The Security Engineer will be responsible for ensuring the security and integrity of our applications and cloud infrastructure.
The role requires hands-on experience in information security, with a focus on application security and / or cloud Responsibilities :
- Conduct security reviews (static / dynamic analysis) of application code and designs throughout the SDLC.
- Perform penetration testing and vulnerability assessments of web and mobile applications.
- Work with development teams to remediate identified security vulnerabilities and implement secure coding best practices.
- Design, implement, and enforce security controls within our cloud environments.
- Assist in security audits, compliance assessments, and risk management activities.
- Participate in security incident response activities as :
- 3-7 years of hands-on experience in information security, with a focus on application security and / or cloud security.
- Familiarity with common web application vulnerabilities (OWASP Top 10) and mitigation techniques.
- Experience with SAST / DAST tools.
- Understanding of secure coding principles in at least one programming language.
- Hands-on experience securing resources on at least one major cloud platform.
- Knowledge of cloud security services and data encryption in cloud environments.
- Strong understanding of fundamental security concepts.
- Excellent analytical and problem-solving skills.
- Strong verbal and written communication :
- Relevant security certifications.
- Experience with DevSecOps practices and integrating security into CI / CD pipelines.
- Knowledge of container security and familiarity with compliance frameworks
(ref : hirist.tech)