Get alerts for new jobs matching your selected skills, preferred locations, and experience range.
3.0 years
0 Lacs
Mumbai, Maharashtra, India
On-site
About BNP Paribas India Solutions Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, European Union’s leading bank with an international reach. With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center. India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group. Driving innovation and growth, we are harnessing the potential of over 10000 employees, to provide support and develop best-in-class solutions. About BNP Paribas Group BNP Paribas is the European Union’s leading bank and key player in international banking. It operates in 65 countries and has nearly 185,000 employees, including more than 145,000 in Europe. The Group has key positions in its three main fields of activity: Commercial, Personal Banking & Services for the Group’s commercial & personal banking and several specialised businesses including BNP Paribas Personal Finance and Arval; Investment & Protection Services for savings, investment, and protection solutions; and Corporate & Institutional Banking, focused on corporate and institutional clients. Based on its strong diversified and integrated model, the Group helps all its clients (individuals, community associations, entrepreneurs, SMEs, corporates and institutional clients) to realize their projects through solutions spanning financing, investment, savings and protection insurance. In Europe, BNP Paribas has four domestic markets: Belgium, France, Italy, and Luxembourg. The Group is rolling out its integrated commercial & personal banking model across several Mediterranean countries, Turkey, and Eastern Europe. As a key player in international banking, the Group has leading platforms and business lines in Europe, a strong presence in the Americas as well as a solid and fast-growing business in Asia-Pacific. BNP Paribas has implemented a Corporate Social Responsibility approach in all its activities, enabling it to contribute to the construction of a sustainable future, while ensuring the Group's performance and stability Commitment to Diversity and Inclusion At BNP Paribas, we passionately embrace diversity and are committed to fostering an inclusive workplace where all employees are valued, respected and can bring their authentic selves to work. We prohibit Discrimination and Harassment of any kind and our policies promote equal employment opportunity for all employees and applicants, irrespective of, but not limited to their gender, gender identity, sex, sexual orientation, ethnicity, race, colour, national origin, age, religion, social status, mental or physical disabilities, veteran status etc. As a global Bank, we truly believe that inclusion and diversity of our teams is key to our success in serving our clients and the communities we operate in. About Business Line/Function ITG provides testing services for the BNP Paribas Group. The Security testing team is responsible to execute Penetration Tests (Black or Gray Box), SAST, SCA, Mobile Testing for the applications pertaining to the group Job Title Security Test Engineer Date 21-Oct-2024 Department ITG Location: Mumbai Business Line / Function ITG Security Testing Reports To (Direct) Grade (if applicable) (Functional) Number Of Direct Reports Directorship / Registration: NA Position Purpose Provide a brief description of the overall purpose of the position, why this position exists and how it will contribute in achieving the team’s goal. Responsibilities Direct Responsibilities Direct Responsibilities To perform Penetration testing (Gray Box and/or Black Box) for Web applications; Thick Client, API, and mobile applications. To understand the application’s security requirements and identify & document the scope of the test Ensure execution of the documented security scenarios for the application under test. Document and report all findings Collaborate with the developers to help them understand the vulnerabilities reported in application Escalate issues to the local management and onshore stakeholders in case it affects the testing progress Ensure processes for the project is followed for the assessments Note Optional, experience in Source Code Assessment (SCA)/SAST, Mobile Testing Contributing Responsibilities Technical & Behavioral Competencies Clear understanding of OWASP Top 10 - application security risks Tools/OS: Burp Suite, OWASP ZAP, Kali Linux Manual Security Testing & Analysis, Security Test Designing Excellent Inter personal and presentation skills Strong in verbal and written communication Good analytical skills Strong Time Management Must be flexible, independent, self-motivated Team player Specific Qualifications (if Required) CSSLP/CEH or equivalent certification preferred Skills Referential Behavioural Skills: (Please select up to 4 skills) Choose an item. Choose an item. Choose an item. Choose an item. Transversal Skills: (Please select up to 5 skills) Choose an item. Choose an item. Choose an item. Choose an item. Choose an item. Education Level Bachelor Degree or equivalent Experience Level At Least 3 years Show more Show less
Posted 3 weeks ago
5.0 years
0 Lacs
Greater Kolkata Area
Remote
About Smart Working At Smart Working, we believe your job should not only look right on paper but also feel right every day. This isn’t just another remote role — it’s belonging remotely, and that’s a big difference. From day one, you're part of a genuine community where you’re supported and valued. We’re proud to be one of the highest-rated companies on Glassdoor India. With one vision in mind — “Geographical limitations should not dictate access to talent” — Smart Working helps great people build long-term, full-time remote careers with exceptional UK teams. We’ve created a culture where you're backed from day one and given the space to grow — personally and professionally. About the Role We’re hiring a Senior PHP/Symfony Developer for a company specializing in mission-critical aviation systems and advanced fuel management solutions. In this role, you will focus on developing and maintaining backend systems using PHP, Symfony, and PHPUnit, ensuring optimal performance across digital platforms. You will work on implementing robust, secure backend architectures that align with business requirements while maintaining reliability, maintainability, and code quality within an Agile environment. This is a permanent, full-time, remote role —perfect for a technically driven developer who thrives in a hands-on environment, building mission-critical backend systems that support global aviation operations. What You’ll Be Doing Build & Run Our Products— Collaborate across teams to align business, technical, and testing goals Estimate and plan tasks collaboratively to ensure delivery confidence Review specs, design solutions, and deliver high-impact features Monitor, deploy, and troubleshoot features in staging and production Own incidents during on-call rotations, ensuring rapid resolution Ensure High Quality & Continuously Improve— Uphold and enforce coding and testing standards Break down complex work into manageable tasks for better delivery Conduct code reviews, ensure test coverage, and maintain strong documentation Stay up to date on tools, libraries, and secure coding practices (OWASP) Provide Technical Excellence & Leadership— Break down epics, design scalable APIs and systems Mentor peers on TDD, BDD, DDD, and best practices Identify risks, drive automation, and recommend process improvements Champion clean, modular, and maintainable architecture Must-Have Skills PHP (5+ years) Symfony (at least 1 year of experience with one hands-on project) PHPUnit (for testing) (1.5+ years) Nice-to-Have Skills MongoDB (2+ years ) Docker Kubernetes JavaScript JQuery React API NodeJS Typescript What Sets You Apart Backend Expertise in PHP, Symfony, and PHPUnit, delivering scalable, high-quality solutions Efficient Problem-Solving, breaking down complexity for timely, reliable delivery Proactive Mindset, driving improvements through thoughtful, hands-on solutions Team Player & Mentor, sharing knowledge and upholding best practices Operational Readiness, responding swiftly during on-call rotations Quality-Focused, with clean code, thorough reviews, and strong documentation Adaptable & Growth-Oriented, staying current with tools and driving innovation Why Smart Workers Love It Here Fixed Shifts — 12:00 PM – 9:30 PM IST (Summer) | 1:00 PM – 10:30 PM IST (Winter) No Weekend Work — Real work-life balance, not just words Day 1 Benefits — Laptop and full medical insurance provided Support That Matters — Mentorship, community, and forums where ideas are shared True Belonging — A long-term home where your contributions are valued At Smart Working, you’ll never be just another remote hire. Be a Smart Worker — valued, empowered, and part of a culture that celebrates integrity, excellence, and ambition. If you’re ready to make a meaningful impact in aviation technology while working with a team that values excellence and integrity, we’d love to hear from you. 🧡 Show more Show less
Posted 3 weeks ago
5.0 years
0 Lacs
Kochi, Kerala, India
Remote
About Smart Working At Smart Working, we believe your job should not only look right on paper but also feel right every day. This isn’t just another remote role — it’s belonging remotely, and that’s a big difference. From day one, you're part of a genuine community where you’re supported and valued. We’re proud to be one of the highest-rated companies on Glassdoor India. With one vision in mind — “Geographical limitations should not dictate access to talent” — Smart Working helps great people build long-term, full-time remote careers with exceptional UK teams. We’ve created a culture where you're backed from day one and given the space to grow — personally and professionally. About the Role We’re hiring a Senior PHP/Symfony Developer for a company specializing in mission-critical aviation systems and advanced fuel management solutions. In this role, you will focus on developing and maintaining backend systems using PHP, Symfony, and PHPUnit, ensuring optimal performance across digital platforms. You will work on implementing robust, secure backend architectures that align with business requirements while maintaining reliability, maintainability, and code quality within an Agile environment. This is a permanent, full-time, remote role —perfect for a technically driven developer who thrives in a hands-on environment, building mission-critical backend systems that support global aviation operations. What You’ll Be Doing Build & Run Our Products— Collaborate across teams to align business, technical, and testing goals Estimate and plan tasks collaboratively to ensure delivery confidence Review specs, design solutions, and deliver high-impact features Monitor, deploy, and troubleshoot features in staging and production Own incidents during on-call rotations, ensuring rapid resolution Ensure High Quality & Continuously Improve— Uphold and enforce coding and testing standards Break down complex work into manageable tasks for better delivery Conduct code reviews, ensure test coverage, and maintain strong documentation Stay up to date on tools, libraries, and secure coding practices (OWASP) Provide Technical Excellence & Leadership— Break down epics, design scalable APIs and systems Mentor peers on TDD, BDD, DDD, and best practices Identify risks, drive automation, and recommend process improvements Champion clean, modular, and maintainable architecture Must-Have Skills PHP (5+ years) Symfony (at least 1 year of experience with one hands-on project) PHPUnit (for testing) (1.5+ years) Nice-to-Have Skills MongoDB (2+ years ) Docker Kubernetes JavaScript JQuery React API NodeJS Typescript What Sets You Apart Backend Expertise in PHP, Symfony, and PHPUnit, delivering scalable, high-quality solutions Efficient Problem-Solving, breaking down complexity for timely, reliable delivery Proactive Mindset, driving improvements through thoughtful, hands-on solutions Team Player & Mentor, sharing knowledge and upholding best practices Operational Readiness, responding swiftly during on-call rotations Quality-Focused, with clean code, thorough reviews, and strong documentation Adaptable & Growth-Oriented, staying current with tools and driving innovation Why Smart Workers Love It Here Fixed Shifts — 12:00 PM – 9:30 PM IST (Summer) | 1:00 PM – 10:30 PM IST (Winter) No Weekend Work — Real work-life balance, not just words Day 1 Benefits — Laptop and full medical insurance provided Support That Matters — Mentorship, community, and forums where ideas are shared True Belonging — A long-term home where your contributions are valued At Smart Working, you’ll never be just another remote hire. Be a Smart Worker — valued, empowered, and part of a culture that celebrates integrity, excellence, and ambition. If you’re ready to make a meaningful impact in aviation technology while working with a team that values excellence and integrity, we’d love to hear from you. 🧡 Show more Show less
