Information Security Engineer Lead

3 - 6 years

5 - 15 Lacs

Posted:5 days ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Job Summary

penetration testing and vulnerability assessment

Key Responsibilities

Penetration Testing & Vulnerability Assessment

  • Perform

    manual and automated penetration testing

    on web applications, APIs, mobile apps, cloud environments, and internal/external networks.
  • Conduct

    Red Team & Blue Team exercises

    , simulate real-world cyber-attack scenarios.
  • Identify security gaps, exploit vulnerabilities ethically, and document findings.
  • Perform

    Vulnerability Scanning (SAST/DAST), Threat Modelling & Risk Assessment

    .
  • Develop and execute

    test plans, exploitation scripts, and PoC attacks

    .
  • Evaluate security of

    firewalls, SIEM, IAM, WAF, VPN, endpoints, containers, VMs, Kubernetes

    , etc.

Reporting & Documentation

  • Prepare

    detailed Pen Test reports

    , risk ratings, and mitigation recommendations.
  • Present security findings to management and technical teams.
  • Assist development teams in understanding and fixing vulnerabilities (DevSecOps support).

Security Best Practices & Compliance

  • Ensure adherence to

    ISO 27001, NIST, OWASP Top 10, CIS Benchmarks

    , PCI-DSS and other standards.
  • Support security audits, incident response, and forensic investigation if needed.
  • Contribute in

    security policies, procedures, and hardening guidelines

    .

Continuous Improvement

  • Research emerging threats, exploits, and attack vectors.
  • Recommend advance security tools, frameworks, and automation approaches.
  • Mentor junior security staff and participate in cybersecurity training sessions.

Required Skills & Qualifications

  • Bachelors in Computer Science, Cybersecurity or related field.
  • 3–7 years experience

    in Penetration Testing / Ethical Hacking.
  • Strong knowledge of

    OWASP, Kali Linux, Burp Suite, Metasploit, Nmap, Wireshark, Nessus

    , etc.
  • Experience in

    reconnaissance, exploitation, privilege escalation, post-exploitation

    .
  • Ability to test

    Web/Mobile apps, Network Security, Cloud Security, Active Directory attacks

    .
  • Hands-on scripting knowledge:

    Python, Bash, PowerShell, JS or similar

    .
  • Understanding of

    Secure SDLC, DevSecOps, CI/CD security integration

    .

Preferred Certifications (Plus)

  • CEH (Certified Ethical Hacker)
  • OSCP / OSWE / OSEP
  • GPEN, GWAPT
  • CISSP (bonus)
  • ISO 27001 Lead Implementer/Auditor (preferred)

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now
Synkcode logo
Synkcode

Software Development

Dubai Vadodara

RecommendedJobs for You

hyderabad, chennai, bengaluru