Get alerts for new jobs matching your selected skills, preferred locations, and experience range.
3.0 - 7.0 years
5 - 9 Lacs
Noida
Work from Office
Paytm is India's leading mobile payments and financial services distribution company. Pioneer of the mobile QR payments revolution in India, Paytm builds technologies that help small businesses with payments and commerce. Paytm s mission is to serve half a billion Indians and bring them to the mainstream economy with the help of technology. About Team The Internal Audit team at Paytm comprises seasoned professionals with diverse skill sets and experience across different verticals like process audits, technology audits and forensics. The team focuses on implementing the approved audit plan, ensuring delivery of qualitative audits and conducting internal / special reviews while leveraging technology & data analytics and gauging key risks across business processes. About the role: We are seeking an experienced and detail-oriented Information Security and Cloud Security Auditor to join our team. The ideal candidate will have 3-7 years of expertise in data security and privacy control implementation, internal auditing, third-party risk management, cybersecurity governance, and cloud security (banking sector preferred). This role will be responsible for conducting comprehensive IT and cloud security audits, ensuring compliance with regulatory requirements, and enhancing our information security policies and procedures. Key Responsibilities: Conduct IT and cloud security audits across various domains, including IT General Controls, Information Security Controls, Cloud Security, Network Security, Vulnerability Management, and Vendor Risk Assessments. Assess compliance with relevant laws, regulations, and organizational policies, providing expertise in regulatory requirements specific to both on-premises and cloud environments. Develop and enhance information security and cloud security policies and procedures in alignment with industry best practices. Maintain thorough documentation of audit findings, risk assessments, and security measures for internal and external reporting. Validate ITGC, cloud security, and application-specific controls, and manage audit documentation including risk assessments, working papers, audit program checklists, and evidence gathering. Follow up on and ensure closure of non-compliance issues identified during audits. Manage and oversee third-party risk assessments and audits, ensuring robust security controls are in place for both traditional and cloud-based service providers. Lead and participate in the development, migration, and implementation of security controls and policies for network and cloud security solutions. Conduct risk-based security assessments on internal, vendor, and third-party hosted environments, focusing on both traditional IT and cloud infrastructure. Participate in product and vendor selection processes, contributing to the implementation and integration of new technologies, with a strong emphasis on cloud security solutions. Experience/ Skills Required: Minimum 5 years of experience in information security and auditing, with a strong background in cloud security, and the banking and IT industries. Proven experience in performing IT and cloud security audits, validating ITGC and cloud application controls, and maintaining audit documentation. Hands-on experience with vulnerability management, risk management, physical security, identity & access management, encryption, secure development, incident management, security infrastructure, and security policy for both on-premises and cloud environments. Expertise in third-party risk management, regulatory compliance, and managing IT audit findings in both traditional and cloud-based contexts. Strong analytical and problem-solving skills. Excellent communication and documentation skills. Ability to manage multiple projects and meet deadlines. Strong understanding of IT, cloud security, and cybersecurity frameworks and standards. Proficiency in using various security assessment tools and technologies, particularly those related to cloud environments. Strong analytical and problem-solving skills. Excellent communication and documentation skills. Ability to manage multiple projects and meet deadlines. Strong understanding of IT, cloud security, and cybersecurity frameworks and standards. Proficiency in using various security assessment tools and technologies, particularly those related to cloud environments. Qualifications & Certification: Bachelor's / Master s degree in Information Technology, Cyber Security, or a related field. ISO 27001/CNSS/CCNA/CISA/CISM/CISSP Preferred Detailed knowledge of security tools, PCI-DSS, general ITGC controls, compliance testing, cloud risk assessment, GRC, OWASP, MITRE ATT&CK, change management, and policies and procedures. Proficiency in various security and cloud technologies including AWS, Azure, Google Cloud Platform, Palo Alto, Fortinet & Checkpoint Firewalls, SOAR (Cortex), Force scout Why join us 1. A collaborative output driven program that brings cohesiveness across businesses through technology 2. Improve the average revenue per use by increasing the cross-sell opportunities 3. A solid 360 feedback from your peer teams on your support of their goals 4. Respect, that is earned, not demanded from your peers and manager Compensation: If you are the right fit, we believe in creating wealth for you With enviable 500 mn+ registered users, 21 mn+ merchants and depth of data in our ecosystem, we are in a unique position to democratize credit for deserving consumers & merchants - and we are committed to it. India s largest digital lending story is brewing here. It s your opportunity to be a part of the story!
Posted 15 hours ago
5.0 - 10.0 years
7 - 12 Lacs
Pune
Work from Office
Hello Visionary! We know that the only way a business thrive is if our people are growing. That’s why we always put our people first. Our global, diverse team would be happy to support you and challenge you to grow in new ways. Who knows where our shared journey will take you We are looking for Product and Solution Security Expert (PSSE) How do you craft the future Smart BuildingsWe’re looking for the makers of tomorrow, the hardworking individuals ready to help Siemens transform entire industries, cities and even countries. Get to know us from the inside, develop your skills on the job. You’ll make a difference by: 1. Integration with SDLC: Collaborate with software development teams to integrate security practices throughout the Software Development Life Cycle (SDLC). Perform security code reviews and analyze vulnerabilities during different SDLC phases. Ensure security requirements are included in the design, development, testing, and deployment stages of software projects. 2. Security Activities: Develop and implement security protocols, guidelines, and best practices for software development. Conduct threat modelling and risk assessments to identify potential security issues early in the development process. Provide guidance on secure coding practices and remediation of identified vulnerabilities. 3. Stakeholder Interaction: Work closely with key stakeholders, including product managers, project managers, and business analysts, to support and promote security activities within products. Communicate security risks, issues, and mitigation strategies effectively to both technical and non-technical stakeholders. Foster a security-aware culture within the development teams and across the organization. 4. Security Tools and Technologies: Implement and manage security tools such as static and dynamic analysis tools, intrusion detection systems, and vulnerability scanners. Stay updated with the latest security tools, trends, and best practices to enhance the organization's security posture. 5. Incident Response: Assist in the development and implementation of incident response plans and procedures. Participate in security incident investigations and provide expertise in resolving security breaches. 6. Training and Awareness: Conduct security training and awareness programs for development teams. Promote continuous improvement and knowledge sharing related to application security. You’ll win us over by: 1. Technical Skills: In-depth knowledge of application security, secure coding practices, and common vulnerabilities (e.g., OWASP Top Ten). Experience with security tools and technologies such as static analysis tools (SAST), dynamic analysis tools (DAST), and vulnerability scanners. Proficiency in programming languages such as Java, C#, Python. Understanding of DevSecOps practices and integration of security into CI/CD pipelines. Promote continuous improvement and knowledge sharing related to application security. 2. Soft Skills: Strong communication and interpersonal skills. Ability to explain complex security concepts to non-technical stakeholders. Strong analytical and problem-solving skills. Collaborative mindset and ability to work effectively with cross-functional teams. 3. Certification Preferred: Certified Secure Software Lifecycle Professional (CSSLP). Experience: Proven experience working with software development teams and integrating security practices into the SDLC. Experience interacting with key stakeholders and supporting security activities within software products. You’ll win us over by: Having An engineering degree B.E/B.Tech/MCA/M.Tech/M.Sc with good academic record. Minimum 5 years of experience in cybersecurity, with a focus on application security. We’ll support you with: Hybrid working Opportunities. Diverse and inclusive culture. Great variety of learning & development opportunities. Create a better #TomorrowWithUs! This role, based in Pune, is an individual contributor position. You may be required to visit other locations within India and internationally. In return, you'll have the opportunity to work with teams shaping the future. At Siemens, we are a collection of over 312,000 minds building the future, one day at a time, worldwide. We are dedicated to equality and welcome applications that reflect the diversity of the communities we serve. All employment decisions at Siemens are based on qualifications, merit, and business need. Bring your curiosity and imagination, and help us shape tomorrow Find out more about the Digital world of Siemens here[1] www.siemens.com/careers/digitalminds Find out more about Siemens careers at[2] www.siemens.com/careers
Posted 15 hours ago
7.0 - 10.0 years
9 - 12 Lacs
Bengaluru
Work from Office
