Job Description :
We are seeking a skilled and passionate Cybersecurity Engineer to play a pivotal role in designing and implementing robust security measures for Parspec's systems. As an early member of our engineering team, you will help shape the cybersecurity framework of our organization while contributing to a culture of excellence. This role offers a unique opportunity to lead critical security initiatives, including secure DevOps practices, penetration testing, incident response, and compliance efforts. You will collaborate closely with cross-functional teams to ensure the highest standards of security across all applications, services, and cloud infrastructure components.
The core responsibilities for the job include the following :
Cybersecurity Framework Development :
- Design and implement comprehensive cybersecurity measures, policies, guidelines, and processes for all applications, services, and cloud infrastructure components (e. g., AWS, GCP, Azure).
- Develop and maintain policies that incorporate early detection of security issues while adhering to industry best practices in cybersecurity.
Secure Development Practices :
Collaborate with the engineering team to ensure secure DevOps practices are followed (e. g., SAST, DAST, SCA).Lead initiatives to foster a culture of secure coding by conducting training sessions on topics such as OWASP Top 10 Web and OWASP Top 10 AI.Penetration Testing and Vulnerability Management :
Build Parspec's internal penetration testing function from the ground up by defining its scope and partnering with the engineering team for remediation efforts.Conduct regular manual security assessments and vulnerability scans for web applications, APIs, and cloud environments.Incident Response Leadership :
Act as Incident Commander during security incidents by rallying team members to contain and resolve issues promptly.Monitor and analyze security events to provide timely responses and mitigation strategies.Compliance and Risk Management :
Assist with compliance efforts such as SOC2 audits and ensure adherence to relevant frameworks (e. g., ISO 27001 NIST).Collaborate on external engagements for cybersecurity projects while maintaining alignment with regulatory Tool Implementation :Implement and manage security tools such as firewalls, VPNs, intrusion detection / prevention systems (IDS / IPS), SIEM systems, endpoint protection solutions, and vulnerability management tools.Cross-Functional Collaboration :
Partner with development and DevOps teams to integrate security best practices into the software development lifecycle (SDLC).Collaborate with leadership on research and development efforts related to cybersecurity innovations.Requirements :
Bachelor's or Master's degree in Computer Science, Information Technology, or a related field.4-5 years of experience in cybersecurity with a focus on web applications, cloud infrastructure (e. g., AWS / GCP), and API integrations.Proven experience securing at least one major cloud environment (AWS or GCP).Strong understanding of web application security (e. g., OWASP Top 10) and secure coding practices.Proficiency in scripting languages (e. g., Python, Bash) for automation tasks.Familiarity with security frameworks such as ISO 27001 NIST, GDPR, or CIS Controls.Experience implementing tools like WAFs, VPNs, IDS / IPS systems, SIEM solutions, endpoint protection tools, or vulnerabilityscanners.
Relevant certifications such as CISSP, CEH, CISM (or equivalent).Preferred Qualifications :
Master's degree in Computer Science or related fields.Expertise in securing both AWS and GCP environments.Experience with web application frameworks like Django or React.Familiarity with DevSecOps practices and CI / CD pipeline security integration.Proven experience managing Bug Bounty programs or conducting penetration testing for web applications / cloud infrastructure.Knowledge of zero-trust architecture principles.(ref : hirist.tech)