Posted 3 weeks ago
5.0 years
0 Lacs
Ahmedabad, Gujarat, India
Remote
About Smart Working At Smart Working, we believe your job should not only look right on paper but also feel right every day. This isn’t just another remote role — it’s belonging remotely, and that’s a big difference. From day one, you're part of a genuine community where you’re supported and valued. We’re proud to be one of the highest-rated companies on Glassdoor India. With one vision in mind — “Geographical limitations should not dictate access to talent” — Smart Working helps great people build long-term, full-time remote careers with exceptional UK teams. We’ve created a culture where you're backed from day one and given the space to grow — personally and professionally. About the Role We’re hiring a Senior PHP/Symfony Developer for a company specializing in mission-critical aviation systems and advanced fuel management solutions. In this role, you will focus on developing and maintaining backend systems using PHP, Symfony, and PHPUnit, ensuring optimal performance across digital platforms. You will work on implementing robust, secure backend architectures that align with business requirements while maintaining reliability, maintainability, and code quality within an Agile environment. This is a permanent, full-time, remote role —perfect for a technically driven developer who thrives in a hands-on environment, building mission-critical backend systems that support global aviation operations. What You’ll Be Doing Build & Run Our Products— Collaborate across teams to align business, technical, and testing goals Estimate and plan tasks collaboratively to ensure delivery confidence Review specs, design solutions, and deliver high-impact features Monitor, deploy, and troubleshoot features in staging and production Own incidents during on-call rotations, ensuring rapid resolution Ensure High Quality & Continuously Improve— Uphold and enforce coding and testing standards Break down complex work into manageable tasks for better delivery Conduct code reviews, ensure test coverage, and maintain strong documentation Stay up to date on tools, libraries, and secure coding practices (OWASP) Provide Technical Excellence & Leadership— Break down epics, design scalable APIs and systems Mentor peers on TDD, BDD, DDD, and best practices Identify risks, drive automation, and recommend process improvements Champion clean, modular, and maintainable architecture Must-Have Skills PHP (5+ years) Symfony (at least 1 year of experience with one hands-on project) PHPUnit (for testing) (1.5+ years) Nice-to-Have Skills MongoDB (2+ years ) Docker Kubernetes JavaScript JQuery React API NodeJS Typescript What Sets You Apart Backend Expertise in PHP, Symfony, and PHPUnit, delivering scalable, high-quality solutions Efficient Problem-Solving, breaking down complexity for timely, reliable delivery Proactive Mindset, driving improvements through thoughtful, hands-on solutions Team Player & Mentor, sharing knowledge and upholding best practices Operational Readiness, responding swiftly during on-call rotations Quality-Focused, with clean code, thorough reviews, and strong documentation Adaptable & Growth-Oriented, staying current with tools and driving innovation Why Smart Workers Love It Here Fixed Shifts — 12:00 PM – 9:30 PM IST (Summer) | 1:00 PM – 10:30 PM IST (Winter) No Weekend Work — Real work-life balance, not just words Day 1 Benefits — Laptop and full medical insurance provided Support That Matters — Mentorship, community, and forums where ideas are shared True Belonging — A long-term home where your contributions are valued At Smart Working, you’ll never be just another remote hire. Be a Smart Worker — valued, empowered, and part of a culture that celebrates integrity, excellence, and ambition. If you’re ready to make a meaningful impact in aviation technology while working with a team that values excellence and integrity, we’d love to hear from you. 🧡 Show more Show less
Posted 3 weeks ago
5.0 years
0 Lacs
Jaipur, Rajasthan, India
Remote
About Smart Working At Smart Working, we believe your job should not only look right on paper but also feel right every day. This isn’t just another remote role — it’s belonging remotely, and that’s a big difference. From day one, you're part of a genuine community where you’re supported and valued. We’re proud to be one of the highest-rated companies on Glassdoor India. With one vision in mind — “Geographical limitations should not dictate access to talent” — Smart Working helps great people build long-term, full-time remote careers with exceptional UK teams. We’ve created a culture where you're backed from day one and given the space to grow — personally and professionally. About the Role We’re hiring a Senior PHP/Symfony Developer for a company specializing in mission-critical aviation systems and advanced fuel management solutions. In this role, you will focus on developing and maintaining backend systems using PHP, Symfony, and PHPUnit, ensuring optimal performance across digital platforms. You will work on implementing robust, secure backend architectures that align with business requirements while maintaining reliability, maintainability, and code quality within an Agile environment. This is a permanent, full-time, remote role —perfect for a technically driven developer who thrives in a hands-on environment, building mission-critical backend systems that support global aviation operations. What You’ll Be Doing Build & Run Our Products— Collaborate across teams to align business, technical, and testing goals Estimate and plan tasks collaboratively to ensure delivery confidence Review specs, design solutions, and deliver high-impact features Monitor, deploy, and troubleshoot features in staging and production Own incidents during on-call rotations, ensuring rapid resolution Ensure High Quality & Continuously Improve— Uphold and enforce coding and testing standards Break down complex work into manageable tasks for better delivery Conduct code reviews, ensure test coverage, and maintain strong documentation Stay up to date on tools, libraries, and secure coding practices (OWASP) Provide Technical Excellence & Leadership— Break down epics, design scalable APIs and systems Mentor peers on TDD, BDD, DDD, and best practices Identify risks, drive automation, and recommend process improvements Champion clean, modular, and maintainable architecture Must-Have Skills PHP (5+ years) Symfony (at least 1 year of experience with one hands-on project) PHPUnit (for testing) (1.5+ years) Nice-to-Have Skills MongoDB (2+ years ) Docker Kubernetes JavaScript JQuery React API NodeJS Typescript What Sets You Apart Backend Expertise in PHP, Symfony, and PHPUnit, delivering scalable, high-quality solutions Efficient Problem-Solving, breaking down complexity for timely, reliable delivery Proactive Mindset, driving improvements through thoughtful, hands-on solutions Team Player & Mentor, sharing knowledge and upholding best practices Operational Readiness, responding swiftly during on-call rotations Quality-Focused, with clean code, thorough reviews, and strong documentation Adaptable & Growth-Oriented, staying current with tools and driving innovation Why Smart Workers Love It Here Fixed Shifts — 12:00 PM – 9:30 PM IST (Summer) | 1:00 PM – 10:30 PM IST (Winter) No Weekend Work — Real work-life balance, not just words Day 1 Benefits — Laptop and full medical insurance provided Support That Matters — Mentorship, community, and forums where ideas are shared True Belonging — A long-term home where your contributions are valued At Smart Working, you’ll never be just another remote hire. Be a Smart Worker — valued, empowered, and part of a culture that celebrates integrity, excellence, and ambition. If you’re ready to make a meaningful impact in aviation technology while working with a team that values excellence and integrity, we’d love to hear from you. 🧡 Show more Show less
Posted 3 weeks ago
2.0 - 4.0 years
1 - 6 Lacs
Pune
Work from Office
Role & responsibilities - Perform Application Security Testing - Perform Network Penetration Testing - Perform Vulnerability Assessment of Servers - Verify Scan results through manual testing - Co-ordinate with the clients for Project related queries - Undertake meeting with the client teams for discussing security issues and recommendations - Create detailed security reports - Keep track of project progress & send regular updates - Research on security tools - Create Security Knowledge base for the team - Participate in quality initiatives. Location: Pune-On Site Required Knowledge Areas: Web Application Security OWASP Top 10 Mobile Application Security – Mobile OWASP Top 10 NMAP/Port Scanning Vulnerability Scanning & Verification Web Traffic Interception (For Web/Mobile apps) SSL Security Tools Experience: Working knowledge of following tools is needed: Web Proxy Editors Network Sniffers Nessus Scanner Reverse Engineering Tools Mobile Application security tools – Either Android/IOS Any one Web Application Security Scanner. Certification Requirement: The candidate must possess any one of the following certifications: CEH/ ECSA/ OSCP Other Skills: The candidate should be good in: Documentation Communication Skills. Interested candidate can share their resume on hr@synradar.com or can connect on 8655620119 Immediate joiners are preferred
Posted 3 weeks ago
5.0 years
0 Lacs
Bengaluru, Karnataka, India
On-site
Product Engineer (Full stack) Deployment Location – HSR , Propelld About Company : Propelld is a company (formed in 2017) in the Education financing space backed by WestBridge Capital, Stellaris Ventures and India Quotient. The investors of Propelld are also backers of strong f inancial services companies (Bajaj, AU small finance bank, Cibil, Aptus, India Shelter Finance, 5 star Insurance, etc) and consumer internet companies (MamaEarth, Sharechat, Jiva, etc) Role Overview As a Fullstack Developer-SDE III/IV at Propelld, you will be responsible for designing and developing customer-facing UIs, robust APIs, and secure backend services. You’ll work across the stack — from UI to backend to databases — and collaborate closely with SREs and data engineers to deliver a seamless and secure loan journey. Our tech stack : React, Next.js, Node.js/Express, or Python/FastAPI, PostgreSQL,AWS A day in the life Develop clean code that meets the business needs as well stands test of time Willingness to take calculated risk to move faster Influence the design choices made in the team Responsibilities : • Develop responsive, accessible, and high-performance UIs using React/Next.js, ensuring pixel-perfect designs and seamless cross-device experiences. • Design, build, and maintain RESTful APIs & microservices using Node.js (Express) or Python (FastAPI), optimizing for performance, scalability, and security (OWASP, PCI-DSS compliance). • Work with PostgreSQL & MongoDB to design efficient database schemas, write optimized queries, and ensure data consistency. • Implement security best practices, including PII/financial data protection, RBAC, and secure API handling. • Collaborate with SREs to ensure high availability, scalability, and low-latency systems. • Uphold code quality through modular architecture, code reviews, and mentoring junior developers. Required Skills & Experience Must-Have: • 5+ years of experience in full stack development with a strong grasp of both frontend and backend technologies. • B. E/B. Tech/M. E. /M. Tech/M. S. from a reputed university with a good academic record. • Proficiency in React, Next.js, or similar frontend frameworks. • Strong expertise in Node.js/Express, or Python/FastAPI. • Good understanding of RESTful APIs, microservices, and API security. • Hands-on experience with SQL/NoSQL databases (PostgreSQL, MongoDB). • Exposure to cloud services such as AWS (S3, Lambda, RDS, etc.). Bonus (Good to Have): • Experience with Docker, Kubernetes, and CI/CD pipelines. • Familiarity with fintech or NBFC platforms and data security standards. Why Explore a Career at Propelld Life at Propelld: ● Competitive salary ● Flexible working hours are key. We want to have as much fun after work as you do - and more! ● A comprehensive healthcare plan that takes care of our employees and their dependents. Your health is a priority for us ● We value you for more than just your job. We celebrate your diligence and achievements throughout the year. Exciting rewards await! ● Designed holiday and leave policies so you can live life to the full. (And maybe even tick off those travel goals) ● Learn and grow with us. Meticulously designed learning opportunities to help everyone scale with current and future market standards. ● Who says companies can be boring when you've got delicious food, fun games and a cool office that makes you feel like you don't want to leave the office anytime soon? Show more Show less