Hello Visionary ! We empower our people to stay resilient and relevant in a constantly changing world. We’re looking for people who are always searching for creative ways to grow and learn. People who want to make a real impact, now and in the future. We are looking for a highly skilled and motivated Product & Solution Security Professional to join our team. The ideal candidate will be responsible for defining secure design principles and supporting cross-functional teams to ensure secure architecture, implementation, and testing of products and solutions. Key Responsibilities Integration with SDLC Collaborate with software development teams to integrate security practices throughout the Software Development Life Cycle (SDLC). Ensure security requirements are included in the design, development, testing, and deployment stages of software projects. Perform security code reviews and analyze vulnerabilities during different SDLC phases. 2. Security Activities Develop and implement security protocols, guidelines, and best practices for software development. Conduct threat modelling and risk assessments to identify potential security issues early in the development process. Provide guidance on secure coding practices and remediation of identified vulnerabilities. Stakeholder Interaction Work closely with key stakeholders, including product managers, project managers, and business analysts, to support and promote security activities within products. Communicate security risks, issues, and mitigation strategies effectively to both technical and non-technical stakeholders. Foster a security-aware culture within the development teams and across the organization . 4. Security Tools and Technologies Implement and manage security tools such as static and dynamic analysis tools and vulnerability scanners. Stay updated with the latest security tools, trends, and best practices to enhance product’s security posture. 5. Training and Awareness Conduct security training and awareness programs for development teams. Promote continuous improvement and knowledge sharing related to application security . Skills and Qualifications 1. Technical Skills: In-depth knowledge of application security, secure coding practices, and common vulnerabilities (e.g., OWASP Top Ten). Experience with security tools and technologies such as static analysis tools (SAST), dynamic analysis tools (DAST), and vulnerability scanners. Proficiency in programming languages such as Java, C#, Python. Understanding of DevSecOps practices and integration of security into CI/CD pipelines. Promote continuous improvement and knowledge sharing related to application security. 2. Soft Skills: Strong communication and interpersonal skills. Ability to explain complex security concepts to non-technical stakeholders. Strong analytical and problem-solving skills. Collaborative mindset and ability to work effectively with cross-functional teams. 3. Certification Preferred CEH, Certified Secure Software Lifecycle Professional (CSSLP) or equivalent. Experience Proven experience working with software development teams and integrating security practices into the SDLC. Experience interacting with key stakeholders and supporting security activities within software products. Having An engineering degree B.E/B.Tech/MCA/M.Tech/M.Sc with good academic record. 7 - 10 years of experience in cybersecurity, with a focus on application security. Make your mark in our exciting world at Siemens . This role, based in Bangalore , is an individual contributor position. You may be required to visit other locations within India and internationally. In return, you'll have the opportunity to work with teams shaping the future. At Siemens, we are a collection of over 312,000 minds building the future, one day at a time, worldwide. We are dedicated to equality and welcome applications that reflect the diversity of the communities we serve. All employment decisions at Siemens are based on qualifications, merit, and business need. Bring your curiosity and imagination, and help us shape tomorrow We’ll support you with Hybrid working opportunities. Diverse and inclusive culture. Variety of learning & development opportunities. Attractive compensation package. Find out more about Siemens careers at www.siemens.com/careers
Posted 15 hours ago
3.0 - 8.0 years
5 - 10 Lacs
Bengaluru
Work from Office
The key requirement is to have a passion for developing high quality, highly available services. Candidates that have been successful in this area are typically proficient using a CLI, have a strong desire to work within a CI/CD environment, have a passion for embracing new cloud technologies, and are great team workers that are willing to turn their hand to whatever the highest priority issue of the day happens to be. You need to be collaborative, tenacious, be able to handle responsibility, and love learning new techniques and tools. As a member of the data services team you will join the primary on-call rotation (includes weekends) where you will be the primary responder for day to day operational issues. Working closely with our worldwide teams, this provides a unique opportunity to gain first-hand experience with the latest database technologies. The services must meet stringent availability targets 24x7 in all datacenters across the globe. You will follow runbooks to resolve such issues and use your troubleshooting and analytical skills to diagnose or troubleshoot platform or Data Service issues. Key Responsibilities: Design, build, and maintain our RESTful Ruby on Rails API, adhering to OpenAPI standards. Utilize OpenAPI (Swagger) to create clear and comprehensive API documentation, ensuring easy adoption and integration by other teams and external developers. Write clean, maintainable, and well-tested code, ensuring high standards of code quality and performance. Work closely with front-end developers, product managers, and other stakeholders to translate requirements into technical solutions. Develop automated tests to ensure API reliability and stability. Identify and fix bugs and performance bottlenecks. Manage API versioning to ensure backward compatibility and a smooth transition between different API versions. Adhere to best practices including unit and automated testing, code quality, and peer review of pull requests. Participate in sprint planning and backlog grooming sessions, providing insights on the size and complexity of tasks. Mentor other members of the team, fostering a culture of continuous learning and improvement. Offer opinions and insights on new and upcoming features, shaping the functionality within the product. Stay updated with the latest developments in the open-source community and front-end technologies. Required education Bachelor's Degree Preferred education Master's Degree Required technical and professional expertise Technical Skills: 3+ years of experience in backend development with Ruby on Rails, specifically in building and maintaining RESTful APIs. Strong experience with OpenAPI standards, including API design, documentation, and versioning. Experience with RSpec, Minitest, or similar testing frameworks. Knowledge of CI/CD pipelines, cloud deployment practices, and Kubernetes environments. Knowledge of OWASP best practices and vulnerability management. Prior experience in a similar role within a development organization preferably cloud based. Experience with Go and Python and is preferred Preferred technical and professional experience Strong problem-solving skills. Strong communication skills to interact with various stakeholders. Ability to work collaboratively with a small cross-functional team of engineers, PMs, designers, and researchers. Empathy for user challenges and focus on building user-centric solutions. Ability to scope solutions collaboratively and work comfortably with ambiguity. Ability to mentor team members and foster a culture of continuous improvement. Enjoy high-visibility work and presenting to stakeholders. Comfortable working in an agile, fast paced environment. Passion for following the latest developments in the open-source community and front-end technologies. Preferred Qualifications: A degree in Computer Science, Engineering, or a related field is preferred, but equivalent practical experience is also considered.
Posted 16 hours ago
3.0 - 8.0 years
5 - 10 Lacs
Bengaluru
Work from Office
As a Security Consultant, you play a pivotal role as a key advisor for IBM's clients. Your primary responsibility is to analyze business requirements and leverage your expertise to design and implement optimal security solutions tailored to meet the unique needs of our clients. Your technical skills will be crucial in finding the delicate balance between enabling and securing our client's organization, utilizing cognitive solutions that have contributed to making IBM the fastest-growing enterprise security business globally. - Develop a deep technical understanding of IBM Public Cloud offerings and infrastructure - Plan and perform red team exercises against various cloud offerings - Plan and perform full stack security tests against various system(s) and application(s) independently as well as within a team - Engage in security monitoring and visibility improvement activities across the IBM Public Cloud organization - Thoroughly document techniques, tactics, and proof of concepts used during security testing and red team exercises - Communicate with various business and technology leaders to interpret identified vulnerabilities and assist in the development and planning for risk mitigation plans - Research and continuously improve skills in attacker tools, methods, and techniques - Lead by example for the greater red team in professionalism, communication, and technical expertise Required education Bachelor's Degree Preferred education Bachelor's Degree Required technical and professional expertise 3+ years of demonstrating experience in planning and executing penetration tests/red team exercises against web applications, containers, APIs, network devices, databases, operating systems, and various cloud technologies Demonstrates strong understanding of offensive cybersecurity operations and defensive integrations, including enumeration and exploitation of various cloud-based technologies and development of secure applications. Demonstrates strong ability to communicate highly technical aspects to Executives and IT staffs, respectively Demonstrates ability by creating custom tools for penetration testing and contributing to opensource technologies Demonstrates strong experience with various scripting languages (Python, Ruby, Bash, etc.) Possess one or more of the following credentialsOSCP, OSCE, OSWE, GWAPT, GPEN, GXPN, CRTP, Crest Penetration Certification. Familiarity with serverless services, containerization and other cloud technologies Strong familiarity with OWASP Top Ten, NIST, and MITRE ATT&CK 3+ years of demonstrating experience in system or application administration role(s) Preferred technical and professional experience 5+ years of demonstrating experience in planning and executing penetration tests/red team exercises against web applications, containers, APIs, network devices, databases, operating systems, and various cloud technologies Understanding of offensive cybersecurity operations and defensive integrations, including enumeration and exploitation of various cloud-based technologies and development of secure applications. Ability to communicate highly technical aspects to Executives and IT staff, respectively Demonstrates ability by creating custom tools for penetration testing and contributing to opensource technologies Expertise in developing exploits and customized attack tooling and approaches Demonstratedsecurity research leading to bug bounty and CVE awards Deep understanding of serverless services, containerization and other cloud technologies Demonstrates strong experience with various scripting languages (Python, Ruby, Bash, etc.) CGood to have one of these certsCRTP, CEH, OSCP, OSCE, OSWE, GWAPT, GPEN, GXPN, CRTP, Crest Penetration Certification. Familiarity with serverless services, containerization and other cloud technologies Strong familiarity with OWASP Top Ten, NIST, and MITRE ATT&CK 5+ years of demonstrating experience in system or application administration role(s)
Posted 16 hours ago
0 years
0 - 0 Lacs
Alleppey
On-site
