Roles & Security & Hardening:
- Own and continuously strengthen the information security posture of VuNet's Business Observability platform across SaaS, cloud-native, hybrid, and on-premise deployment models.
- Lead comprehensive security assessments, including application security testing, API security testing, infrastructure security reviews, penetration testing, and CIS benchmark validation.
- Define, implement, and govern security controls across cloud environments, Kubernetes platforms, containerised workloads, and enterprise deployments.
- Establish and maintain secure deployment standards, hardening guidelines, and security architecture recommendations for both customer-managed and cloud-hosted environments.
- Manage endpoint security and EDR platforms, including endpoint hardening, malware protection, detection engineering, and security monitoring across enterprise assets.
- Support enterprise security initiatives, including VPN security, identity and access management, infrastructure hardening, and privileged access controls.
DevSecOps & Vulnerability Management:
- Drive DevSecOps initiatives by integrating vulnerability management, SAST, DAST, container scanning, dependency scanning, compliance validation, and security gates into CI/CD pipelines.
- Own the end-to-end vulnerability management lifecycle, including CVE analysis, CVSS-based risk assessment, prioritisation, remediation tracking, validation, and reporting.
- Develop and maintain security automation using Python, Bash, and scripting for vulnerability assessments, reporting, and security operations.
- Maintain Software Bill of Materials (SBOMs), open-source software inventory, license compliance, and software supply chain security controls.
- Evaluate, implement, and optimise security technologies for application security, cloud security, vulnerability management, compliance automation, and security monitoring.
Security Architecture & Risk:
- Lead threat modelling exercises, security design reviews, and risk assessments for new products, features, and architectural changes.
- Maintain security policies, standards, procedures, audit evidence repositories, and risk management frameworks.
- Stay ahead of emerging threats, evolving regulations, and industry best practices to continuously improve VuNet's security posture.
Compliance & Governance:
- Drive compliance and governance programs, including ISO 27001, SOC 2 Type II, GDPR, customer audits, and regulatory security requirements.
- Act as the primary security stakeholder during customer security reviews, vendor assessments, compliance evaluations, and technical due diligence engagements.
- Maintain audit evidence repositories, risk registers, and compliance documentation to ensure audit readiness at all times.
Stakeholder Engagement & Leadership:
- Partner with Engineering, Product Management, Customer Success, and Leadership teams to define security requirements and ensure timely closure of security risks and compliance gaps.
- Mentor junior security engineers and promote a security-first culture across engineering and operational teams.
What You Bring:
Mandatory Skills:
- 46 years of hands-on experience in Information Security, Product Security, Application Security, or Cybersecurity Engineering.
Application & Infrastructure Security:
- Strong expertise in Web, API, Infrastructure, Cloud, and Kubernetes security.
- Experience performing penetration testing, vulnerability assessments, security audits, and platform hardening.
- Strong understanding of OWASP Top 10, Secure SDLC, Threat Modelling, and Risk Assessment methodologies.
- Hands-on experience with at least one major cloud platform (AWS, GCP, or Azure), including cloud-native security controls.
DevSecOps & Vulnerability Management:
- Experience integrating security controls within CI/CD pipelines including SAST, DAST, container scanning, and dependency scanning.
- Strong understanding of CVE analysis, CVSS scoring, vulnerability prioritisation, and risk-based remediation.
- Experience with SBOM generation, OSS inventory management, software supply chain security, and open-source license compliance.
Kubernetes & Container Security:
- Hands-on experience with Kubernetes security assessments, RBAC reviews, CIS benchmark validation, container image scanning, and secrets management.
Security Tools:
- Hands-on experience with tools across the following categories - specific tools may vary:
1. Pen Testing / Scanning: Burp Suite, OWASP ZAP, Nmap, Nessus, or equivalent
2. Container / K8S Security: Trivy, Kubescape, Dockle, or equivalent
3. SAST / Code Scanning: SonarQube, Semgrep, Snyk, or equivalent
4. Vulnerability Management: Qualys or equivalent
5. SIEM / Monitoring: Any enterprise SIEM platform
Compliance & Governance:
- Ability to independently drive audit preparation, customer security reviews, and remediation programs.
Scripting & Automation:
- Experience with Python, Bash, or similar scripting languages for security automation, reporting, and workflow orchestration.
Experience Range:
- 4 - 6 years.
Educational Qualifications:
- B.Tech/B.E.
Skills Required:
- Python, Bash, API Platform.
Senior Information Security Engineer • Karnataka