Posted 3 weeks ago
4.0 years
0 Lacs
Hyderabad, Telangana, India
On-site
Looking for a skilled & experienced freelance VA&PT Specialists to perform our VA&PT tasks. Candidate should have minimum 4 years of experience in VAPT roles and should capable to perform VA&PT Tasks independently, and can able to generate VAPT &, CAP reports. Independent VAPT consultants, or a small team of fascinating VAPT experts can apply as a single team. Key Responsibilities • Conduct Vulnerability Assessments using tools like Nessus, Qualys, OpenVAS • Perform Penetration Testing on web applications, networks, APIs, and mobile platforms • Simulate real-world attacks to uncover security gaps and provide actionable recommendations • Prepare detailed technical reports and executive summaries of findings • Collaborate with development, infrastructure, and security teams to address vulnerabilities • Stay updated on emerging threats, vulnerabilities, and attack techniques • Support compliance audits and security assessments (e.g., ISO 27001, PCI-DSS) Skill Set & Requirements • Minimum 4 years of hands-on experience in Red Teaming and VA&PT activities • Ability to independently handle on-call tasks, conduct VA&PT, and deliver comprehensive reports • Deep understanding of network protocols, web technologies, and operating systems • Proficient with tools like Burp Suite, Metasploit, Nmap, Wireshark, Nikto, etc. • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVE databases How to Apply Send your CV to careers@isstechnologies.in with Job Code: CVPT4-0625 in the subject line. Show more Show less
Posted 3 weeks ago
0 years
0 Lacs
Gurgaon, Haryana, India
On-site
Who We Are Boston Consulting Group partners with leaders in business and society to tackle their most important challenges and capture their greatest opportunities. BCG was the pioneer in business strategy when it was founded in 1963. Today, we help clients with total transformation-inspiring complex change, enabling organizations to grow, building competitive advantage, and driving bottom-line impact. To succeed, organizations must blend digital and human capabilities. Our diverse, global teams bring deep industry and functional expertise and a range of perspectives to spark change. BCG delivers solutions through leading-edge management consulting along with technology and design, corporate and digital ventures—and business purpose. We work in a uniquely collaborative model across the firm and throughout all levels of the client organization, generating results that allow our clients to thrive. What You'll Do This position is with BCG information security team and as a security engineer you will be responsible for performing DAST and penetration testing across different products and systems. The role will require working closely with product development teams to ensure applications are built to BCG security standards and have robust and secure design and development. Working knowledge of SAST is good to have. Following Are Key Responsibilities For This Role Perform security tests on web-based applications, Mobile applications, API’s, Thick client-based applications, SAAS systems and networks. Keep up with the latest methods for ethical hacking and testing and are always evaluating new penetration testing tools. Regular follow up’s on identified security issues with Development and infrastructure teams to ensure compliance with vulnerability management policy. Assist development teams in understanding security issues, relevant risk levels and its likelihood. Help them gain a long-term understanding of security and its usefulness while writing code. Enable development teams to build security throughout SDLC stages such as planning, designing, development, and testing as well as proactively work with development teams on security best practices. Liaise with application developers, security champions, architects, and project managers for improving application security posture and bring application security standard conformance across the enterprise. Maintain penetration testing scheduling calendar. Ensure 100% compliance with annual penetration testing criteria and policy. Keep a close eye on the web inventory and maintain records. Ability to perform network level penetration tests and SAST reviews is plus. Must be willing to collaborate with other team members such as security code review specialists, security architects to build a database of security learnings. Write technical penetration testing reports documenting security issues identified, their risk ratings along with countermeasures. What You'll Bring Skills The desired candidate will have application security background with sound penetration testing tools and methodologies knowledge. Following are key skills for this role: Proficient in OWASP TOP 10 and SANS TOP 25 vulnerabilities. Strong technical knowledge of commercial and open-source Dynamic Application Security Testing tools and platform. Must know advantages, challenges, and limitation of using such tools. Must have knowledge of security in CI/CD, the security of CI/CD, and security outside of CI/CD concepts. Well aware of AWS Cloud Platform, Azure, GCP, Docker, Kubernetes, and bringing security tooling to DevOps. Should have knowledge of languages/Frameworks (JavaScript, Java, .NET, Nodejs, Angular, Technologies supporting SPA) and advice teams on secure coding guidelines. CEH and OSCP certification is a huge plus. Who You'll Work With You will work in a fast-paced, intellectually intense, service-oriented environment to protect our applications and information systems. You will be a part of a team of security architects, and security professionals working in support of consultants delivering business and management strategy to our clients through these applications and systems. You will work with application developers, data analysts, and system owners providing information security for applications and systems. Additional info YOU’RE GOOD AT Responsibilities This role will work with various teams and functions and have teams which are responsible for developing application and products along with Information Security Risk Management (ISRM) as major stakeholders. This role will be change and communication intensive, requiring short and long term engagement with business and technology owners across BCG. The following key attributes will help you be successful at the job: Be a strong believer of application security at speed to unblock product’s speed to market requirements. Ability to explain complex security topics in business and plain language. Demonstrate identified security issues to various stakeholders Ability to persuade and negotiate risks as per organisation risk appetite Good reasoning and analytical approach, ability to create mental visuals, and comfortable in dealing with ambiguity Attitude to remove roadblocks and enable teams to meet their objectives Understanding of GDPR privacy by design. Boston Consulting Group is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity / expression, national origin, disability, protected veteran status, or any other characteristic protected under national, provincial, or local law, where applicable, and those with criminal histories will be considered in a manner consistent with applicable state and local laws. BCG is an E - Verify Employer. Click here for more information on E-Verify. Show more Show less
Posted 3 weeks ago
2.0 years
0 Lacs
Gurugram, Haryana, India
On-site
Line of Service Advisory Industry/Sector FS X-Sector Specialism Risk Management Level Senior Associate Job Description & Summary We are seeking a highly skilled Sailpoint Developer .If candidate has experience of 2-3 years, he/she must be Sailpoint Certified, above 3 years experience sailpoint certification is not mandatory but good to have. *Why PWC At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us . At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. " Job Description & Summary : We are seeking a professional to join our Cybersecurity and Privacy services team, where you will have the opportunity to help clients implement effective cybersecurity programs that protect against threats, drive transformation, and foster growth. As companies increasingly adopt digital business models, the generation and sharing of data among organizations, partners, and customers multiply. We play a crucial role in ensuring that our clients are protected by developing transformation strategies focused on security, efficiently integrating and managing new or existing technology systems, and enhancing their cybersecurity investments. As an L3 Analyst/SOC Manager, you will be responsible for overseeing regular operations, driving continuous improvement processes, and managing client and vendor interactions. This role involves managing complex incidents escalated from L2 analysts, operating the Security Incident process, and mentoring junior team members to build a cohesive and motivated unit. Responsibilities: Review cybersecurity events analyzed by L2 security analysts, serving as the escalation point for detection, response, and remediation activities. Monitor and guide the team in triaging cybersecurity events, prioritizing, and recommending/performing response measures. Provide technical support for IT teams in response and remediation activities for escalated cybersecurity events/incidents. Follow up on cybersecurity incident tickets until closure . Guide L1 and L2 analysts in analyzing events and response activities. Expedite cyber incident response and remediation activities when delays occur, coordinating with L1 and L2 team members. Review and provide suggestions for information security policies and best practices in client environments. Ensure compliance with SLAs and contractual requirements , maintaining effective communication with stakeholders. Review and share daily, weekly, and monthly dashboard reports with relevant stakeholders. Update and review documents, playbooks, and standard operational procedures. Validate and update client systems and IT infrastructure documentation. Share knowledge on current security threats, attack patterns, and tools with team members. Create and review new use cases based on evolving attack trends. Analyze and interpret Windows, Linux OS, firewall , web proxy, DNS, IDS, and HIPS log events. Develop and maintain threat detection rules, parsers, and use cases. Understand security analytics and flows across SaaS applications and cloud computing tools. Validate use cases through selective testing and logic examination. Maintain continuous improvement processes and build/groom teams over time. Develop thought leadership within the SOC. Mandatory skill sets: Bachelor’s degree ( minimum requirement). 