Job Title: Cybersecurity Intern (Paid) Company: Ziya Academy LLP Location: Muppathadam, Aluva, Kerala (On-site) About the Internship Are you interested in ethical hacking, network defense, and cybersecurity practices? Join Ziya Academy LLP as a Cybersecurity Intern and gain real-world experience identifying security vulnerabilities, defending systems, and using professional tools to protect digital assets. This internship is designed to equip you with practical skills and project experience to launch your career in cyber security. What You'll Learn Hands-on training with cyber security tools Real-time project exposure: vulnerability scans, network audits, and simulations Internship Certificate & Performance Letter upon completion Familiarity with tools like Wireshark , Nmap , Burp Suite , Metasploit , and Kali Linux Opportunity to grow into a full-time cybersecurity analyst or ethical hacker role Eligibility Students, freshers, or graduates in Computer Science, IT, or Cybersecurity fields Basic knowledge of networking , Linux , or information security Strong interest in ethical hacking and cyber defense Must be available to work on-site at our Aluva location Key Learning Areas Cybersecurity Fundamentals & Threat Models Networking, TCP/IP & Web Security (OWASP Top 10) Vulnerability Assessment & Reporting Basics of Ethical Hacking & Penetration Testing Firewalls, VPNs, IDS/IPS Cyber Laws & Risk Assessment Tools: Kali Linux, Wireshark, Metasploit, Burp Suite Internship Duration 3 to 6 Months (Duration based on candidate availability and performance) Stipend & Growth Path Monthly Stipend: ₹3,000 – ₹6,000 (performance-based) Initial pay : 5000/- Top performers may receive a full-time job offer: ₹10,000 – ₹25,000/month Work Schedule & Mode Timing: Day Shift Mode: On-site (Muppathadam, Aluva) Perks & Benefits Mentorship from experienced cybersecurity professionals Access to live case studies & real-world security simulations Resume and LinkedIn profile development Internship Certificate & Letter of Recommendation Opportunity for full-time placement upon successful completion How to Apply Call or WhatsApp: +91 73063 53515 Email: ziyaacademyedu@gmail.com Job Details Job Types: Internship, Fresher, Full-time (Post-internship opportunity) Expected Post-Internship Salary: ₹10,000 – ₹25,000/month Supplemental Pay Options: ✔ Performance Bonus ✔ Overtime Pay ✔ Commission Pay ✔ Quarterly / Yearly Bonus ✔ Shift Allowance Work Location: In person (Aluva, Kerala) Job Types: Full-time, Permanent, Fresher, Internship Pay: ₹8,000.00 - ₹30,000.00 per month Schedule: Day shift Morning shift Supplemental Pay: Commission pay Overtime pay Performance bonus Quarterly bonus Shift allowance Yearly bonus Work Location: In person
Posted 18 hours ago
2.0 years
0 Lacs
Gurugram, Haryana, India
On-site
Line of Service Advisory Industry/Sector FS X-Sector Specialism Risk Management Level Senior Associate Job Description & Summary At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. Those in penetration testing at PwC will focus on penetration testing (or pen testing) which is a security exercise where a cybersecurity consultant attempts to find and exploit vulnerabilities in a computer system. The purpose of this simulated attack is to identify any weak spots in a system's defences which attackers could take advantage of. *Why PWC At PwC , you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us . At PwC , we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations Job Description & Summary: Job Description & Summary: We are seeking a highly skilled and experienced Cybersecurity/Risk Consulting Senior Associate to join our Risk Consulting team. As a Cybersecurity Senior Associate, you will be responsible for leading and managing a team of consultants to deliver high-quality cybersecurity and risk management services to our clients. Responsibilities: Key Responsibilities: · Good interpersonal skills (written and oral communication) and ability to articulate complex issues · Ability to communicate technical · information clearly and concisely, commensurate with the audience · Conceptual thinking and communication skills — the ability to conceptualize complex business and technical requirements into comprehensible models and templates. · Good communicator (written and verbal) and listener. · Must be a team player and motivated self-starter with ability to work independently with limited supervision. · Must be assertive, methodical and detail oriented Technical Experience: · Experience in Web and Mobile Application Security Testing, Vulnerability Assessment and Penetration testing · Analyze scan reports and suggest remediation / mitigation plan for security vulnerabilities · Should be aware of tools like Qualys, HP Fortify, IBM Appscan, Burpsuite, Kali Linux suite of tools · Expertise in mobile apps reverse engineering and in-depth knowledge of Android and iOS ecosystems. Knowledge of industry standard tools for mobile pentest. · Thorough understanding of OWASP Top 10 vulnerabilities and their mitigations. Knowledge of Network Security technology in areas of Firewall, IPS, VPN, Gateway security solutions (proxy, web filtering) · Conduct penetration test and launch exploits using Nessus, Metaspoilt, kali linux penetration testing distribution tools sets · Conduct Vulnerability Assessments of Network Devices using various open source and commercial tools · Map out a network, discover ports and services running on the different exposed network and security devices · Research and maintain proficiency in computer network exploitation, tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, network security, and encryption. · In-depth understanding on Common Vulnerability Exposure (CVE)/ CERT advisory database. Broad background of networks, operating systems (Window, Unix, Linux), firewalls and security engineering concepts. · Knowledge of scripting languages (Perl, Python, Shell etc) will be added advantage · Knowledge of Open-Source Security Testing Methodology Manual (OSSTMM) Mandatory skill sets: CEH, ECSA, LPT (any one) Preferred skill sets: OSCP, OSWE Years of experience required: 2-10 Years Education qualification: B.Tec Education (if blank, degree and/or field of study not specified) Degrees/Field of Study required: Bachelor of Technology Degrees/Field of Study preferred: Certifications (if blank, certifications not specified) Required Skills Optional Skills Accepting Feedback, Accepting Feedback, Active Listening, Analytical Thinking, Bash (Programming Language), Common Vulnerability Scoring System (CVSS), Communication, Creativity, Cybersecurity, Embracing Change, Emotional Regulation, Empathy, Encryption, Ethical Hacking, Firewall (Network Security), Inclusion, Information Security, Information Security Management System (ISMS), Information Security Risk Assessments, Intellectual Curiosity, Intrusion Detection System (IDS), IT Infrastructure, Kali Linux, Learning Agility, Microsoft Active Directory {+ 25 more} Desired Languages (If blank, desired languages not specified) Travel Requirements Not Specified Available for Work Visa Sponsorship? No Government Clearance Required? No Job Posting End Date Show more Show less
Posted 18 hours ago
2.0 years
0 Lacs
Greater Kolkata Area
On-site
Line of Service Advisory Industry/Sector FS X-Sector Specialism Risk Management Level Manager Job Description & Summary At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies. They work to identify vulnerabilities, develop secure systems, and provide proactive solutions to safeguard sensitive data. As a cybersecurity generalist at PwC, you will focus on providing comprehensive security solutions and experience across various domains, maintaining the protection of client systems and data. You will apply a broad understanding of cybersecurity principles and practices to address diverse security challenges effectively. *Why PWC At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us . At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. " Job Description & Summary: We are seeking a highly skilled and experienced Cybersecurity/Risk Consulting Senior Associate to join our Risk Consulting team. As a Cybersecurity Senior Associate, you will be responsible for leading and managing a team of consultants to deliver high-quality cybersecurity and risk management services to our clients. Responsibilities: Key Responsibilities: · Good interpersonal skills (written and oral communication) and ability to articulate complex issues · Ability to communicate technical · information clearly and concisely, commensurate with the audience · Conceptual thinking and communication skills — the ability to conceptualize complex business and technical requirements into comprehensible models and templates. · Good communicator (written and verbal) and listener. · Must be a team player and motivated self-starter with ability to work independently with limited supervision. · Must be assertive, methodical and detail oriented Technical Experience: · Experience in Web and Mobile Application Security Testing, Vulnerability Assessment and Penetration testing · Analyze scan reports and suggest remediation / mitigation plan for security vulnerabilities · Should be aware of tools like Qualys, HP Fortify, IBM Appscan, Burpsuite, Kali Linux suite of tools · Expertise in mobile apps reverse engineering and in-depth knowledge of Android and iOS ecosystems. Knowledge of industry standard tools for mobile pentest. · Thorough understanding of OWASP Top 10 vulnerabilities and their mitigations. Knowledge of Network Security technology in areas of Firewall, IPS, VPN, Gateway security solutions (proxy, web filtering) · Conduct penetration test and launch exploits using Nessus, Metaspoilt, kali linux penetration testing distribution tools sets · Conduct Vulnerability Assessments of Network Devices using various open source and commercial tools · Map out a network, discover ports and services running on the different exposed network and security devices · Research and maintain proficiency in computer network exploitation, tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding, network security, and encryption. · In-depth understanding on Common Vulnerability Exposure (CVE)/ CERT advisory database. Broad background of networks, operating systems (Window, Unix, Linux), firewalls and security engineering concepts. · Knowledge of scripting languages (Perl, Python, Shell etc) will be added advantage · Knowledge of Open-Source Security Testing Methodology Manual (OSSTMM) Mandatory skill sets: CEH, ECSA, LPT (any one) Preferred skill sets: OSCP, OSWE Years of experience required: 2-10 Years Education qualification: B.Tech Education (if blank, degree and/or field of study not specified) Degrees/Field of Study required: Bachelor of Technology Degrees/Field of Study preferred: Certifications (if blank, certifications not specified) Required Skills SoCs Optional Skills Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Analytical Thinking, Azure Data Factory, Coaching and Feedback, Communication, Creativity, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Learning Agility, Managed Services, Optimism, Privacy Compliance, Professional Courage {+ 13 more} Desired Languages (If blank, desired languages not specified) Travel Requirements Not Specified Available for Work Visa Sponsorship? No Government Clearance Required? No Job Posting End Date Show more Show less
Posted 18 hours ago
8.0 - 10.0 years
0 Lacs
Gurugram, Haryana, India
On-site
