Experience
3 - 8 yrs
Job Location
Bengaluru, India
Vacancy
1
Designation
Senior Cyber Security Engineer
Job Type
ONSITE
Job Description
- Strong experience implementing and monitoring IEC 62443-4-1 Secure Development Lifecycle requirements.
- Strong understanding of Secure Development Lifecycle processes, software security assurance, and cybersecurity compliance.
- Hands-on experience conducting STRIDE Threat Modelling and secure architecture reviews.
- Strong experience performing penetration testing for Web Applications, Mobile Applications, and Thick Client/Desktop Applications.
- Strong understanding of OWASP Top 10, secure coding principles, application security testing methodologies, and common software vulnerabilities.
- Strong knowledge of vulnerability assessment, vulnerability management, and industry-standard risk scoring methodologies such as CVSS.
- Hands-on experience with application security tools such as Burp Suite, OWASP ZAP, SonarQube, Black Duck, Wireshark, and common Kali Linux security tools.
- Good understanding of software development and secure development practices using one or more technologies such as .NET/C#, Java, Python, or C++.
- Strong understanding of web technologies, REST APIs, authentication and authorization mechanisms, encryption, secure communications, and networking concepts including HTTP, HTTPS, TCP/IP, and TLS.
- Good understanding of security controls such as encryption, secure authentication, secure session management, defense-in-depth, least privilege, and Zero Trust principles.
- Experience working in Agile/Scrum development environments with cross-functional software engineering teams.
- Experience developing and reviewing security documentation, standards, procedures, and compliance evidence.
- Excellent analytical, problem-solving, communication, and stakeholder management skills.
- Ability to mentor junior engineers and promote secure development best practices across project teams.
Minimum Qualification
- Bachelor s degree in computer science, Information Technology, Electronics, Cybersecurity, or a related Engineering discipline.
- 3-5 years of experience in Application Security/Product Security (preferred over network security).
- Professional cybersecurity certifications such as CEH, CompTIA Security+, CompTIA PenTest+, or equivalent are preferred.