2 -8 years of experience in SOC operations. Experience analyzing malicious traffic and building detections. Experience in application security, network security, and systems security. Knowledge of security testing tools (e.g., BurpSuite , Mimikatz , Cobalt Strike, PowerSploit , Metasploit, Nessus, HP Web Inspect). Proficiency in common programming and scripting languages (Python, PowerShell, Ruby, Perl, Bash, JavaScript, VBScript). Familiarity with cybersecurity frameworks and practices (OWASP, NIST CSF, PCI DSS, NY-DFS). Experience with traditional security operations, event monitoring, and SIEM tools. Knowledge of MITRE or similar frameworks and procedures used by adversaries. Ability to develop and maintain threat detection rules and use cases. Preferred skill sets: Strong communication skills, both written and oral. Experience with SMB and large enterprise clients. Good understanding of ITIL processes (Change Management, Incident Management, Problem Management). Strong expertise in multiple SIEM tools and other SOC environment devices. Knowledge of firewalls, IDS/IPS, AVI, EDR, Proxy, DNS, email, AD, etc. Understanding of raw log formats of various security devices. Foundational knowledge of networking concepts (TCP/IP, LAN/WAN, Internet network topologies). Relevant certifications (CEH, CISA, CISM, etc.) . Strong work ethic and time management skills. Coachability and dedication to consistent improvement. Ability to mentor and encourage junior teammates. Knowledge of regex and parser creation. Ability to deploy SIEM solutions in customer environments. Years of experience required : 2 - 12 + years Education qualification: B.Tech Education (if blank, degree and/or field of study not specified) Degrees/Field of Study required: Bachelor of Engineering Degrees/Field of Study preferred: Certifications (if blank, certifications not specified) Required Skills SoCs Optional Skills Accepting Feedback, Accepting Feedback, Access Control Models, Access Control System, Access Management, Active Listening, Analytical Thinking, Authorization Compliance, Authorization Management Systems, Azure Active Directory, Cloud Identity and Access Management (IAM), Communication, Creativity, CyberArk Management, Cybersecurity, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Federated Identity Management, ForgeRock Identity Platform, Identity and Access Management (IAM), Identity-Based Encryption, Identity Federation, Identity Governance Framework (IGF) {+ 22 more} Desired Languages (If blank, desired languages not specified) Travel Requirements Not Specified Available for Work Visa Sponsorship? No Government Clearance Required? No Job Posting End Date Show more Show less
Posted 3 weeks ago
0.0 - 1.0 years
2 - 3 Lacs
Lucknow
Work from Office
Softwarez Technocrew is looking for Programmer (C# ASP. Net) to join our dynamic team and embark on a rewarding career journey. Develop software applications based on business requirements and technical specifications. Write clean, efficient, and maintainable code. Test and debug software applications to ensure they meet quality standards. Collaborate with cross-functional teams to design, develop, and deploy new features. Troubleshoot and resolve software defects and issues. Optimize software performance and ensure scalability. Conduct code reviews and provide constructive feedback to team members. Stay up-to-date with industry trends and emerging technologies. Document software designs, code, and technical specifications. Participate in agile development processes and contribute to continuous improvement.
Posted 3 weeks ago
10.0 years
0 Lacs
New Delhi, Delhi, India
On-site
Position Name:- Practice Lead for App Development Client and the Project we are hiring for :- rSTAR FTE/CONTRACT:- FTE Location:- Delhi, India (Immediate Joiners Only) Job Description- We are seeking a Practice Lead for App Development to lead and expand our Application Development practice. This is a strategic leadership role, responsible for building, mentoring, and managing offshore development teams while ensuring successful delivery of enterprise-grade applications. The ideal candidate will have strong full-stack development expertise, technical leadership, and a client-centric mindset. You will work closely with the sales and practice teams to understand customer requirements, develop technical solutions, and articulate the value and vision of these solutions to potential clients. Years of experience :- 10+ Years Roles and Responsiblities :- 1. Leadership and Oversight a) Lead and manage an offshore engineering team to deliver high-quality software solutions on time and within budget. Establish clear goals, objectives, and performance metrics for the offshore team. b) Act as a technical mentor to junior and senior engineers, fostering a culture of learning and continuous improvement. Ensure alignment with onshore teams and global engineering best practices. 2. Development and Coding Standards Establish and enforce comprehensive coding standards, including: a) Code Consistency – Maintain consistent indentation, naming conventions, and code formatting (e.g., using tools like Pret b) Modularity and Reusability – Encourage building modular, reusable components and clean architecture. c) Security Best Practices – Ensure adherence to OWASP guidelines and secure coding practices. d) Performance Optimization – Write efficient, scalable, and performant code. e) Documentation – Ensure comprehensive internal documentation of code and architecture. f) Version Control – Enforce best practices using Git (branching strategies, pull requests, merge conflicts). g) Code Review Standards – Define structured review processes (e.g., pre-merge review checklists). h) Coding Language-Specific Standards – Apply industry-specific standards for programming languages (e.g., PEP-8 for Python) i) Linting and Static Code Analysis – Integrate automated tools to identify and fix coding issues early. 3. AI Adoption in Development Develop and implement AI-driven development strategies: a) AI Code Assistants – Integrate tools like GitHub Copilot, Tabnine, and others to accelerate development. b) Automated Code Generation – Leverage AI to auto-generate boilerplate code and documentation. c) AI-Driven Testing – Use AI for automated test case generation and error detection. d) AI Code Review – Implement AI-based static code analysis and review suggestions. e) AI-Based Debugging – Incorporate AI tools for real-time debugging and performance analysis. f) Continuous Monitoring – Use AI to monitor application health and suggest performance improvements. 4. Efficiency Gains Through Unit Testing and Test Automation a) Unit Testing Standards – Define minimum code coverage (e.g., 90%) and enforce unit test writing. b) Automated Testing Pipelines – Integrate tools like Jest, Mocha, and JUnit into CI/CD pipelines. c) Test-Driven Development (TDD) – Encourage writing tests before implementing functionality. d) Code Coverage Reporting – Ensure regular reporting of code coverage and test failures. e) Performance Testing – Implement performance benchmarks and load testing. f) End-to-End (E2E) Testing – Automate full user flow testing using Cypress, Selenium, etc. 5. Peer Reviews and Design Reviews a) Code Review Culture – Establish mandatory peer reviews for all code merges. b) Design Review Process – Conduct regular architectural design reviews for scalability, security, and performance. c) Pair Programming – Encourage real-time collaborative coding sessions. d) Structured Review Checklist – Define a clear checklist for code reviews (e.g., readability, modularity, test coverage). e) Feedback Loop – Create a mechanism for engineers to give and receive constructive feedback. 6. Continuous Integration/Continuous Deployment (CI/CD) a) Manage CI/CD pipelines using industry-standard tools (e.g., Jenkins, GitLab CI, GitHub Actions). b) Automate build, test, and deployment processes to reduce manual effort. c) Implement rollbacks and automated error recovery in deployment pipelines. d) Monitor pipeline health and performance metrics. 7. Performance Monitoring and Incident Management a) Implement observability tools like Datadog, Prometheus, and New Relic for real-time monitoring. b) Set up alerting and automated incident response processes. c) Conduct root cause analysis (RCA) for all major incidents and define preventive measures. a) d) Monitor error rates, response times, and user experience metrics. 8. Collaboration and Stakeholder Management a) Work closely with product managers, designers, and business stakeholders to define technical requirements. b) Ensure alignment between offshore and onshore engineering teams. c) Manage stakeholder expectations regarding deliverables, timelines, and technical challenges. Qualification & skills :- a) Bachelor's or master's degree in computer science, Software Engineering, or related field. b) 8+ years of experience in software development and engineering leadership roles. c) Proficiency in programming languages (e.g., Java, Python, JavaScript, C#). d) Deep understanding of design patterns, system architecture, and microservices. e) Hands-on experience with AI-driven development tools and practices . f) Strong knowledge of software development lifecycle (SDLC) and Agile methodologies. g) Experience with cloud platforms (AWS, Azure , GCP). h) Familiarity with containerization (Docker, Kubernetes) and infrastructure as code (Terraform). i) Excellent communication and leadership skills. j) Proven track record in driving engineering excellence and efficiency improvements. Preferred Qualifications: a) Experience managing geographically distributed teams. b) Knowledge of machine learning models and AI frameworks. c) Experience with DevSecOps and security compliance frameworks. d) Strong background in performance optimization and large-scale application architecture. Show more Show less
Posted 3 weeks ago
2.0 - 7.0 years
5 - 9 Lacs
Bengaluru
Work from Office
Wayfair is the online leader for home furnishings and decor. Through technology and innovation, Wayfair makes it possible for shoppers to quickly and easily find exactly what they want from a selection of more than 8 million items across home furnishings, d cor, home improvement, housewares and more. Wayfair operates a growing Security Operations Center and we re looking for a talented Security Engineer to join and help grow our team. Our Security Operations team is tasked with monitoring and protecting Wayfair from an ever growing number of security risks, and finding new and creative ways to do so. We have a strong focus on engineering and innovation, and are seeking individuals who love to find new problems and hate fixing the same problem twice. What You ll Need 2+ years experience working in cyber security operations Understanding of the threat landscape, the latest security trends, attack vectors for corporate and cloud environments, and how build detection and response tooling to identify and respond to malicious actors Experience with SOAR/SIEM technologies Experience with incident detection and remediation Working knowledge of threat vectors, vulnerabilities, and what anomalies to look for Working knowledge of Linux and/or Windows logs & indicators Python experience to build and automate tooling Experience writing SIEM logging parsing rules Experience with incident response and monitoring tools, such as SIEM, EDR, cloud monitoring, etc. Strong communication skills to describe challenges and roadblocks when building and maintaining our security operations tooling and logging Understanding of cyber security best practices and frameworks such as NIST, MITRE, ATT&CK Framework, and OWASP Top 10 What You ll Do In this role you will work closely with the cyber security organization to build monitoring and response tooling and processes to reduce our mean-time-to-detect and remediate to keep up with threat actors changing tactics, techniques, and procedures (TTPs) Logging - Gather all security relevant cloud, infrastructure and application logs parsed, and into our SIEM Detection - Setup detection and prevention rules and policies, PoC and deploy tools that help with detection, tune/audit deployed rules/policies in security tools on true and false positives, setting up a detection framework Response - Build plan and procedures for Incident Response, create playbooks to be followed, automate response, develop/deploy malware analysis tools and techniques, forensic tools and techniques to capture evidence/malware, PoC and deploy tools that help with response, integrate with customer service teams and engineering teams etc. Build security alerts & dashboards in various incident response tools. Monitor for suspicious activities/alerts in the cloud / infrastructure / application from various sources such as internal reports from employees as well as external reports such as customers/social media, vendors, partners, bug bounty programs etc., deployed/integrated security tools, data visualization tools etc. Build and maintain security infrastructure tooling that supports continuous SOC operations and vulnerability management As needed, support the response to security alerts and incidents, and take appropriate action to remediate and resolve .
