be able to effectively work with and interact with teams of various backgrounds and maintain positive relationships; be able to work in a collaborative team environment.

Skills Required

  • Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, or related field
  • Certification in GCIH, GCIA, GPEN, OSCP or other relevant cybersecurity certs
  • Several years of experience in software security and securing cloud-based services/environments (GCP, AWS, Azure)
  • Experience using security tools for vulnerability assessment (Nmap, Metasploit, Kali Linux, Burp Suite)
  • Ability to perform vulnerability assessments against iOS and Android applications
  • Experience in iOS and Android development
  • Knowledge of detecting attacks via jailbreaking, encryption checks, debugger/swizzle/hook detection
  • Experience identifying application attack vectors and knowledge of OWASP Top 10
  • Understanding defensive techniques (obfuscation, string encryption, symbol stripping, debug info handling)
  • Proficiency with web application firewalls, intrusion detection systems, encryption and vulnerability scanning tools
  • Understanding of security operations, network security, threat intelligence, and incident response
  • Strong knowledge across server and gateway platforms: Linux/Unix/Windows/macOS
  • Experience with scripting/programming tools such as PowerShell, Python, SQL
  • Ability to analyze logs from multiple devices/environments and identify security indicators
  • Familiarity with security frameworks and standards (NIST, ISO 27001, OWASP, PCI DSS)
  • Experience defining and implementing security controls and processes in application/software development
  • Excellent verbal and written communication; ability to document processes and explain findings to non-security stakeholders
  • Ability to work collaboratively across cross-functional teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
5,017 Employees
Year Founded: 2007

What We Do

Photon.com has emerged as one of the world’s largest and fastest-growing Digital Agencies. We work with 40% of the Fortune 100 on their Digital initiatives and are known for our ability to integrate Strategy Consulting, Creative Design, and Technology at scale. Please visit www.photon.com to learn more about us, how we work, and our customer case studies. Digital Transformation Starts Here.

Similar Jobs

Capco Logo Capco

Data Engineer

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

CSC Logo CSC

Senior Payroll Analyst

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
2 Locations
8500 Employees

Comcast Logo Comcast

Data Analyst

Digital Media • Information Technology • News + Entertainment
Hybrid
Chennai, Tamil Nadu, IND
115000 Employees

Comcast Logo Comcast

Engineer 2 - Machine Learning

Digital Media • Information Technology • News + Entertainment
Hybrid
Chennai, Tamil Nadu, IND
115000 Employees

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account