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Senior Security Consultant Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value. The opportunity As a Security Consultant, the individual will provide security guidance to internal IT project teams responsible for delivering business solutions, with a focus on end user technology and related solutions. They will identify and prioritize security-related requirements, promote secure-by-default designs and ensure information systems and infrastructure will be secured throughout the system development life cycle (SDLC) in an agile environment. Your Key Responsibilities The successful candidate is expected to perform risk assessments of mobile applications, mobile and desktop end user technology platforms, infrastructure systems and solutions; effectively articulate findings and recommendations to internal customers and management; and they will be expected to work on multiple projects and tasks concurrently. Skills And Attributes For Success Solid understanding of key security and privacy issues, risks and threats, and ability to apply this expertise across business needs via internal consulting and security risk assessment types of activities. Strong written and verbal communication skills are essential Proven background in IT risk assessments, and knowledge of good security practices and controls used in applications and infrastructure. Translate technical vulnerabilities and security risks into business risk terminology for business units and recommend corrective actions to customers and project stakeholders. Ability to document and produce important artefacts on risk assessments, engagement Statements of Work, process, minimum security baselines and presentations on security risks. Manage customer expectations and deliver quality security consulting services while balancing business objectives with security requirements. Ability to partner with technical teams in a practical manner when conflicting interests arise while preserving EY core security principles and policies. Ability to proactively lead, own and research security related subject matters when required to take a position or resolve issues. Ability to collaborate to facilitate and enhance the understanding & compliance to security policies. To qualify for the role, you must have A minimum of 8-10 years of experience in an Information Security or Information Technology subject area. Two or more years of experience with iOS and Android security such as mobile application security analysis, mobile application penetration testing, mobile threat modelling, mobile device forensics, and assessing mobile device security capabilities. Three or more years of experience with understanding and defining good security practices for end user technology platforms (e.g., iOS, Android, macOS, Windows 10), multi-tier information systems, applications (e.g., web, mobile, desktop), and End Point Security solutions. Working experience in performing security risk assessments for information systems and applications such as those for web, desktop, and mobile. Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or risk assessments. Good interpersonal, communication, organizational and project management skills. Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change. Ideally,you will also have One or more years of experience with iOS and Android mobile application development, Agile Methodology, Continuous Integration / Continuous Delivery, and IoT security. Knowledge or experience with Microsoft Azure cloud technology stack (e.g., M365, SharePoint, OneDrive for Business, Intune, Conditional Access) and Azure cloud applications. Knowledge of common information security standards and risk analysis methodologies, such as: ISO 27001/27002, NIST, PCI, COBIT, ISF IRAM2, and OWASP. What We Look For We look for people who are customer-centric with good interpersonal, communication and organizational skills. The ideal candidate will have flexibility in adjusting to multiple demands, shifting priorities, ambiguity, rapid change, and an ardent desire to learn. What We Offer As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here is a snapshot of what we offer: Continuous learning: You will develop the mindset and skills to navigate whatever comes next. Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way. Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Show more Show less
Posted 18 hours ago
5.0 years
0 Lacs
Chennai, Tamil Nadu, India
On-site
Themesoft is seeking Java Web Application Developers for one of our clients. Experience: 5-10 years of experience is mandatory. Location: Chennai (Hybrid) Position: Senior Java Developer Type: Full-Time Notice Period: Maximum 45 days of Notice period ✅ Requirements: 5+ years of hands-on experience in Java web application development. Strong proficiency in JSP , Servlets , and Java frameworks Proven experience managing and upgrading dependencies using Maven or Gradle Experience using Eclipse IDE for Java development Solid understanding of secure coding principles and familiarity with the OWASP Top 10 Comfortable with Git version control, including branching strategies, pull requests, and code reviews Strong communication skills with the ability to work both independently and in distributed teams If you are interested, share updated resume with mythili@themesoft.com #SeniorJavaDeveloper #JavaJobs #ChennaiJobs #HybridJobs #FullTimeJob #JavaDevelopment #SecureCoding #OWASPTop10 #LegacyCode #Maven #Gradle #EclipseIDE #GitWorkflow #JavaCareers #HiringNow #TechJobsIndia #SoftwareEngineering #BackendDeveloper #JavaExperts #ExperiencedProfessionals Show more Show less
Posted 18 hours ago
2.0 years
0 Lacs
Jaipur
Remote
Job Summary Auriga is looking for a Software Engineer who can develop and deploy APIs and Web applications using Java MVC Frameworks and power a variety of leading-edge digital products. You’ll need to bring creative thinking and architectural problem solving to the table, to devise optimal technical solutions, along with highly performant user experiences. Responsibilities Work with business users to gather functional requirements Combine your technical expertise and problem-solving passion to turn complex problems into end-to-end solutions Work with client architect/senior developers to do high level/low level design/architecture. Design and implement high-quality, test-driven BE code for various projects Unit Testing/Integration Testing Code Configuration and Release Management. Create and maintain documentation, implement and follow best practices for development workflow. Work collaboratively with team members to ensure deadlines are met. Stay current on changes in technology and keep adding to your skillset. Qualifications Minimum 2 Years of experience in Web Application and API development in Java 8 and above Working experience with MVC frameworks like Spring, Play, etc. Experience with Multi-threading, Collections, and concurrent API Working experience with web-services and APIs (REST, SOAP) Working experience with data platforms (relational and/or NoSQL) and messaging technologies Excellent OOPs, data structure, and algorithm knowledge Understanding & experience in API management, Swagger Working knowledge of API Testing Tools (e.g. Postman), Version control systems like GIT. Working experience with LINUX/UNIX environment and shell scripts Proficiency in English Strong collaborator and comfortable to work in an agile, remote and distributed team environment Follow secure coding practices and ensure data protection, authentication, and authorization mechanisms are implemented effectively (e.g., OAuth2, JWT). Knowledge of OWASP Top 10 and implementation of security controls in APIs. Nice to have Experience in one or more front-end development technologies Experience in developing microservices in Spring Boot. Experience writing high-quality code with fully automated unit test coverage (Junit, Mockito, etc.) Experience defining and applying design/coding standards, patterns, and quality metrics depending on the solution Working experience with various CI/CD systems (Jenkins, Docker, Kubernetes) and build tools (ant, maven, gradle, etc.). Working experience creating high performing applications, including profiling and tuning to improve performance Experience with application logging and monitoring using tools like ELK Stack, Prometheus, Grafana, or New Relic Experience in Scrum/Agile Knowledge of public cloud infrastructures (AWS, Azure, GCP) Knowledge of one or more security or integration framework (PING, Octa) Familiarity with services such as S3, Lambda, EC2, IAM, CloudWatch, or RDS is a plus. Understanding of API rate limiting, request throttling, caching strategies (e.g., Redis), and gateway tools like Kong, Apigee, or AWS API Gateway. Ability to take full ownership of assigned modules or projects with minimal supervision. About Company Hi there! We are Auriga IT. We power businesses across the globe through digital experiences, data and insights. From the apps we design to the platforms we engineer, we're driven by an ambition to create world-class digital solutions and make an impact. Our team has been part of building the solutions for the likes of Zomato, Yes Bank, Tata Motors, Amazon, Snapdeal, Ola, Practo, Vodafone, Meesho, Volkswagen, Droom, ICICI and many more. We are a group of people who just could not leave our college-life behind and the inception of Auriga was solely based on a desire to keep working together with friends and enjoying the extended college life. Who Has not Dreamt of Working with Friends for a Lifetime Come Join In! https://www.aurigait.com/
Posted 18 hours ago
2.0 years
0 Lacs
New Delhi, Delhi, India
On-site
Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We believe that our work to help our clients discover and remediate their unique security risks makes every one of us safer. Our clients trust us to use cutting-edge offensive security tools, creativity, imagination, and expert knowledge to find cybersecurity risks in their networks, systems, and software. We're looking to grow our team of penetration testers in India. We perform testing of web and smartphone applications, computer networks, cloud infrastructure, hardware devices, employees via social engineering, organizations via red team testing, and more. As an Offensive Security Consultant, you’ll be reporting to a Vice President in our APAC Offensive Security team and deliver projects for some of the biggest enterprises in the world. You will perform various web application, API, mobile, and infrastructure penetration tests. You will also draft reports based on the assessment results and gathered evidence and help address client inquiries regarding these results. In addition to the execution of traditional security assessments, you will participate in their refinement and improvement. Below are the roles and responsibilities for the Consultant, Offensive Security role based in India: Day To Day Responsibilities Execute offensive security and consultative engagements for our clients’ applications, cloud assets, and infrastructure Author deliverables such as vulnerability reports and executive reports Engage with our clients to understand their requirements, update them on project status, answer their queries, and present your findings and recommendations Keep your skills and knowledge up to date with the latest trends in cybersecurity and emerging technology Willingness to work in EST Time zone Essential Traits 2+ years in cybersecurity, with at least 1 year in penetration testing, cloud security, or red teaming A strong understanding of offensive security methodology and vulnerability frameworks such as the OWASP Top 10, MITRE ATT&CK, PTES, or others An ability to analyze root causes and deliver technological recommendations to our clients Prerequisites Bachelor’s degree or college diploma in information security, computer science or engineering, software engineering, or IT/System/Network administration Excellent oral and written communication skills Experience working both as part of a team and independently About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. Kroll is committed to equal opportunity and diversity, and recruits people based on merit. In order to be considered for a position, you must formally apply via careers.kroll.com Show more Show less