Posted 3 weeks ago
5.0 - 10.0 years
5 - 10 Lacs
Hyderabad
Work from Office
Job Description: Prudent Technologies and Consulting is hiring for a fast-growing Cybersecurity team that supports a customer base including the world s largest organizations. We have an immediate opening for a Senior Application Security Consultant. The role requires an experienced offensive consultant who understands application security testing methodologies, frameworks, tools and reporting. As a Senior Consultant you will perform and lead technical teams to conduct thorough security assessments as well as perform field related research. Candidates should be familiar with a variety of technologies including web, mobile, API, AI/LM, cloud, desktop, single sign-on and OAuth. Responsibilities: Consult with technical and non-technical client stakeholders Collaborate with Sales teams to assist in scoping efforts Lead projects and mentor less experienced consultants Perform advanced comprehensive penetration tests, adhering to industry-standard best practices Conduct penetration testing across diverse environments, including desktop applications, mobile applications, web applications, cloud environments, on-prem environments, APIs and AI/LM Document and report vulnerabilities, show proof-of-concepts where applicable, and provide detailed explanations to highlight severity, business impact, and tailored remediation steps Manages priorities and tasks to achieve utilization targets Participate in research and development efforts to improve the Cybersecurity practice Qualifications: Required Qualifications: 5+ years of direct experience performing manual penetration testing assessments on desktop applications, mobile applications, web applications, cloud environments, API and AI/LM Proficient at using penetration testing tools such as Burp Suite, DAST scanners, Metasploit and Nessus to identify and exploit vulnerabilities Able to write deliverable reports, including executive summaries and presentations, and status reports for clients Understanding of industry-standard security frameworks (e.g., OWASP and MITRE ATT&CK) Excellent project management, leadership, time management, and client consulting skills Preferred Qualifications: Bachelor s degree in computer science, information security, or related field Relevant certifications (e.g., OSCP and/or OSWE) Experience with scripting languages such as Python and Bash Experience with application development, systems engineering, or similar Published CVE/CWE contributions, participation in CTF events and independent research projects Education: Direct work experience performing application penetration testing assessments; ability to begin testing immediately with guidance on Prudent s specific approach and methodology
Posted 3 weeks ago
5.0 - 6.0 years
5 - 9 Lacs
Hyderabad
Work from Office
Senior Application Security Engineer at Practical DevSecOps | Jobs at Practical DevSecOps We are seeking an Application Security Engineer to join our team and help maintain, enhance, and develop security training exercises for our renowned DevSecOps, API Security, Threat Modeling and many other courses. The ideal candidate will bring technical security expertise while having the ability to create educational content that aligns with our practical, hands-on training approach. Key Responsibilities Training Content Excellence Fix and troubleshoot existing training exercises when issues arise from tool or environment version upgrades Modernize exercises by upgrading components when tools become outdated, maintaining industry relevance Create new, innovative security exercises that demonstrate real-world vulnerabilities using our open source projects Assist our training team in developing new courses aligned with emerging security domains Contribute to our open source security projects with practical, educational components Conduct application security assessments using methodologies taught in our training programs Help clients implement secure coding practices and remediation strategies based on our training principles Support integration of security tools into CI/CD pipelines using techniques from our courses Apply and reinforce the practical DevSecOps methodologies we advocate in our training Stay current with security trends, adapting our training content to reflect the evolving threat landscape Develop educational materials that bridge theory and practice in DevSecOps Support instructors with technical expertise during course delivery Help maintain our position as thought leaders in practical DevSecOps implementation Required Qualifications Understanding of application security concepts, particularly those covered in our OWASP-aligned curricula Experience with security testing tools featured in our training (e.g., SAST/DAST tools, containers, cloud security) Proficiency in programming languages relevant to our courses (Python, Java, JavaScript) Knowledge of DevSecOps practices as applied in real-world environments Familiarity with the core domains we teach: DevSecOps, AI Security, API Security, and Threat Modeling Strong troubleshooting abilities to resolve complex training environment issues Preferred Qualifications Familiarity with our open source projects (DevSecOps Studio, DevSlop, etc.) Security certifications relevant to our training domains Experience creating educational content or technical documentation Background in developer education or security training Public speaking or training delivery experience Skills Strong technical problem-solving abilities Clear communication skills for explaining complex security concepts Passion for DevSecOps methodologies and security education Self-motivated approach to improving training materials Collaborative mindset to work effectively with our international team
Posted 3 weeks ago
2.0 - 3.0 years
10 - 12 Lacs
Bengaluru
Work from Office
About LeadSquared: One of the fastest-growing SaaS companies in the CRM space, LeadSquared empowers organizations with the power of automation. More than 1700 customers with 2 lakhs+ users across the globe utilize the LeadSquared platform to automate their sales and marketing processes and run high-velocity sales at scale.We are backed by prominent investors such as Stakeboat Capital, Jyoti Bansal, and Gaja Capital to name a few. We raised $153mn in our latest Series C funding round from WestBridge Capital, and were now Indias 103rd Unicorn! We are expanding rapidly and our 1100+ strong and still growing workforce is spread across India, the U.S, the Middle East, ASEAN, ANZ, and South Africa. * Among the Top 50 fastest-growing tech companies in India as per Deloitte Fast 50 programs * Frost and Sullivans 2019 Marketing Automation Company of the Year award * Among Top 100 fastest growing companies in FT 1000: High-Growth Companies Asia- Pacific * Listed as Top Rates Product on G2Crowd, GetApp, and TrustRadiusLocation: Cessna Business Park (Bangalore)-WFORequirements: * 2-3 years of experience in product or application security; at least 1 year of hands-on software development experience is highly desirable. * Proficiency in application security testing using tools such as Burp Suite, SonarQube, SQLMap, and others (SAST, DAST, SCA). * Experience with secure coding practices, and strong scripting skills in Python or JavaScript. * Solid understanding of industry standards and frameworks such as OWASP Top 10, SANS CWE, etc. * Knowledge of security fundamentals like cryptography, authentication, risk assessment, and threat modeling. * Exposure to cloud platforms (e.g., AWS, Azure) and their associated security best practices. * Familiar with CI/CD pipelines and DevSecOps practices for integrating security into development workflows. * Understanding of compliance standards such as ISO 27001 and HIPAA. * Ability to automate security testing to increase assessment coverage and efficiency. * Strong communication skills to effectively convey technical findings to both technical and non-technical stakeholders.Key Responsibilities: * Conduct application security assessments on web,API and mobile platforms. * Perform secure code reviews on apps * Carry out cloud security assessments for SaaS infrastructure and services. * Manage the vulnerability lifecycle from discovery to resolution. * Deliver security training and awareness sessions to internal teams. * Develop tools and frameworks to support security automation and engineering initiatives.
