Senior Lead Engineer - Security Consultant

Posted 14 Days Ago
Be an Early Applicant
Joka, Kolkata, West Bengal, IND
In-Office
Senior level
Artificial Intelligence • Internet of Things • Software • Energy
The Role
Lead design and implementation of enterprise application, cloud, and infrastructure security. Embed AppSec and DevSecOps controls (SAST/DAST/SCA) into CI/CD, perform risk and vulnerability assessments, design secure architectures, lead SIEM deployments, support incident response and compliance (NIST, ISO 27001, PCI DSS, GDPR), and provide security guidance and training to stakeholders.
Summary Generated by Built In
The Security Consultant is responsible for assessing, designing, implementing, and maintaining information security controls to protect organizational systems, networks, and data. The role ensures compliance with security standards, manages cyber risks, and supports secure digital transformation initiatives.

Key Responsibility: 

1.       Security Assessment & Risk Management

  • Architect  enterprise-wide Application Security (AppSec) programs across complex, distributed enterprise environments—embedding SAST, DAST, and SCA into CI/CD pipelines to enable secure-by-design architecture and reduce vulnerabilities.
  • Define secure architecture patterns and guardrails, integrating AppSec controls into DevSecOps pipelines to standardize risk management across distributed engineering teams.
  • Collaborated with Customer Security teams to embed security architecture principles to produce secure project environment.
  • Experience in Application Security  governance frameworks, aligning with NIST, ISO 27001, and PCI DSS to achieve compliance posture and audit readiness
  • Conduct security risk assessments, vulnerability assessments, and threat modeling across applications, infrastructure, and networks.
  • Identify security gaps and provide risk-based mitigation recommendations.
  • Perform periodic security posture reviews and maturity assessments.

2.       Security Architecture & Solution Design

  • Design and review secure architecture for applications, cloud, and on-premise systems.
  • Ensure security-by-design principles are embedded in system development and integration.
  • Review technical designs to ensure alignment with security standards and best practices.

3.       Application & Infrastructure Security

  • Support and define application security testing (SAST, DAST, API security testing).
  • Support secure coding practices and review source code for vulnerabilities.
  • Assess infrastructure security including servers, databases, networks, and endpoints.

4.       Cloud & DevSecOps Security

  • Implement and review cloud security controls for AWS, Azure, or GCP environments.

 

  • Integrate security tools into CI/CD pipelines (DevSecOps).
  • Lead full-lifecycle SIEM deployments, from HLD/LLD design through to steady-state operations.
  • Produce detailed solution proposals, policies, and procedures to support secure, reliable SIEM services
  •  Ensure secure configuration, identity access management, and logging in cloud platforms.

5.       Security Operations & Incident Management

  • Support security incident detection, response, and investigation activities.
  • Perform root cause analysis and recommend corrective and preventive actions.
  • Coordinate with SOC, IT, and business teams during security incidents.

6.       Compliance & Governance

  • Ensure compliance with security frameworks and regulations (ISO 27001, NIST, GDPR, etc.).
  • Support internal and external security audits and risk assessments.
  • Develop and maintain security policies, standards, and procedures.

7.       Awareness & Stakeholder Engagement

  • Provide security guidance to development, infrastructure, and business teams.
  • Conduct security awareness sessions and training programs.
  • Act as a trusted advisor on security best practices and emerging threats.

8.       Continuous Improvement & Reporting

  • Stay updated with latest cyber security threats, vulnerabilities, and trends.
  • Prepare security assessment reports, dashboards, and risk summaries for management.
  • Recommend continuous improvements to enhance organizational security posture.


Requirements
Qualification: Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field.

Professional Certificate Preferred: 

  •  CISSP (Certified Information Systems Security Professional).
  •  CISM (Certified Information Security Manager).
  •  CEH (Certified Ethical Hacker).
  •  ISO/IEC 27001 Lead Implementer or Lead Auditor.
  •  AWS / Azure / GCP Security Certification.
  •  CompTIA Security+ (added advantage).
Years of Exp: 8-13 years of experience in information security, cyber security consulting, or related roles

Job Specific Skill: 
  • Strong knowledge of cyber security principles, tools, and frameworks.
  • Hands-on experience with vulnerability assessment and penetration testing tools.
  • Experience in application, infrastructure, and cloud security.
  • Knowledge of security compliance and regulatory standards.
  • Understanding of networking, operating systems, and databases.
  • Strong documentation, reporting, and stakeholder communication skills.


Skills Required

  • Bachelor's degree in Computer Science, IT, Cyber Security, or related field
  • 8-13 years of experience in information security or cybersecurity consulting
  • Hands-on experience integrating SAST, DAST, and SCA into CI/CD pipelines (DevSecOps)
  • Experience designing secure architectures for applications, cloud (AWS/Azure/GCP), and on-prem systems
  • Experience leading full-lifecycle SIEM deployments (HLD/LLD through steady-state)
  • Hands-on vulnerability assessment and penetration testing experience with related tools
  • Knowledge of security frameworks and compliance (NIST, ISO 27001, PCI DSS, GDPR)
  • Strong documentation, reporting, and stakeholder communication skills
  • CISSP, CISM, CEH, ISO/IEC 27001 Lead Implementer/Auditor, or cloud security certs (AWS/Azure/GCP)
  • CompTIA Security+
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
850 Employees
Year Founded: 2014

What We Do

Esyasoft is a global energy-transition technology group delivering integrated smart-utility solutions across software, analytics and AI, e-mobility, battery energy storage, and digital infrastructure. Its offerings help utilities, governments, and businesses modernize electricity, water, and gas infrastructure, improve operational visibility, optimize resources, and support cleaner energy systems through smart metering, IoT-driven platforms, intelligent infrastructure, and energy services for connected, sustainable energy networks.

Similar Jobs

Capco Logo Capco

Learning & Training-Third Party Risk Management

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

The Aerospace Corporation Logo The Aerospace Corporation

Sr Advanced Application Engr

Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Remote or Hybrid
India
4600 Employees

CrowdStrike Logo CrowdStrike

Artificial Intelligence Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
India
11000 Employees

Halter Logo Halter

'The Returners' Talent Pool

Greentech • Hardware • Internet of Things • Machine Learning • Software • Business Intelligence • Agriculture
In-Office or Remote
8 Locations
350 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account