Posted 18 hours ago
5.0 - 7.0 years
0 Lacs
Bengaluru, Karnataka, India
On-site
Penetration Tester Role: The Penetration Tester, will provide broad and in depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective and response controls across the global technology landscape. You will use your expertise to help influence technology decisions and work as part of a team to create consistent approaches to the offensive security processes and techniques. Penetration Testing Duties and Responsibilities: Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired, wireless networks, and mobile applications/devices, Cloud(Azure, AWS, Google Etc) apps and software’s. Set up environment and maintain required tools needed for the team. Lead and manage Penetration Testing team and Supporting vendors to get qualitative deliveries to our customer. Develop and maintain security testing plans Able to automate penetration and other security testing on networks, systems and applications. Develop meaningful metrics to reflect the true posture of the environment allowing the organization to make educated decisions based on risk. Produce actionable, threat-based, reports on security testing results Act as a source of direction, training, and guidance for less experienced staff Consult with application developers, systems administrators, and management to demonstrate security testing results, explain the threat presented by the results, and consult on remediation Communicate security issues to a wide variety of internal and external “customers” to include technical teams, executives, risk groups, vendors and regulators Deliver the annual penetration testing schedule and conducting awareness campaigns to ensure proper budgeting by business lines for annual tests. Foster and maintain relationships with key stakeholders and business partners Certificates: Must Have Offensive Security Certified Professional (OSCP) Good to have CREST Registered Penetration Tester (CRT) Certified Ethical Hacker (CEH) Certification GIAC Certified Penetration Tester (GPEN) Penetration Testing Expert Requirements and Qualification: Previous working experience as a Penetration Testing Expert for 5 - 7 year BE in Computer Information Systems, Management Information Systems, or similar relevant field In-depth knowledge of application development processes and at least one programing or scripting language (e.g., Java, Scala, C#, Ruby, Perl, Python, PowerShell) Must know about standard Industry security Practices (OWASP, SANS, etc), Knowledgeable about industry Security guidelines and compliance such as ISO27001, SOC2, HIPPA etc. Hands on experience with testing frameworks such as the PTES and OWASP. Applicable knowledge of Windows client/server, Unix/Linux systems, Mac OS X, VMware/Xen, and cloud technologies such as AWS, Azure, or Google Cloud Critical thinker and problem solver Excellent organizational and time management skills Show more Show less
Posted 18 hours ago
2.0 years
0 Lacs
Hyderabad, Telangana, India
On-site
Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We believe that our work to help our clients discover and remediate their unique security risks makes every one of us safer. Our clients trust us to use cutting-edge offensive security tools, creativity, imagination, and expert knowledge to find cybersecurity risks in their networks, systems, and software. We're looking to grow our team of penetration testers in India. We perform testing of web and smartphone applications, computer networks, cloud infrastructure, hardware devices, employees via social engineering, organizations via red team testing, and more. As an Offensive Security Consultant, you’ll be reporting to a Vice President in our APAC Offensive Security team and deliver projects for some of the biggest enterprises in the world. You will perform various web application, API, mobile, and infrastructure penetration tests. You will also draft reports based on the assessment results and gathered evidence and help address client inquiries regarding these results. In addition to the execution of traditional security assessments, you will participate in their refinement and improvement. Below are the roles and responsibilities for the Consultant, Offensive Security role based in India: Day To Day Responsibilities Execute offensive security and consultative engagements for our clients’ applications, cloud assets, and infrastructure Author deliverables such as vulnerability reports and executive reports Engage with our clients to understand their requirements, update them on project status, answer their queries, and present your findings and recommendations Keep your skills and knowledge up to date with the latest trends in cybersecurity and emerging technology Willingness to work in EST Time zone Essential Traits 2+ years in cybersecurity, with at least 1 year in penetration testing, cloud security, or red teaming A strong understanding of offensive security methodology and vulnerability frameworks such as the OWASP Top 10, MITRE ATT&CK, PTES, or others An ability to analyze root causes and deliver technological recommendations to our clients Prerequisites Bachelor’s degree or college diploma in information security, computer science or engineering, software engineering, or IT/System/Network administration Excellent oral and written communication skills Experience working both as part of a team and independently About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. Kroll is committed to equal opportunity and diversity, and recruits people based on merit. In order to be considered for a position, you must formally apply via careers.kroll.com Show more Show less
Posted 19 hours ago
2.0 years
0 Lacs
India
On-site
Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We believe that our work to help our clients discover and remediate their unique security risks makes every one of us safer. Our clients trust us to use cutting-edge offensive security tools, creativity, imagination, and expert knowledge to find cybersecurity risks in their networks, systems, and software. We're looking to grow our team of penetration testers in India. We perform testing of web and smartphone applications, computer networks, cloud infrastructure, hardware devices, employees via social engineering, organizations via red team testing, and more. As an Offensive Security Consultant, you’ll be reporting to a Vice President in our APAC Offensive Security team and deliver projects for some of the biggest enterprises in the world. You will perform various web application, API, mobile, and infrastructure penetration tests. You will also draft reports based on the assessment results and gathered evidence and help address client inquiries regarding these results. In addition to the execution of traditional security assessments, you will participate in their refinement and improvement. Below are the roles and responsibilities for the Consultant, Offensive Security role based in India: Day To Day Responsibilities Execute offensive security and consultative engagements for our clients’ applications, cloud assets, and infrastructure Author deliverables such as vulnerability reports and executive reports Engage with our clients to understand their requirements, update them on project status, answer their queries, and present your findings and recommendations Keep your skills and knowledge up to date with the latest trends in cybersecurity and emerging technology Willingness to work in EST Time zone Essential Traits 2+ years in cybersecurity, with at least 1 year in penetration testing, cloud security, or red teaming A strong understanding of offensive security methodology and vulnerability frameworks such as the OWASP Top 10, MITRE ATT&CK, PTES, or others An ability to analyze root causes and deliver technological recommendations to our clients Prerequisites Bachelor’s degree or college diploma in information security, computer science or engineering, software engineering, or IT/System/Network administration Excellent oral and written communication skills Experience working both as part of a team and independently About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. Kroll is committed to equal opportunity and diversity, and recruits people based on merit. In order to be considered for a position, you must formally apply via careers.kroll.com Show more Show less
Posted 19 hours ago
8.0 - 10.0 years
0 Lacs
Kochi, Kerala, India
On-site
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Senior Security Consultant Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value. The opportunity As a Security Consultant, the individual will provide security guidance to internal IT project teams responsible for delivering business solutions, with a focus on end user technology and related solutions. They will identify and prioritize security-related requirements, promote secure-by-default designs and ensure information systems and infrastructure will be secured throughout the system development life cycle (SDLC) in an agile environment. Your Key Responsibilities The successful candidate is expected to perform risk assessments of mobile applications, mobile and desktop end user technology platforms, infrastructure systems and solutions; effectively articulate findings and recommendations to internal customers and management; and they will be expected to work on multiple projects and tasks concurrently. Skills And Attributes For Success Solid understanding of key security and privacy issues, risks and threats, and ability to apply this expertise across business needs via internal consulting and security risk assessment types of activities. Strong written and verbal communication skills are essential Proven background in IT risk assessments, and knowledge of good security practices and controls used in applications and infrastructure. Translate technical vulnerabilities and security risks into business risk terminology for business units and recommend corrective actions to customers and project stakeholders. Ability to document and produce important artefacts on risk assessments, engagement Statements of Work, process, minimum security baselines and presentations on security risks. Manage customer expectations and deliver quality security consulting services while balancing business objectives with security requirements. Ability to partner with technical teams in a practical manner when conflicting interests arise while preserving EY core security principles and policies. Ability to proactively lead, own and research security related subject matters when required to take a position or resolve issues. Ability to collaborate to facilitate and enhance the understanding & compliance to security policies. To qualify for the role, you must have A minimum of 8-10 years of experience in an Information Security or Information Technology subject area. Two or more years of experience with iOS and Android security such as mobile application security analysis, mobile application penetration testing, mobile threat modelling, mobile device forensics, and assessing mobile device security capabilities. Three or more years of experience with understanding and defining good security practices for end user technology platforms (e.g., iOS, Android, macOS, Windows 10), multi-tier information systems, applications (e.g., web, mobile, desktop), and End Point Security solutions. Working experience in performing security risk assessments for information systems and applications such as those for web, desktop, and mobile. Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or risk assessments. Good interpersonal, communication, organizational and project management skills. Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change. Ideally,you will also have One or more years of experience with iOS and Android mobile application development, Agile Methodology, Continuous Integration / Continuous Delivery, and IoT security. Knowledge or experience with Microsoft Azure cloud technology stack (e.g., M365, SharePoint, OneDrive for Business, Intune, Conditional Access) and Azure cloud applications. Knowledge of common information security standards and risk analysis methodologies, such as: ISO 27001/27002, NIST, PCI, COBIT, ISF IRAM2, and OWASP. What We Look For We look for people who are customer-centric with good interpersonal, communication and organizational skills. The ideal candidate will have flexibility in adjusting to multiple demands, shifting priorities, ambiguity, rapid change, and an ardent desire to learn. What We Offer As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here is a snapshot of what we offer: Continuous learning: You will develop the mindset and skills to navigate whatever comes next. Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way. Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Show more Show less
Posted 19 hours ago
0 years
0 Lacs
Trivandrum, Kerala, India
On-site
Job Family Advanced Business Analysis (India) Travel Required None Clearance Required None What You Will Do Utilizing technology to streamline processes and integrate different systems within an organization, including implementing software and tools to automate tasks, improve efficiency, and ensure seamless system integration. Ensuring smooth and high-quality delivery of software products to end users by coordinating release schedules, conducting quality assurance testing, and implementing processes to minimize the risk of errors in software releases. Tailoring and implementing technology solutions to meet the specific needs and expectations of clients, involving understanding client requirements, customizing solutions, and ensuring successful delivery and adoption of the technology. Participating in the design, development, and enhancement of software applications, including tasks such as coding, testing, debugging, and collaborating with team members to create software that meets user requirements and industry standards. What You Will Need Candidates from computer background (B.Tech Computer Science, B.Sc CS, BCA, etc.) Good communication and teamwork skills Knowledge in programming/scripting languages Understanding of database concepts and hands-on experience in SQL Knowledge of SDLC and Agile methodologies Knowledge in OOPs concepts Flexibility to learn and build new skill set, eagerness to stay updated Algorithms and Data Structures Strong problem-solving skills Positive attitude, commitment, and can-do approach Must be Trained, certified, or an intern with experience in the following technologies: Full-stack development (React, Angular, or Vue.js, GoLang, Python, Ruby on Rails, or Java Spring, MySQL, PostgreSQL), Cloud computing (AWS, Microsoft Azure, serverless computing, container orchestration, cloud databases) DevOps (Git, Jenkins, Docker, Kubernetes) Microservices architecture Vulnerability (OWASP) Agile methodologies (Scrum, Kanban, Jira) AI and machine learning (basic understanding of concepts and algorithms, integrating AI and machine learning features into applications). What Would Be Nice To Have You will receive a skills assessment sheet to share your proficiency. What We Offer Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace. About Guidehouse Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee. Show more Show less
Posted 19 hours ago
8.0 - 10.0 years
0 Lacs
Trivandrum, Kerala, India
On-site
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Senior Security Consultant Today’s world is fueled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team help protect the EY brand and build client trust. Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value. The opportunity As a Security Consultant, the individual will provide security guidance to internal IT project teams responsible for delivering business solutions, with a focus on end user technology and related solutions. They will identify and prioritize security-related requirements, promote secure-by-default designs and ensure information systems and infrastructure will be secured throughout the system development life cycle (SDLC) in an agile environment. Your Key Responsibilities The successful candidate is expected to perform risk assessments of mobile applications, mobile and desktop end user technology platforms, infrastructure systems and solutions; effectively articulate findings and recommendations to internal customers and management; and they will be expected to work on multiple projects and tasks concurrently. Skills And Attributes For Success Solid understanding of key security and privacy issues, risks and threats, and ability to apply this expertise across business needs via internal consulting and security risk assessment types of activities. Strong written and verbal communication skills are essential Proven background in IT risk assessments, and knowledge of good security practices and controls used in applications and infrastructure. Translate technical vulnerabilities and security risks into business risk terminology for business units and recommend corrective actions to customers and project stakeholders. Ability to document and produce important artefacts on risk assessments, engagement Statements of Work, process, minimum security baselines and presentations on security risks. Manage customer expectations and deliver quality security consulting services while balancing business objectives with security requirements. Ability to partner with technical teams in a practical manner when conflicting interests arise while preserving EY core security principles and policies. Ability to proactively lead, own and research security related subject matters when required to take a position or resolve issues. Ability to collaborate to facilitate and enhance the understanding & compliance to security policies. To qualify for the role, you must have A minimum of 8-10 years of experience in an Information Security or Information Technology subject area. Two or more years of experience with iOS and Android security such as mobile application security analysis, mobile application penetration testing, mobile threat modelling, mobile device forensics, and assessing mobile device security capabilities. Three or more years of experience with understanding and defining good security practices for end user technology platforms (e.g., iOS, Android, macOS, Windows 10), multi-tier information systems, applications (e.g., web, mobile, desktop), and End Point Security solutions. Working experience in performing security risk assessments for information systems and applications such as those for web, desktop, and mobile. Develop appropriate risk treatment and mitigation options to address security risks identified during security reviews or risk assessments. Good interpersonal, communication, organizational and project management skills. Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change. Ideally,you will also have One or more years of experience with iOS and Android mobile application development, Agile Methodology, Continuous Integration / Continuous Delivery, and IoT security. Knowledge or experience with Microsoft Azure cloud technology stack (e.g., M365, SharePoint, OneDrive for Business, Intune, Conditional Access) and Azure cloud applications. Knowledge of common information security standards and risk analysis methodologies, such as: ISO 27001/27002, NIST, PCI, COBIT, ISF IRAM2, and OWASP. What We Look For We look for people who are customer-centric with good interpersonal, communication and organizational skills. The ideal candidate will have flexibility in adjusting to multiple demands, shifting priorities, ambiguity, rapid change, and an ardent desire to learn. What We Offer As part of this role, you will work in a highly coordinated, globally diverse team with the opportunity and tools to grow, develop and drive your career forward. Here, you can combine global opportunity with flexible working. The EY benefits package goes above and beyond too, focusing on your physical, emotional, financial, and social well-being. Your recruiter can talk to you about the benefits available in your country. Here is a snapshot of what we offer: Continuous learning: You will develop the mindset and skills to navigate whatever comes next. Success as defined by you: We will provide the tools and flexibility, so you can make a significant impact, your way. Transformative leadership: We will give you the insights, coaching and confidence to be the leader the world needs. Diverse and inclusive culture: You will be accepted for who you are and empowered to use your voice to help others find theirs. EY | Building a better working world EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets. Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow. EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories. Show more Show less
Posted 19 hours ago
0 years
0 Lacs
Trivandrum, Kerala, India
On-site
Job Family Software Application & Development (India) Travel Required None Clearance Required None What You Will Do Utilizing technology to streamline processes and integrate different systems within an organization, including implementing software and tools to automate tasks, improve efficiency, and ensure seamless system integration. Ensuring smooth and high-quality delivery of software products to end users by coordinating release schedules, conducting quality assurance testing, and implementing processes to minimize the risk of errors in software releases. Tailoring and implementing technology solutions to meet the specific needs and expectations of clients, involving understanding client requirements, customizing solutions, and ensuring successful delivery and adoption of the technology. Participating in the design, development, and enhancement of software applications, including tasks such as coding, testing, debugging, and collaborating with team members to create software that meets user requirements and industry standards. What You Will Need Candidates from computer background (B.Tech Computer Science, B.Sc CS, BCA, etc.) Good communication and teamwork skills Knowledge in programming/scripting languages Understanding of database concepts and hands-on experience in SQL Knowledge of SDLC and Agile methodologies Knowledge in OOPs concepts Flexibility to learn and build new skill set, eagerness to stay updated Algorithms and Data Structures Strong problem-solving skills Positive attitude, commitment, and can-do approach Must be Trained, certified, or an intern with experience in the following technologies: Full-stack development (React, Angular, or Vue.js, GoLang, Python, Ruby on Rails, or Java Spring, MySQL, PostgreSQL), Cloud computing (AWS, Microsoft Azure, serverless computing, container orchestration, cloud databases) DevOps (Git, Jenkins, Docker, Kubernetes) Microservices architecture Vulnerability (OWASP) Agile methodologies (Scrum, Kanban, Jira) AI and machine learning (basic understanding of concepts and algorithms, integrating AI and machine learning features into applications). What Would Be Nice To Have Certifications on modern technologies What We Offer Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace. About Guidehouse Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee. Show more Show less