Posted 3 weeks ago
5.0 - 10.0 years
8 - 14 Lacs
Pune
Work from Office
Job Summary : We're looking for a skilled .NET Developer with a strong background in Security Testing (DAST) to design, develop, and test secure web applications. The ideal candidate will have expertise in identifying and mitigating security vulnerabilities using DAST tools and techniques. Responsibilities : - Design, develop, and test secure web applications using .NET framework - Conduct Dynamic Application Security Testing (DAST) to identify security vulnerabilities - Analyze and mitigate security risks using DAST tools and techniques - Collaborate with cross-functional teams to ensure secure coding practices - Develop and maintain security testing frameworks and tools - Stay up-to-date with emerging security threats and trends - Participate in code reviews and ensure adherence to security best practices - Develop and deliver training programs on security testing and secure coding practices Requirements : - 5+ years of experience in .NET development with a focus on security testing (DAST) - Strong expertise in .NET framework, C#, (link unavailable), and related technologies - In-depth knowledge of DAST tools and techniques, such as OWASP ZAP, Burp Suite, and SQLMap - Experience with security testing frameworks and tools, such as NMap, Nessus, and OpenVAS - Strong understanding of web application security risks and vulnerabilities, such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF) - Excellent problem-solving skills and attention to detail - Strong communication and collaboration skills - Experience with Agile development methodologies and version control systems, such as Git Nice to Have : - Experience with cloud-based security testing tools and platforms, such as AWS Security Hub and Google Cloud Security Command Center - Knowledge of containerization and orchestration technologies, such as Docker and Kubernetes - Experience with DevOps practices and tools, such as Jenkins, Puppet, and Ansible - Certification in security testing or related field, such as OSCP, CEH, or CISSP What We Offer : - Competitive salary and benefits package - Opportunity to work with a talented team of professionals - Collaborative and dynamic work environment - Professional development and growth opportunities - Flexible working hours and remote work options
Posted 3 weeks ago
7.0 years
0 Lacs
New Delhi, Delhi, India
Remote
Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We believe that our work to help our clients discover and remediate their unique security risks makes every one of us safer. Our clients trust us to use cutting-edge offensive security tools, creativity, imagination, and expert knowledge to find cybersecurity risks in their networks, systems, and software. We're looking to grow our team of penetration testers in India. We perform testing of web and smartphone applications, computer networks, cloud infrastructure, hardware devices, employees via social engineering, organizations via red team testing, and more. As a Principal Offensive Security Consultant, you’ll be reporting to a Vice President in our Offensive Security team and deliver projects for some of the biggest enterprises in the world. You will perform various web application, API, mobile, and infrastructure penetration tests. You will also draft reports based on the assessment results and gathered evidence and help address client inquiries regarding these results. In addition to the execution of traditional security assessments, you will participate in their refinement and improvement. Below are the roles and responsibilities for the Principal Consultant, Offensive Security role based in New Delhi: Day To Day Responsibilities Lead the execution of consultative, offensive security, and cloud security engagements as a thought-leader in the eyes of the client and your teammates Solution and scope engagements for our clients, including penetration tests, consultative engagements, cloud security projects, and more Oversee the delivery of multiple engagements in parallel to ensure that junior members of the team can deliver and exceed client expectation Execute internal strategic initiatives to help our practice grow, adapt, and evolve Manage junior members of the team by conducting one-on-ones, providing feedback and coaching, and supporting their career growth Remote working would be an option Essential Traits: 7+ years in cybersecurity, with at least 5 years in penetration testing, cloud security or red teaming A strong understanding of offensive security methodology and vulnerability frameworks such as the OWASP Top 10, MITRE ATT&CK, PTES, or others An ability to analyze root causes and deliver technological recommendations to our clients Essential Traits: Bachelor’s degree or college diploma in information security, computer science or engineering, software engineering, or IT/System/Network administration Deep understanding of penetration testing, cloud security, or red teaming The capability to build and cultivate relationships with clients and colleagues A proven ability to lead and deliver information security assessments that don’t always come with a playbook A deep understanding of application security, cloud security, infrastructure security, and other offensive or defensive security domains Demonstrated ability to manage and coach a team of ambitious information security phenoms About Kroll Join the global leader in risk and financial advisory solutions—Kroll. With a nearly century-long legacy, we blend trusted expertise with cutting-edge technology to navigate and redefine industry complexities. As a part of One Team, One Kroll, you'll contribute to a collaborative and empowering environment, propelling your career to new heights. Ready to build, protect, restore and maximize our clients’ value? Your journey begins with Kroll. Kroll is committed to equal opportunity and diversity, and recruits people based on merit. In order to be considered for a position, you must formally apply via careers.kroll.com Show more Show less
Posted 3 weeks ago
5.0 years
0 Lacs
Hyderabad, Telangana, India
On-site
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. EY- Cyber Security Strategy, Risk, Compliance and Resilience – Technology Consulting – Senior As part of our EY Strategy, Risk, Compliance and Resilience (SRCR) Technology Consulting team, you would work on various SRCR projects for our customers across the globe. An important part of your role will be to actively establish, maintain and strengthen internal and external relationships. You’ll also identify potential business opportunities for EY and GDS within existing engagements and escalate these as appropriate. Similarly, you’ll anticipate and identify risks within engagements and share any issues with senior members of the team. In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards and is reviewed by the next-level reviewer. As an influential member of the team, you’ll help to create a positive learning culture, coach and counsel junior team members and help them to develop. The opportunity We’re looking for Senior Security Consultant with expertise in cyber / information security, risk and controls concepts. This is a fantastic opportunity to be part of a leading firm whilst being instrumental in the growth of a new service offering. Your Key Responsibilities Engage in Cyber Strategy & Governance, Cyber Risk & Compliance, Cyber Resilience, Cyber Transformation and Co-Sourcing, Application & Network Security engagements Work effectively as a team member, sharing responsibility, providing support, maintaining communication and updating senior team members on progress. Execute the engagement requirements, along with review of work by junior team members. Help prepare reports and schedules that will be delivered to clients and other parties. Develop and maintain productive working relationships with client personnel. Build strong internal relationships within EY Consulting Services and with other services across the organization Contribute to people related initiatives including recruiting and retaining Cyber Transformation professionals Maintain an educational program to continually develop personal skills of staff Understand and follow workplace policies and procedures Building a quality culture at GDS Help senior team members in performance reviews and contribute to performance feedback for staff/junior level team members Manage the performance management for the direct reportees, as per the organization policies. Foster teamwork and lead by example; training and mentoring of project resources Participating in the organization-wide people initiatives Skills And Attributes For Success Hands-on experience of more than 5 years with key components of cybersecurity including (but not limited to): Vendor/3rd Party Risk Management & Assessment Cyber Strategy & Governance, Cyber Transformation, Cyber Dashboarding Regulations/standards such as ISO 27001, PCI DSS, HIPAA, HITRUST, GDPR, CCPA, FISMA/FEDRAMP, COBIT, OWASP Top 10, NIST 800-53 Business Continuity & Disaster Recovery Must have experience in working in client facing roles, interacting with the third parties, assessing different kinds of environments (IT and non-IT) and ability to apply cyber security concepts in all these sectors. Experienced in creation and review of security policy/procedures, and in performing risk assessments. Good to have experience in assessing ITGC requirements across various industries including both Cybersecurity and resilience requirements. Should have a good understanding of VAPT process, common application security vulnerabilities, exploitation techniques and remediation measures. Basic understanding of Network Security and network architecture diagram reviews, access and perimeter control, vulnerability management and intrusion detection, firewall rule-based reviews. Good understanding of logging and monitoring tools (SIEM). Knowledge in any one of the SIEM tools is a plus. To qualify for the role, you must have: BE - B. Tech / MCA / M. Tech/ MBA with background in computer science and programming. More than 5 Years of relevant experience. Strong Excel and PowerPoint skills. Should be proficient in leading medium to large engagements and coach junior staff. Ideally, you’ll also have CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer. Project management skills. What We Look For A team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills. An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide. Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries. What Working At EY Offers At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are. You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer: Support, coaching and feedback from some of the most engaging colleagues around Opportunities to develop new skills and progress your career The freedom and flexibility to handle your role in a way that’s right for you EY | Building a better working world EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today. Show more Show less
Posted 3 weeks ago
0 years
0 Lacs
Pune, Maharashtra, India
On-site
