Experience
4 - 6 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Senior Cyber Security Engineer
Job Type
Not specified
Job Description
- Strong experience implementing and monitoring IEC 62443-4-1 Secure Development Lifecycle requirements.
- Strong understanding of Secure Development Lifecycle processes, software security assurance, and cybersecurity compliance.
- Hands-on experience conducting STRIDE Threat Modelling and secure architecture reviews.
- Strong experience performing penetration testing for Web Applications, Mobile Applications, and Thick Client/Desktop Applications.
- Strong understanding of OWASP Top 10, secure coding principles, application security testing methodologies, and common software vulnerabilities.
- Strong knowledge of vulnerability assessment, vulnerability management, and industry-standard risk scoring methodologies such as CVSS.
- Hands-on experience with application security tools such as Burp Suite, OWASP ZAP, SonarQube, Black Duck, Wireshark, and common Kali Linux security tools.
- Good understanding of software development and secure development practices using one or more technologies such as .NET/C#, Java, Python, or C++.
- Strong understanding of web technologies, REST APIs, authentication and authorization mechanisms, encryption, secure communications, and networking concepts including HTTP, HTTPS, TCP/IP, and TLS.
- Good understanding of security controls such as encryption, secure authentication, secure session management, defense-in-depth, least privilege, and Zero Trust principles.
- Experience working in Agile/Scrum development environments with cross-functional software engineering teams.
- Experience developing and reviewing security documentation, standards, procedures, and compliance evidence.
- Excellent analytical, problem-solving, communication, and stakeholder management skills.
- Ability to mentor junior engineers and promote secure development best practices across project teams.
Minimum Qualification
- Bachelor’s degree in computer science, Information Technology, Electronics, Cybersecurity, or a related Engineering discipline.
- 3–5 years of experience in Application Security/Product Security (preferred over network security).
- Professional cybersecurity certifications such as CEH, CompTIA Security+, CompTIA PenTest+, or equivalent are preferred.
Roles and Responsibilities
- Drive and monitor Secure Development Lifecycle (SDL) implementation across software development projects in compliance with prescribed cybersecurity standards.
- Ensure project compliance with IEC 62443-4-1 Secure Development Lifecycle requirements by creating/maintaining compliance artifacts and client-defined cybersecurity processes.
- Contribute to all stages of the Secure Development Lifecycle, including Security Requirements Analysis, Secure Design, Secure Implementation, Security Testing, and Secure Deployment.
- Support STRIDE-based Threat Modelling activities for software products and collaborate with architects and development teams to identify and mitigate security risks.
- Ensure project teams adhere to secure coding standards by supporting manual code reviews and automated security scanning activities.
- Coordinate and analyze Static Application Security Testing (SAST) and Software Composition Analysis (SCA) results using approved security tools, and work with development teams to remediate identified findings.
- Develop security test plans covering penetration testing, security requirements verification, threat validation testing, vulnerability assessment, and regression testing.
- Design and maintain comprehensive security test cases and test suites aligned with project requirements and cybersecurity standards.
- Perform manual penetration testing of web applications, mobile applications, and thick client applications, validate identified vulnerabilities, and verify remediation effectiveness.
- Review, analyze, document, and track security defects through successful closure while ensuring timely reporting and retesting.
- Perform vulnerability analysis for internally identified issues, automated scan findings, third-party disclosures, and customer-reported vulnerabilities using industry-standard risk assessment methodologies.
- Participate in Agile sprint planning to identify, estimate, and track security-related activities and user stories.
- Collaborate closely with software developers, testers, and project teams to embed security throughout the software development lifecycle.
- Participate in customer discussions and technical reviews to communicate project security posture, compliance status, security risks, and remediation activities.
- Represent projects during internal quality audits and external cybersecurity assessments by providing compliance evidence and addressing audit observations.
- Conduct security awareness sessions and technical guidance for development teams on secure development practices and emerging security threats.
- Continuously stay updated with evolving cybersecurity threats, vulnerabilities, tools, technologies, and industry best practices.
No Referrers Available
There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.