Posted 19 hours ago
3.0 years
0 Lacs
Pune, Maharashtra, India
On-site
Staff4Me is currently looking for a highly skilled and detail-oriented IT Security Test Engineer to join our team. As an IT Security Test Engineer, you will play a crucial role in ensuring the security and integrity of our systems and applications. You will be responsible for conducting security testing, identifying vulnerabilities, and providing recommendations for mitigation. Additionally, you will work closely with the development and operations teams to enhance security measures and drive continuous improvement. Responsibilities Design and execute security testing strategies and plans for applications, systems, and network infrastructure Identify vulnerabilities and security weaknesses through various testing techniques, including vulnerability scanning, penetration testing, and code review Work closely with the development and operations teams to address identified security issues and drive security enhancements Develop and optimize security testing tools and methodologies to ensure comprehensive coverage Create detailed test reports and documentation, including vulnerability findings, risk assessments, and remediation recommendations Stay up-to-date with the latest trends and advancements in information security and testing methodologies Collaborate with cross-functional teams to ensure compliance with industry standards and regulations Participate in incident response activities and provide support in handling security incidents Conduct security awareness training for employees and promote a culture of security awareness and compliance Requirements Bachelor's degree in Computer Science, Information Security, or a related field 3+ years of experience in IT security testing or a similar role Strong knowledge of security testing methodologies and tools, such as vulnerability scanning tools, penetration testing frameworks, and code review tools Experience in conducting vulnerability assessments, penetration testing, and security code reviews Knowledge of industry standards and best practices, such as OWASP, NIST, and CIS Familiarity with common security vulnerabilities and attack vectors Strong understanding of network protocols, operating systems, and web technologies Excellent analytical and problem-solving skills Attention to detail and ability to work independently Strong communication and collaboration skills Related certifications such as CEH, CISSP, or OSCP are preferred Show more Show less
Posted 19 hours ago
5.0 years
0 Lacs
Bengaluru, Karnataka, India
On-site
About QpiAI At QPiAI, we are leading the effort to discover optimal AI and Quantum systems in Life sciences, Healthcare, Transportation, Finance, Industrial, and Space technologies. QPiAI is building a full stack Enterprise Quantum Computers. QPiAI Quantum hardware team is responsible for designing and characterization of Quantum Processor, Cryogenic Quantum Control Circuits, RF Control Hardware, and QPiAI ASGP. Job Summary: We are looking for a skilled and proactive Cybersecurity Analyst/Engineer to protect the organization's digital assets, systems, and networks from cyber threats. The ideal candidate will be responsible for identifying security risks, monitoring security events, and implementing protective measures to ensure the confidentiality, integrity, and availability of information systems. Key Responsibilities: Monitor, analyze, and respond to security alerts and incidents. Conduct vulnerability assessments and penetration testing. Configure and maintain firewalls, antivirus software, and intrusion detection/prevention systems (IDS/IPS). Implement and enforce security policies, procedures, and best practices. Manage user access controls, multi-factor authentication, and identity management systems. Support compliance efforts for industry standards such as ISO 27001, GDPR, HIPAA, or NIST. Conduct regular audits and risk assessments to identify security gaps. Investigate and report on security breaches and incidents. Provide security awareness training for employees. Keep systems and security tools up to date with the latest patches and updates. Participate in disaster recovery and business continuity planning. Required Skills and Qualifications: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. 2–5 years of experience in a cybersecurity role (analyst, engineer, or equivalent). Strong knowledge of network security, endpoint protection, and cloud security principles. Experience with SIEM tools (e.g., Splunk, QRadar, LogRhythm). Familiarity with common threat intelligence platforms and frameworks (MITRE ATT&CK, OWASP). Understanding of firewalls, VPNs, IDS/IPS, and endpoint detection and response (EDR). Working knowledge of operating systems (Windows, Linux) and scripting languages (PowerShell, Python) is a plus. Relevant certifications such as CompTIA Security+, CEH, CISSP, or CISM are preferred. Soft Skills: Strong analytical and problem-solving skills. Excellent communication and documentation abilities. Ability to work independently and collaboratively in a team environment. Attention to detail and ability to manage multiple tasks effectively. Show more Show less
Posted 19 hours ago
3.0 years
0 Lacs
Coimbatore, Tamil Nadu, India
On-site
Job Title: VAPT Consultant Location: Coimbatore (Work from Office) Experience: 3+ years Availability: Immediate Joiners Preferred Job Description: We are looking for a skilled Vulnerability Assessment and Penetration Testing (VAPT) Consultant to join our team in Coimbatore. The ideal candidate will have a solid understanding of information security principles and hands-on experience in identifying and exploiting vulnerabilities across a variety of platforms. Key Responsibilities: Conduct end-to-end VAPT assessments for web applications, networks, APIs, cloud, and mobile applications Identify security vulnerabilities and provide detailed risk analysis reports Recommend appropriate remediation measures and assist in retesting Maintain documentation of all testing results, tools used, and findings Collaborate with clients and internal teams to ensure implementation of security best practices Stay updated with the latest vulnerabilities, exploits, and security trends Requirements: Minimum 3 years of relevant experience in VAPT Strong knowledge of tools like Burp Suite, Nessus, Metasploit, Nmap, etc. Familiarity with OWASP Top 10 and SANS CWE Good communication and reporting skills Certifications like CEH, OSCP (preferred but not mandatory) Show more Show less
Posted 20 hours ago
0 years
0 Lacs
Bengaluru, Karnataka, India
On-site
Job Description Product Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software architecture and should be able to perform manual security code review. They need to be able to integrate security in the software development process with defense-in-depth strategies such as automated testing in CI/CD pipeline. A Product Security Engineer preferably needs to have a software development background and should have practical programming knowledge. They will work very closely with our Software Engineering Team to implement Secure SDLC in Traveloka. They will also need to have proficiency in handling multiple projects based on different frameworks and groups. Responsibilities Carry out manual and automated review of source code to identify security vulnerabilities and risks Implement automated security testing tools (SAST, DAST, IAST) and their deployment within continuous integration systems Implement hardening and secure framework such as RASP, WAF, safe library, and security decorator functions Perform vulnerability assessment & penetration testing on web API, front-end service, internal RPC, and mobile application Attend design reviews and actively lead the discussions from a security standpoint Analyze possible security incident related to application security such as payment abuse or sensitive data exposure via web API Ensure that product security requirements are identified early on and are being baked into all projects Provide effective recommendations or patches to mitigate security vulnerabilities Develop in-house tools to integrate with SDLC and to track and derive security metrics Skills & Experience Academic background in Computer Science or equivalent Relevant professional experience or extensive experience in security activities (e.g. CTF, bug bounty, security research, publications, blog) Practical knowledge of modern software development such as microservices, application containerization, REST architecture, object oriented programming, stateless/stateful authentication, and cloud platform Working knowledge of one or more of these programming languages: Java, JavaScript, Kotlin, C#, Objective-C, Swift Experience in security code review, vulnerability assessment, and penetration testing. Knowledge of common vulnerabilities such as OWASP Top 10 and CWE including business logic issue (e.g. IDOR) Core skill set in two or more of the following areas: JavaScript framework (e.g. React) Java framework (e.g. Spring) Android / iOS platform DevOps AWS Automation tool development Dynamic debugging Unit testing Algorithm & data structure If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us! Show more Show less
Posted 20 hours ago
2.0 years
0 Lacs
Mumbai, Maharashtra, India
On-site