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title And Summary Manager, Software Engineering Who is Mastercard? Mastercard is a global technology company in the payments industry. Our mission is to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart, and accessible. Using secure data and networks, partnerships and passion, our innovations and solutions help individuals, financial institutions, governments, and businesses realize their greatest potential. Our decency quotient, or DQ, drives our culture and everything we do inside and outside of our company. With connections across more than 210 countries and territories, we are building a sustainable world that unlocks priceless possibilities for all. Overview The Settlement Program provides vital systems and services to the Mastercard Treasury and Finance team in support of global payments/customer funds movement, treasury operations, liquidity, foreign exchange, risk management and capital management. We are directly responsible for moving billions of dollars each day between our customers. We are an agile development organization with teams located in both St. Louis, Missouri, Dublin, Ireland and Pune, India. Role: Overview Responsible for the analysis, design, development and delivery of software solutions Defines requirements for new applications and customizations, adhering to standards, processes and best practices Formally supervise and coach 2+ teams of engineers to build, enhance, and support multiple applications/services in the delivery of internal or market-facing Products, Platforms, or Product bundles Work with business/product owners to develop and deliver on new services to introduce new products and bundles Ensure objectives and development plans are established at the start of the year and reviewed continuously throughout the year Recruit and hire the right talent, always bringing in someone better than at least half the individuals in the role Continuously engage and improve teams’ performance by conducting recurring 1-1 meetings, knowing your people, managing career development, and understanding who is at risk Provide and facilitate timely feedback, coaching in the moment, and mentoring for staff at all levels Emulate and drive Mastercard Way behaviors through their behavior, recognitions, coaching, and employee engagement Manage and optimize budgets, forecasting, and cost allocation while delivering on business needs in the area of ownership Provide strategic thinking and leadership related to a wide range of applications and systems, or software-development methodologies Benchmark and drive engineering productivity, quality, and technology policy compliance in the areas of ownership Proactively share and seek knowledge within their Guild/Program to drive reuse of patterns/libraries/practices and enhance productivity About You: IT experience with successful track record in managing small scale development organization (2+ teams) with demonstrated thought-leadership, cross-functional influence, and partnership Progressively grown career with proven design and development experiences in multiple languages, secure coding standards (e.g., OWASP, CWE, SEI CERT), and vulnerability management. Has skills in building applications using open frameworks to achieve reuse and reduce development times (e.g., Spring Boot, Steeltoe, Angular, DXP, others) Understands internals of operating systems (Windows, Linux) to deliver interoperable and performant code Able to perform debugging and troubleshooting to analyze core, heap, thread dumps and remove coding errors Has skills to document and coach team on the development practices and coding guidelines (e.g., branching, peer reviews, library use, logging, scanning rules, test-driven development, error handling) Understands use cases for advanced design patterns (e.g., service-to-worker, MVC, API gateway, intercepting filter, dependency injection, lazy loading, all from the gang of four) to implement efficient code Has skills to undertake a technical review of code across applications and their dependencies to look for anti-patterns and promote continuous refactoring Understands and elaborates technical debt and operational issues to drive prioritization discussions with stakeholders to improve the run experience Understands system architecture to plan for platform and infrastructure capacity (e.g., database, compute, network, storage) and drives the dependency prioritization to reduce the delivery lead time Has skills to understand customer journeys and ensure a good customer experience by continuously reducing mean time to mitigate (MTTM) for incidents and ensuring high availability (99.95% as a starting point) Has skills to simplify deployment and eliminate software and infrastructure snowflakes using standardized platforms, ephemeral instances, and automation Has skills to orchestrate release workflows and pipelines and apply standardized pipelines via APIs to achieve CI and CD using industry-standard tools (e.g., Jenkins, Bamboo, AWS/Azure pipelines, XL Release, others) Able to configure rules and build automation for code with vulnerability scanning and software composition analysis using standard tools (e.g., Sonar, Checkmarx, Nexus, JFrog XRay, Veracode, others) Has skills to define, organize, and report on test runs for major, minor, and hotfix releases (including unit, component level, system level, customer journeys, past customer issues, and regulatory controls) Has skills to conduct various performance tests (e.g., load, spike, breakpoint, endurance) to understand application/service limits and behaviors Corporate Security Responsibility All Activities Involving Access To Mastercard Assets, Information, And Networks Comes With An Inherent Risk To The Organization And, Therefore, It Is Expected That Every Person Working For, Or On Behalf Of, Mastercard Is Responsible For Information Security And Must: Abide by Mastercard’s security policies and practices; Ensure the confidentiality and integrity of the information being accessed; Report any suspected information security violation or breach, and Complete all periodic mandatory security trainings in accordance with Mastercard’s guidelines. R-247681 Show more Show less
Posted 3 weeks ago
2.0 years
0 Lacs
Gurugram, Haryana, India
On-site
Line of Service Advisory Industry/Sector FS X-Sector Specialism Risk Management Level Senior Associate Job Description & Summary We are seeking a highly skilled Sailpoint Developer .If candidate has experience of 2-3 years, he/she must be Sailpoint Certified, above 3 years experience sailpoint certification is not mandatory but good to have. Why PWC At PwC, you will be part of a vibrant community of solvers that leads with trust and creates distinctive outcomes for our clients and communities. This purpose-led and values-driven work, powered by technology in an environment that drives innovation, will enable you to make a tangible impact in the real world. We reward your contributions, support your wellbeing, and offer inclusive benefits, flexibility programmes and mentorship that will help you thrive in work and life. Together, we grow, learn, care, collaborate, and create a future of infinite experiences for each other. Learn more about us. At PwC, we believe in providing equal employment opportunities, without any discrimination on the grounds of gender, ethnic background, age, disability, marital status, sexual orientation, pregnancy, gender identity or expression, religion or other beliefs, perceived differences and status protected by law. We strive to create an environment where each one of our people can bring their true selves and contribute to their personal growth and the firm’s growth. To enable this, we have zero tolerance for any discrimination and harassment based on the above considerations. " Job Description & Summary: We are seeking a professional to join our Cybersecurity and Privacy services team, where you will have the opportunity to help clients implement effective cybersecurity programs that protect against threats, drive transformation, and foster growth. As companies increasingly adopt digital business models, the generation and sharing of data among organizations, partners, and customers multiply. We play a crucial role in ensuring that our clients are protected by developing transformation strategies focused on security, efficiently integrating and managing new or existing technology systems, and enhancing their cybersecurity investments. As an L3 Analyst/SOC Manager, you will be responsible for overseeing regular operations, driving continuous improvement processes, and managing client and vendor interactions. This role involves managing complex incidents escalated from L2 analysts, operating the Security Incident process, and mentoring junior team members to build a cohesive and motivated unit. Responsibilities Review cybersecurity events analyzed by L2 security analysts, serving as the escalation point for detection, response, and remediation activities. Monitor and guide the team in triaging cybersecurity events, prioritizing, and recommending/performing response measures. Provide technical support for IT teams in response and remediation activities for escalated cybersecurity events/incidents. Follow up on cybersecurity incident tickets until closure. Guide L1 and L2 analysts in analyzing events and response activities. Expedite cyber incident response and remediation activities when delays occur, coordinating with L1 and L2 team members. Review and provide suggestions for information security policies and best practices in client environments. Ensure compliance with SLAs and contractual requirements, maintaining effective communication with stakeholders. Review and share daily, weekly, and monthly dashboard reports with relevant stakeholders. Update and review documents, playbooks, and standard operational procedures. Validate and update client systems and IT infrastructure documentation. Share knowledge on current security threats, attack patterns, and tools with team members. Create and review new use cases based on evolving attack trends. Analyze and interpret Windows, Linux OS, firewall, web proxy, DNS, IDS, and HIPS log events. Develop and maintain threat detection rules, parsers, and use cases. Understand security analytics and flows across SaaS applications and cloud computing tools. Validate use cases through selective testing and logic examination. Maintain continuous improvement processes and build/groom teams over time. Develop thought leadership within the SOC. Mandatory Skill Sets Bachelor’s degree (minimum requirement). 2-8 years of experience in SOC operations. Experience analyzing malicious traffic and building detections. Experience in application security, network security, and systems security. Knowledge of security testing tools (e.g., BurpSuite, Mimikatz, Cobalt Strike, PowerSploit, Metasploit, Nessus, HP Web Inspect). Proficiency in common programming and scripting languages (Python, PowerShell, Ruby, Perl, Bash, JavaScript, VBScript). Familiarity with cybersecurity frameworks and practices (OWASP, NIST CSF, PCI DSS, NY-DFS). Experience with traditional security operations, event monitoring, and SIEM tools. Knowledge of MITRE or similar frameworks and procedures used by adversaries. Ability to develop and maintain threat detection rules and use cases. Preferred Skill Sets Strong communication skills, both written and oral. Experience with SMB and large enterprise clients. Good understanding of ITIL processes (Change Management, Incident Management, Problem Management). Strong expertise in multiple SIEM tools and other SOC environment devices. Knowledge of firewalls, IDS/IPS, AVI, EDR, Proxy, DNS, email, AD, etc. Understanding of raw log formats of various security devices. Foundational knowledge of networking concepts (TCP/IP, LAN/WAN, Internet network topologies). Relevant certifications (CEH, CISA, CISM, etc.). Strong work ethic and time management skills. Coachability and dedication to consistent improvement. Ability to mentor and encourage junior teammates. Knowledge of regex and parser creation. Ability to deploy SIEM solutions in customer environments. Years Of Experience Required 2-12 + years Education Qualification B.Tech Education (if blank, degree and/or field of study not specified) Degrees/Field of Study required: Bachelor of Engineering Degrees/Field Of Study Preferred Certifications (if blank, certifications not specified) Required Skills SoCs Optional Skills Accepting Feedback, Accepting Feedback, Access Control Models, Access Control System, Access Management, Active Listening, Analytical Thinking, Authorization Compliance, Authorization Management Systems, Azure Active Directory, Cloud Identity and Access Management (IAM), Communication, Creativity, CyberArk Management, Cybersecurity, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Federated Identity Management, ForgeRock Identity Platform, Identity and Access Management (IAM), Identity-Based Encryption, Identity Federation, Identity Governance Framework (IGF) {+ 22 more} Desired Languages (If blank, desired languages not specified) Travel Requirements Not Specified Available for Work Visa Sponsorship? No Government Clearance Required? No Job Posting End Date Show more Show less
Posted 3 weeks ago
1.0 years
0 Lacs
Vellore, Tamil Nadu, India
On-site
Summary Assist in testing software applications to ensure quality and functionality by executing test cases, including API tests, reporting bugs, and collaborating with development teams. Responsibilities Execute manual, automated, and API test cases. Identify, document, and track software defects. Collaborate with developers to reproduce and resolve issues. Assist in preparing test documentation and reports. Participate in test planning and review sessions. Validate API functionality, performance, and security as part of the testing process. Skills Manual/Automation Test (Cypress), API Test (Postman/Jmeter), Jira JavaScript Agile Mobile Testing using Appium Security Testing using OWASP ZAP Version Control Systems Basic Knowledge of Cloud Platforms Basic Knowledge of NOSQL and Databases Qualifications Bachelor’s degree in computer science or related field 6 month – 1 year of experience in development Benefits Competitive salary and benefits package Opportunity to work on challenging and exciting projects Collaborative and supportive work environment Chance to make a real impact on our company and our customers. Contact us on recruiter@wonderws.com / 9047477375. Show more Show less
