Cyber Security Engineer

1 day ago


bangalore, India Anumana Full time

Position: Cyber Security EngineerExperience Range: 3 to 5 yrsJob Location: BangaloreWork Mode: Hybrid (3 days in the office, 2 days remote)Job SummaryAnumana is seeking a skilled and motivated Cybersecurity Engineer to ensure the security, integrity, and compliance of our Software as a Medical Device (SaaMD) products. This position is critical in maintaining our adherence to global security standards and regulations, specifically ISO/IEC 27001, ISO/IEC 27002, and ISO 13485.You will play a key role in implementing and monitoring security controls throughout the software development lifecycle while ensuring that our systems meet the highest standards of security and quality. Additionally, you will support audits, create threat models, conduct penetration testing, and produce comprehensive reports.Key Responsibilities: Security Control ImplementationDesign, implement, and monitor security controls within the SaaMD development lifecycle.Ensure security controls align with ISO/IEC 27001, 27002, and ISO 13485 standards.Collaborate with software development teams to integrate security best practices throughout the development pipeline.Provide guidance on secure coding practices, vulnerability management, and secure software development principles.Maintain a risk-based approach to security, identifying potential threats and vulnerabilities early in the development lifecycle. Compliance & Audit SupportProvide evidence of implemented controls and participate in internal and external audits for ISO/IEC 27001 and 27002.Collaborate with Quality and Regulatory teams to ensure ongoing compliance with ISO 13485.Develop and maintain documentation, policies, and procedures to demonstrate compliance with relevant standards.Implement and manage a robust change management and documentation process to align with audit requirements. Threat Modeling & Penetration TestingCreate, maintain, and refine threat models to identify security vulnerabilities, using tools like LucidChart.Conduct penetration testing and security assessments using tools such as BurpSuite, nmap, Wireshark, and Deptrack.Regularly perform static and dynamic analysis to identify potential vulnerabilities in the software. Vulnerability ManagementConduct vulnerability scans and assessments using tools like Grype, Dockle, and Trivy.Work with development teams to triage and prioritize vulnerabilities for remediation.Track and document vulnerabilities through their lifecycle from identification to resolution.Develop and maintain a comprehensive vulnerability management process, including reporting metrics and key performance indicators (KPIs). Reporting & CommunicationCreate detailed security assessment and penetration testing reports, including actionable remediation recommendations.Communicate findings and collaborate with cross-functional teams to ensure vulnerabilities are addressed.Provide regular updates to management on security posture, vulnerability trends, and remediation efforts. Security Awareness & TrainingContribute to the development and delivery of security awareness training for software development teams.Advocate for a culture of security within the organization, promoting adherence to security best practices. Preferred:Professional certifications such as CISSP, CEH, OSCP, CISM, or ISO/IEC 27001 Lead Implementer.Experience in security in highly regulated environments, especially SaaMD or healthcare applications.Knowledge of risk management frameworks (NIST, HITRUST) and cybersecurity standards.Experience with Continuous Integration/Continuous Deployment (CI/CD) pipelines and DevOps environments.Required Qualification:Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).3+ years of experience in cybersecurity engineering, preferably within the medical device or healthcare sector.In-depth knowledge of ISO/IEC 27001, 27002, and ISO 13485 standards and requirements.Experience with threat modeling and penetration testing methodologies and tools (e.g., BurpSuite, nmap, Wireshark, LucidChart).Hands-on experience with vulnerability assessment tools such as Grype, Dockle, Trivy, and Deptrack.Strong understanding of secure software development practices, including secure coding and DevSecOps principles.Experience in providing evidence for security audits and ensuring regulatory compliance.Familiarity with cloud security best practices, container security, and modern development environments (e.g., Docker, Kubernetes).



  • bangalore, India Tata Consultancy Services Full time

    Job Title : Cyber Security & Infrastructure Engineer - Multiple Roles Experience : 6 to 15+ Years Locations : Mumbai, Chennai, Bangalore, Hyderabad Employment Type : Full-time We are hiring experienced professionals across various domains in Cyber Security, Identity & Access Management (IAM), Cloud Security, and Infrastructure Architecture. This is an...


  • bangalore, India Tata Consultancy Services Full time

    Job Title: Cyber Security & Infrastructure Engineer - Multiple RolesExperience: 6 to 15+ YearsLocations: Mumbai, Chennai, Bangalore, HyderabadEmployment Type: Full-timeWe are hiring experienced professionals across various domains in Cyber Security, Identity & Access Management (IAM), Cloud Security, and Infrastructure Architecture. This is an excellent...


  • bangalore, India IntraEdge Full time

    Position: Cyber Security Engineer (L3)Location: RemoteExperience Level: 5+ YearsJob Type: Full-timeJob Summary:This role will lead the development and implementation of intelligent security solutions using SIEM, SOAR, and machine learning to enhance detection, response, and operational efficiency across the enterprise.Key Responsibilities * Design,...


  • bangalore, India IntraEdge Full time

    Position: Cyber Security Engineer (L3) Location: Remote Experience Level: 5+ Years Job Type: Full-time Job Summary: This role will lead the development and implementation of intelligent security solutions using SIEM, SOAR, and machine learning to enhance detection, response, and operational efficiency across the enterprise. Key Responsibilities * Design,...


  • Bangalore, India FICO Full time

    FICO (NYSE: FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. As a Product Security Engineer II in Cyber Security, you will be supporting security governance for a wide set of customer-facing products and services across full product development lifecycles. Your role focuses on executing...


  • bangalore, India Tata Consultancy Services Full time

    Need an SME with over 6+ years of experience in GRC and specialization in SEBI’s CSCRF . The candidate should be able to guide and drive the organization’s CSCRF implementation.Expert on Cyber Security matters.SME is required to attend the Cyber Security meetings on regular basis.Should be able to guide on strategies to protect company data, safeguard...


  • Bangalore, Karnataka, India Hewlett Packard Enterprise Full time

    Operations Support Engineer - Cyber Security This role has been designed as Onsite with an expectation that you will primarily work from an HPE office Who We Are Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work We help companies connect protect analyze and act on their data and applications wherever they...


  • Bangalore, India Nexoria Techworks Inc. Full time

    Job Description: Cybersecurity Engineer Location : Remote / Bangalore Employment Type : Full-time Department : Security & Risk Management Industry : IT Services & Consulting Role Category : Cybersecurity, Information Security, Threat Management Role & Responsibilities : As a Cybersecurity Engineer , you will play a critical role in safeguarding our systems,...


  • bangalore, India REA Cyber City Full time

    About REA Group:In 1995, in a garage in Melbourne, Australia, REA Group was born from a simple question: “Can we change the way the world experiences property?”Could we? Yes. Are we done? Never.Fast forward 30 years, REA Group is a market leader in online real estate in three continents and continuing to grow rapidly across the globe. The secret to our...


  • bangalore, India VOIS Full time

    Please see below job description: Experience - 6yrs+ Location - Pune/Bangalore (Hybrid) The Secure by Supplier Manager is responsible for identifying, assessing, and mitigating Cyber security and regulatory risks associated with third-party suppliers. This role ensures Vodafone’s compliance with UK-specific regulations, i.e., the UK Telecom Security Act,...