Job description As a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying vulnerabilities, and implementing effective remediation strategies. Leveraging your expertise in penetration testing and ethical hacking, you will play a key role in enhancing the security posture of our clients' systems and networks. This position offers an exciting opportunity to work on challenging projects, collaborate with talented professionals, and contribute to the advancement of cybersecurity practices. Key Responsibilities : Perform end-to-end Vulnerability Assessment and Penetration Testing (VAPT) for clients' IT infrastructure, applications, and networks. Conduct thorough security assessments using industry-standard tools and methodologies, including but not limited to, Nmap, Nessus, Metasploit, Burp Suite, and OWASP. Identify and exploit security vulnerabilities to assess the potential impact on clients' systems and data. Prepare detailed assessment reports outlining findings, risk levels, and recommended remediation measures. Collaborate with clients' IT teams to prioritize and address identified security issues in a timely manner. Develop and implement custom scripts or tools to enhance testing capabilities and automate repetitive tasks. Stay abreast of emerging security threats, vulnerabilities, and industry best practices to continually improve testing methodologies. Provide guidance and mentorship to junior security engineers, fostering a culture of knowledge sharing and skill development within the team. Requirements: Bachelor's degree in Computer Science, Information Technology, or related field. 2+ years of experience in cybersecurity, with a focus on Vulnerability Assessment and Penetration Testing. Proficiency in using tools such as Nmap, Nessus, Metasploit, Burp Suite, and OWASP. Hands-on experience with various operating systems, including Windows, Linux, and Unix. Strong understanding of network protocols, web application architecture, and common security vulnerabilities. Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), or similar certifications preferred. Excellent analytical skills and attention to detail, with the ability to prioritize and manage multiple tasks effectively. Effective communication skills, both verbal and written, with the ability to convey technical concepts to non-technical stakeholders. Proven track record of delivering high-quality security assessments and actionable recommendations. Show more Show less
Posted 21 hours ago
7.0 years
0 Lacs
Serilingampalli, Telangana, India
On-site
Description Cybersecurity Solutions Architect Syneos Health® is a leading fully integrated biopharmaceutical solutions organization built to accelerate customer success. We translate unique clinical, medical affairs and commercial insights into outcomes to address modern market realities. Every day we perform better because of how we work together, as one team, each the best at what we do. We bring a wide range of talented experts together across a wide range of business-critical services that support our business. Every role within Corporate is vital to furthering our vision of Shortening the Distance from Lab to Life®. Discover what our 29,000 employees, across 110 countries already know. WORK HERE MATTERS EVERYWHERE Why Syneos Health We are passionate about developing our people, through career development and progression; supportive and engaged line management; technical and therapeutic area training; peer recognition and total rewards program. We are committed to our Total Self culture – where you can authentically be yourself. Our Total Self culture is what unites us globally, and we are dedicated to taking care of our people. We are continuously building the company we all want to work for and our customers want to work with. Why? Because when we bring together diversity of thoughts, backgrounds, cultures, and perspectives – we’re able to create a place where everyone feels like they belong. Job Responsibilities JOB SUMMARY The Cyber Security Solution Architect will be responsible for transforming the way Syneos Health protects applications, software and code that it uses to support the company to accelerate patient therapies to market and thereby increase cyber threat resiliency. This role will be a member of the Office of the CISO and a member of enterprise security architects. As a key subject matter expert and leader within the team, this role will use a data and risk-based approach to driving enterprise initiatives, formulating requirements, patterns, and solutions to achieve risk mitigation. To be successful, this role will act as a technical influencer, build cross-functional and organizational partnerships to deliver modern security engineering and operational solutions. As an architect you will partner with the software engineering organization to design software security solutions, participate in proof of concepts and enable the engineering organization to deliver secure, operational solutions. The role will own the software security program and initiatives and be responsible for reporting on progress to leadership and stakeholders. The scope of responsibility includes but not limited to supporting the transformation of security engineering into the early phases of enterprise delivery through defined Secure SDLC, Source code management, application security, and the transformation of DevSecOps across the enterprise. The role will bring an everything-as-code security mindset to be applied across applications, API’s and platform engineering. To be successful, the role will need to define and identify technical and business risks along with enterprise requirements that can be consumed by a shared-responsibility model for engineering and operational controls. Be a transformation agent by advocating for modern secure engineering principles and automation. Excellent oral and written communication skills, as well as effective organizational abilities, are essential due to the detailed and time-bound nature of the work and the extensive collaboration with others. Job Responsibilities Mature and modernize the enterprise software security program and initiatives to manage risks and enable technology solutions: Use a data-driven approach to identifying areas of risk Publish metrics and KPI’s Set enterprise requirements for secure software development based on common cyber security frameworks such as NIST, Hitrust, CSF. SafeCode, OWASP etc Contribute to enterprise security policies and standards. Evolve Secure SDLC standards and processes Define, own, and drive the company's software security strategy and roadmap, acting as the key security voice for software security Partner with software and platform engineering teams to: Promote DevSecOps solutions and culture Establish secure code management practices Improve automated CI/CD pipelines with appropriate security services Automate enterprise security requirements into backlogs Champion cloud application and platform security engineering practices. Delivery enterprise security patterns for software engineering Participate in Proof of Concepts with the software engineering organization . Educate and drive engagement of modern secure software principles within the organization by: Being a strategic advisor in software security. Being a transformation agent in promoting a modern security engineering mindset. Performing design reviews to identify security architecture flaws. Qualification Requirements What we are looking for: 5–7 years of experience in software security or related roles. Proven track record building and transforming secure software and platform engineering practices Building road maps and creating initiatives to address enterprise goals. Experience partnering with engineering teams to achieve security goals. Strong familiarity with source code management Strong familiarity software exploitation techniques and Mitre @ttack framework. Strong knowledge of cloud platform security (AWS, Azure, Oracle Infrastructure Cloud) Someone with strong engineering mindset that software engineering experience Experience implementing pipeline automation and source code management Additional Standout Skills Hands-on experience with modern engineering technologies such as Kubernetes and Containers Experience with securing Terraform or other IaC platforms Delivered secure coding practices to large engineering teams Familiar with API Security Enabling DevSecOps within large organizations Education. Security Architecture TOGAF/SABSA Cloud security certifications for OCI, AWS or Azure (Azure preferred) Get to know Syneos Health Over the past 5 years, we have worked with 94% of all Novel FDA Approved Drugs, 95% of EMA Authorized Products and over 200 Studies across 73,000 Sites and 675,000+ Trial patients. No matter what your role is, you’ll take the initiative and challenge the status quo with us in a highly competitive and ever-changing environment. Learn more about Syneos Health. http://www.syneoshealth.com Additional Information Tasks, duties, and responsibilities as listed in this job description are not exhaustive. The Company, at its sole discretion and with no prior notice, may assign other tasks, duties, and job responsibilities. Equivalent experience, skills, and/or education will also be considered so qualifications of incumbents may differ from those listed in the Job Description. The Company, at its sole discretion, will determine what constitutes as equivalent to the qualifications described above. Further, nothing contained herein should be construed to create an employment contract. Occasionally, required skills/experiences for jobs are expressed in brief terms. Any language contained herein is intended to fully comply with all obligations imposed by the legislation of each country in which it operates, including the implementation of the EU Equality Directive, in relation to the recruitment and employment of its employees. The Company is committed to compliance with the Americans with Disabilities Act, including the provision of reasonable accommodations, when appropriate, to assist employees or applicants to perform the essential functions of the job. Summary JOB SUMMARY The Cyber Security Solution Architect will be responsible for transforming the way Syneos Health protects applications, software and code that it uses to support the company to accelerate patient therapies to market and thereby increase cyber threat resiliency. This role will be a member of the Office of the CISO and a member of enterprise security architects. As a key subject matter expert and leader within the team, this role will use a data and risk-based approach to driving enterprise initiatives, formulating requirements, patterns, and solutions to achieve risk mitigation. To be successful, this role will act as a technical influencer, build cross-functional and organizational partnerships to deliver modern security engineering and operational solutions. As an architect you will partner with the software engineering organization to design software security solutions, participate in proof of concepts and enable the engineering organization to deliver secure, operational solutions. The role will own the software security program and initiatives and be responsible for reporting on progress to leadership and stakeholders. The scope of responsibility includes but not limited to supporting the transformation of security engineering into the early phases of enterprise delivery through defined Secure SDLC, Source code management, application security, and the transformation of DevSecOps across the enterprise. The role will bring an everything-as-code security mindset to be applied across applications, API’s and platform engineering. To be successful, the role will need to define and identify technical and business risks along with enterprise requirements that can be consumed by a shared-responsibility model for engineering and operational controls. Be a transformation agent by advocating for modern secure engineering principles and automation. Excellent oral and written communication skills, as well as effective organizational abilities, are essential due to the detailed and time-bound nature of the work and the extensive collaboration with others. Show more Show less
Posted 22 hours ago
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
Accenture
36723 Jobs | Dublin
Wipro
11788 Jobs | Bengaluru
EY
8277 Jobs | London
IBM
6362 Jobs | Armonk
Amazon
6322 Jobs | Seattle,WA
Oracle
5543 Jobs | Redwood City
Capgemini
5131 Jobs | Paris,France
Uplers
4724 Jobs | Ahmedabad
Infosys
4329 Jobs | Bangalore,Karnataka
Accenture in India
4290 Jobs | Dublin 2