Talent.com
Neemtree
Senior Information Security EngineerNeemtree • Karnataka
Senior Information Security Engineer

Senior Information Security Engineer

Neemtree • Karnataka
24 days ago
Job description

Roles & Security & Hardening:

- Own and continuously strengthen the information security posture of VuNet's Business Observability platform across SaaS, cloud-native, hybrid, and on-premise deployment models.

- Lead comprehensive security assessments, including application security testing, API security testing, infrastructure security reviews, penetration testing, and CIS benchmark validation.

- Define, implement, and govern security controls across cloud environments, Kubernetes platforms, containerised workloads, and enterprise deployments.

- Establish and maintain secure deployment standards, hardening guidelines, and security architecture recommendations for both customer-managed and cloud-hosted environments.

- Manage endpoint security and EDR platforms, including endpoint hardening, malware protection, detection engineering, and security monitoring across enterprise assets.

- Support enterprise security initiatives, including VPN security, identity and access management, infrastructure hardening, and privileged access controls.

DevSecOps & Vulnerability Management:

- Drive DevSecOps initiatives by integrating vulnerability management, SAST, DAST, container scanning, dependency scanning, compliance validation, and security gates into CI/CD pipelines.

- Own the end-to-end vulnerability management lifecycle, including CVE analysis, CVSS-based risk assessment, prioritisation, remediation tracking, validation, and reporting.

- Develop and maintain security automation using Python, Bash, and scripting for vulnerability assessments, reporting, and security operations.

- Maintain Software Bill of Materials (SBOMs), open-source software inventory, license compliance, and software supply chain security controls.

- Evaluate, implement, and optimise security technologies for application security, cloud security, vulnerability management, compliance automation, and security monitoring.

Security Architecture & Risk:

- Lead threat modelling exercises, security design reviews, and risk assessments for new products, features, and architectural changes.

- Maintain security policies, standards, procedures, audit evidence repositories, and risk management frameworks.

- Stay ahead of emerging threats, evolving regulations, and industry best practices to continuously improve VuNet's security posture.

Compliance & Governance:

- Drive compliance and governance programs, including ISO 27001, SOC 2 Type II, GDPR, customer audits, and regulatory security requirements.

- Act as the primary security stakeholder during customer security reviews, vendor assessments, compliance evaluations, and technical due diligence engagements.

- Maintain audit evidence repositories, risk registers, and compliance documentation to ensure audit readiness at all times.

Stakeholder Engagement & Leadership:

- Partner with Engineering, Product Management, Customer Success, and Leadership teams to define security requirements and ensure timely closure of security risks and compliance gaps.

- Mentor junior security engineers and promote a security-first culture across engineering and operational teams.

What You Bring:

Mandatory Skills:

- 46 years of hands-on experience in Information Security, Product Security, Application Security, or Cybersecurity Engineering.

Application & Infrastructure Security:

- Strong expertise in Web, API, Infrastructure, Cloud, and Kubernetes security.

- Experience performing penetration testing, vulnerability assessments, security audits, and platform hardening.

- Strong understanding of OWASP Top 10, Secure SDLC, Threat Modelling, and Risk Assessment methodologies.

- Hands-on experience with at least one major cloud platform (AWS, GCP, or Azure), including cloud-native security controls.

DevSecOps & Vulnerability Management:

- Experience integrating security controls within CI/CD pipelines including SAST, DAST, container scanning, and dependency scanning.

- Strong understanding of CVE analysis, CVSS scoring, vulnerability prioritisation, and risk-based remediation.

- Experience with SBOM generation, OSS inventory management, software supply chain security, and open-source license compliance.

Kubernetes & Container Security:

- Hands-on experience with Kubernetes security assessments, RBAC reviews, CIS benchmark validation, container image scanning, and secrets management.

Security Tools:

- Hands-on experience with tools across the following categories - specific tools may vary:

1. Pen Testing / Scanning: Burp Suite, OWASP ZAP, Nmap, Nessus, or equivalent

2. Container / K8S Security: Trivy, Kubescape, Dockle, or equivalent

3. SAST / Code Scanning: SonarQube, Semgrep, Snyk, or equivalent

4. Vulnerability Management: Qualys or equivalent

5. SIEM / Monitoring: Any enterprise SIEM platform

Compliance & Governance:

- Ability to independently drive audit preparation, customer security reviews, and remediation programs.

Scripting & Automation:

- Experience with Python, Bash, or similar scripting languages for security automation, reporting, and workflow orchestration.

Experience Range:

- 4 - 6 years.

Educational Qualifications:

- B.Tech/B.E.

Skills Required:

- Python, Bash, API Platform.

(ref:hirist.tech)
Create a job alert for this search

Senior Information Security Engineer • Karnataka