Posted 3 weeks ago
6.0 years
0 Lacs
Vadodara, Gujarat, India
On-site
Key responsibilities: Lead and scale diverse technical teams to execute on the SecOps roadmap Partner and align with Engineering teams to reinforce product security to drive and automate secure development practices while maintaining business needs Develop an effective strategy to assess and mitigate risk, manage incidents, maintain continuity of operations, and safeguard the engineering products Lead Security Incident Response, Third Party Information Security Assessment, Data Protection and Encryption, threat detection and rapid security response to protect customer data Define cybersecurity governance and control strategies for emerging technologies such as cloud & containerization, blockchain, and AI/ML Continuously evaluate and integrate new technologies to improve SecOps practices Stay up to date with market trends, customer demands and changes to adapt SecOps practices within the organization Build and inspire a highly skilled and diverse Security team. Foster a culture of trusted cross-functional partnership, and continuous improvement Technical and functional areas of expertise: Strong understanding of SecOps methodologies, threat intelligence and penetration testing for web, desktop and mobile Strong understanding of OWASP top 10 for web, mobile, desktop, cloud, and AI Experience working with static assessment SAST and compliance tools like Snyk, Github Advanced Security, etc Experience with penetration testing tools like ZAP/Burp Suite and Objection/Frida Experience with implementation of at least one compliance standard like ISO 27001, HIPAA, GDPR Scripting exposure to using Python, Shell Script or PowerShell Key Behaviors: Strong problem-solving and analytical skills Excellent communication and collaboration abilities Ability to work independently and lead cross-functional initiatives Adaptable to change and passionate about security and compliance Strong trade off sense with an ability to balance ‘business value’ vs ‘security risk’ Education and experience: Bachelors or Master’s in Computer Science or related fields 6+ years of experience Show more Show less
Posted 3 weeks ago
8.0 years
0 Lacs
Bengaluru, Karnataka, India
On-site
Job Summary This position is a Contractor at Senior Specialist Cyber Security role for performing Application Security Testing in Cyber Security Organization. This profile will be passionate in preventing risk by performing remediation validation of vulnerabilities identified during the testing process. While doing so they will also be identifying vulnerabilities in the applications of the enterprise by configuring scan settings for effective vulnerability enumeration, Identify and document findings, approve false positives and define/document approved mitigations used by AppSec Testers. Experience Level: 8 years Location: Hyderabad or Bengaluru Roles and Responsibilities: ¿ Perform SAST/SCA/DAST scans using industry vulnerability scanner ¿ SAST/SCA ¿ Veracode, using supplied compiled binary, configure scan platform to correct scan for both static code CWE¿s as well as SCA derived CVEs. Work will include coordination with app owner to ensure all branches of code are included in compiled binary file. ¿ DAST ¿ Work begins with crawling the target application to identify existing directory and file structure. Once identified, execute DAST scan using HCL product to identify dynamic issue only visible during code execution. ¿ This person will be primarily tasked to execute scan retest by performing revalidation tests of previously identified critical and high severity vulnerabilities as requested by the client application teams. ¿ During testing process, tester MUST ensure application is not degraded and/or taken out of service due to scanning activities. ¿ Tester must ensure results from scanner are present in Vulnerability reporting platforms and visible to approved app users. ¿ Perform manual validation and false positive analysis on the automated scan results.¿ ¿ Provide remediation support will analyze the top rated vulnerabilities along with provide support to application teams on remediation strategies from identified risks. Primary / Mandatory skills: Overall ¿ 8+ years of IT experience ¿ 7+ years of application security Experience ¿ 5+ years of Application Security testing Experience ¿ Bachelor's degree required. ¿ Deep familiarity with the OWASP Top 10 and other security concerns for web applications ¿ Deep Understanding of OWASP Application Security Verification Standards (ASVS) ¿ Deep understanding of SAST, DAST, SCA Scanning practices ¿ Experience in scanning leveraging Veracode, Appscan.or other enterprise tools. ¿ Understand how to interpret and assess CVEs (Common Vulnerability and Exposures) and CWEs (Common Weakness Enumeration) as found by scanning tools. ¿ Understanding of SAST, DAST tools and dependency scanning tools ¿ Experience working/integrating with secret management systems. ¿ Advanced knowledge of front end and back end web application development in at least one technology stack (.NET, Java, PHP, Ruby/Rails, Angular, Node.js, etc.) ¿ Track record of staying current with trends, techniques, tools, and processes that drive improvement of security posture of applications. ¿ Strong documentation skills ¿ Excellent verbal and written communication skills, with proven technical writing abilities (English language proficiency required) ¿ Team oriented thinking with demonstrated ability to produce high quality work as part of a fast paced, dynamic team. ¿ Proven ability to communicate, collaborate, and present effectively with teams and individuals in different disciplines or areas. Technical Skills: SAST, DAST, SCA Show more Show less
Posted 3 weeks ago
6.0 - 10.0 years
11 - 15 Lacs
Bengaluru
Work from Office
Job Title : Hands-On Cloud Security Architect Location : Bangalore Job Type : Full-Time Department : Cloud, Information Technology / Security Reports To : CTO Job Overview : We are seeking an experienced Hands-On Cloud Security Architect to secure the architecture and infrastructure of our enterprise product software deployed in the cloud. As a Cloud Security Architect, you will play a critical role in designing, implementing, and maintaining secure cloud environments for our enterprise software solutions. You will directly contribute to securing the product's cloud-based infrastructure, ensuring both security and compliance, while actively collaborating with development, DevOps, and IT teams to incorporate cloud security practices into the software development lifecycle (SDLC). This role requires a hands-on, technical approach, enabling us to maintain a secure, resilient, and scalable product platform. Key Responsibilities : - Design & Implement Secure Cloud Architecture : Secure enterprise product software hosted in both public and private clouds (AWS, Azure, GCP) and integrate security controls into the architecture. - Embed Security into SDLC : Collaborate with development and DevOps teams to integrate cloud security practices into the product development process, ensuring secure APIs, storage, and networking configurations. - OWASP Integration : Ensure adherence to OWASP Top 10 for secure coding practices and mitigate risks like injection attacks and authentication flaws. - Automate Security Controls : Configure and automate security tools for vulnerability management, patching, and incident response in cloud environments. - Hybrid Cloud Security : Secure workloads across both public and private cloud resources, ensuring seamless integration and consistent security policies. - Compliance & Risk Management : Ensure compliance with regulatory frameworks (SOC 2, HIPAA, GDPR) and manage security risks across the cloud infrastructure. - Security Testing : Perform regular penetration testing, vulnerability assessments, and secure code reviews for cloud-hosted enterprise software. - Incident Response & Monitoring : Lead monitoring efforts and respond to security incidents in real time, ensuring the security of the product's cloud infrastructure. Qualifications : - Education : Bachelor's in Computer Science, Information Security, or related field. Advanced certifications (CISSP, CCSP, AWS Certified Security Specialty) are a plus. - Experience : 8+ years of experience in cloud security, with a focus on enterprise product software in the cloud. - At least 3+ years of hands-on experience with major cloud platforms (AWS, Microsoft Azure, or Google Cloud Platform). - Proven experience with securing enterprise software applications and cloud infrastructures. - Strong background in securing complex, large-scale software environments with a focus on infrastructure security, data security, and application security. - Hands-on experience with the OWASP Top 10 and integrating security measures into cloud applications. - Experience with Hybrid Cloud environments and securing workloads that span on-premises and public cloud platforms. Technical Skills : o In-depth experience with cloud service models (IaaS, PaaS, SaaS) and cloud security tools (e.g., AWS Security Hub, Azure Security Center, GCP Security Command Center). - Expertise in securing enterprise applications, including web services, APIs, and microservices deployed in the cloud. - Strong experience with network security, encryption techniques, IAM policies, security automation, and vulnerability management in cloud environments. - Familiarity with container security (Docker, Kubernetes) and serverless computing security. - Hands-on experience with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or similar tools. - Knowledge of regulatory compliance requirements such as SOC 2, GDPR, HIPAA, and how they apply to enterprise software hosted in the cloud. Certifications : - Certified Information Systems Security Professional (CISSP) - Certified Cloud Security Professional (CCSP) - AWS Certified Security Specialty, Azure Security Engineer, or equivalent certifications. - Other relevant certifications (e.g., CISM, CISA) are a plus. Soft Skills : - Strong problem-solving and analytical skills with the ability to assess and mitigate cloud security risks. - Excellent written and verbal communication skills, with the ability to explain complex security concepts to technical and non-technical stakeholders. - Collaborative mindset, able to work cross-functionally with engineering, operations, and product teams. - Detail-oriented, with a commitment to maintaining high security standards in all aspects of the enterprise software. Additional Information : Work Environment : - This role can be based in Bangalore - Occasional travel may be required for client meetings or industry conferences. Compensation : - Competitive salary and benefits package, including health insurance
Posted 3 weeks ago
Upload Resume
Drag or click to upload
Your data is secure with us, protected by advanced encryption.
The OWASP (Open Web Application Security Project) job market in India is growing rapidly as organizations prioritize cybersecurity and the protection of sensitive data. Professionals with expertise in OWASP are in high demand across various industries, offering lucrative career opportunities for job seekers in India.
These cities are hotspots for OWASP job opportunities, with numerous companies actively seeking professionals with OWASP skills.
The average salary range for OWASP professionals in India varies based on experience levels:
Salaries can vary based on the company, location, and individual skills and qualifications.
A typical career path in OWASP may include progressing from roles such as Junior Security Analyst or Web Application Security Engineer to Senior Security Consultant, OWASP Project Leader, and ultimately to a Chief Information Security Officer (CISO) or Security Architect.
In addition to OWASP expertise, professionals in this field are often expected to have knowledge and experience in areas such as penetration testing, secure coding practices, network security, cryptography, and risk management.
...and many more!
As you explore OWASP job opportunities in India, remember to continuously enhance your skills, stay updated on the latest trends in cybersecurity, and showcase your expertise confidently during interviews. With dedication and preparation, you can secure a rewarding career in OWASP and contribute to safeguarding digital assets in the ever-evolving landscape of cybersecurity. Good luck on your job search!
Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.
We have sent an OTP to your contact. Please enter it below to verify.