Senior Information Security Engineer

Vunet Systems
Posted on
Vunet Systems logo

Experience
2 - 6 yrs
Job Location
Bengaluru, India
Vacancy
3
Designation
Senior Information Security Engineer
Job Type
Not specified

Job Description



Your Role: Senior Information Security Engineer

Experience: 2-6 years

Education: BE/B.ech/BCA or ME/M.Tech/Msc/MCA

Location: Bengaluru (HSR Layout, WFO)

Notice Period: 15 Days / Immediate joiners


As a Senior Information Security Engineer, you will be responsible for driving security initiatives across cloud-native, hybrid, and on-premise deployments of VuNets platform.
You will lead security assessments, compliance programs, DevSecOps initiatives, customer security reviews, vulnerability management programs, and security architecture reviews while partnering closely with Engineering, Product, DevOps, and Customer Success teams.

Roles & Responsibilities
Platform Security & Hardening:

  • Own and continuously strengthen the information security posture of VuNet's Business Observability platform across SaaS, cloud-native, hybrid, and on-premise deployment models
  • Lead comprehensive security assessments including application security testing, API security testing, infrastructure security reviews, penetration testing, and CIS benchmark validation
  • Define, implement, and govern security controls across cloud environments, Kubernetes platforms, containerized workloads, and enterprise deployments
  • Establish and maintain secure deployment standards, hardening guidelines, and security architecture recommendations for both customer-managed and cloud-hosted environments
  • Manage endpoint security and EDR platforms, including endpoint hardening, malware protection, detection engineering, and security monitoring across enterprise assets
  • Support enterprise security initiatives including VPN security, identity and access management, infrastructure hardening, and privileged access controls

DevSecOps & Vulnerability Management

  • Drive DevSecOps initiatives by integrating vulnerability management, SAST, DAST, container scanning, dependency scanning, compliance validation, and security gates into CI/CD pipelines.
  • Own the end-to-end vulnerability management lifecycle including CVE analysis, CVSS-based risk assessment, prioritization, remediation tracking, validation, and reporting.
  • Develop and maintain security automation using Python, Bash, and scripting for vulnerability assessments, reporting, and security operations.
  • Maintain Software Bill of Materials (SBOMs), open-source software inventory, license compliance, and software supply chain security controls.
  • Evaluate, implement, and optimize security technologies for application security, cloud security, vulnerability management, compliance automation, and security monitoring.

Security Architecture & Risk

  • Lead threat modeling exercises, security design reviews, and risk assessments for new products, features, and architectural changes.
  • Maintain security policies, standards, procedures, audit evidence repositories, and risk management frameworks.
  • Stay ahead of emerging threats, evolving regulations, and industry best practices to continuously improve VuNet's security posture.

Compliance & Governance

  • Drive compliance and governance programs including ISO 27001, SOC 2 Type II, GDPR, customer audits, and regulatory security requirements.
  • Act as the primary security stakeholder during customer security reviews, vendor assessments, compliance evaluations, and technical due diligence engagements.
  • Maintain audit evidence repositories, risk registers, and compliance documentation to ensure audit readiness at all times.

Stakeholder Engagement & Leadership

  • Partner with Engineering, Product Management, Customer Success, and Leadership teams to define security requirements and ensure timely closure of security risks and compliance gaps.
  • Mentor junior security engineers and promote a security-first culture across engineering and operational teams.

What You Bring
Mandatory Skills:
2-6 years of hands-on experience in Information Security, Product Security, Application Security, or Cybersecurity Engineering.

Application & Infrastructure Security

  • Strong expertise in Web, API, Infrastructure, Cloud, and Kubernetes security.
  • Experience performing penetration testing, vulnerability assessments, security audits, and platform hardening.
  • Strong understanding of OWASP Top 10, Secure SDLC, Threat Modeling, and Risk Assessment methodologies.
  • Hands-on experience with at least one major cloud platform (AWS, GCP, or Azure) including cloud-native security controls.

DevSecOps & Vulnerability Management

  • Experience integrating security controls within CI/CD pipelines including SAST, DAST, container scanning, and dependency scanning.
  • Strong understanding of CVE analysis, CVSS scoring, vulnerability prioritization, and risk-based remediation.
  • Experience with SBOM generation, OSS inventory management, software supply chain security, and open-source license compliance.

Kubernetes & Container Security

  • Hands-on experience with Kubernetes security assessments, RBAC reviews, CIS benchmark validation, container image scanning, and secrets management.

Security Tools
Hands-on experience with tools across the following categories - specific tools may vary:

  • Pen Testing / Scanning: Burp Suite, OWASP ZAP, Nmap, Nessus, or equivalent
  • Container / K8s Security: Trivy, Kubescape, Dockle, or equivalent
  • SAST / Code Scanning: SonarQube, Semgrep, Snyk, or equivalent
  • Vulnerability Management: Qualys or equivalent
  • SIEM / Monitoring: Any enterprise SIEM platform

Compliance & Governance

  • Experience managing ISO 27001, SOC 2 Type II, GDPR, and customer compliance requirements.
  • Ability to independently drive audit preparation, customer security reviews, and remediation programs.

Scripting & Automation

  • Hands-on experience with Python, Bash, or similar scripting languages for security automation, reporting, and workflow orchestration


No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.