Associate II, Information Security Engineer
5 days ago
We are seeking an experienced Information Security Engineer with a strong background in secure software development practices, application security testing, vulnerability management and Information Security Compliances. The ideal candidate will be responsible for ensuring that security is integrated across the software development lifecycle (SDLC) and will actively collaborate with development, DevOps, and product teams to mitigate application-level risks.
Responsibilities:
Application Security
- Perform comprehensive application security assessments, including Static Application Security Testing (SAST) Pen testing, Dynamic Application Security Testing (DAST), and API security testing across enterprise applications.
- Review and analyse source code to identify and remediate security vulnerabilities.
- Collaborate with development teams to integrate security best practices in the SDLC and provide secure coding guidance.
- Lead and support remediation efforts by providing actionable recommendations and retesting fixes.
- Conduct manual and automated web application and API penetration tests to uncover business logic and security flaws.
- Develop and maintain security testing checklists, processes, and internal documentation.
- Track and report vulnerabilities, ensuring timely closure in collaboration with development and product owners.
- Participate in threat modelling sessions and help teams prioritize risks based on severity and business impact.
- Stay current with emerging threats, vulnerabilities, attack vectors, and security technologies to proactively improve application security posture.
Information Security Compliance:
- Ensure compliance with relevant security standards and regulations, including ISO 27001, NIST Standard, risk management
- Develop and maintain security documentation and procedures.
- Assist with external security audits and assessments.
- Stay up to date on the latest security threats and vulnerabilities.
Other Duties:
- Provide security consulting and support to other teams.
- Evaluate and recommend new security technologies and solutions.
- Participate in security awareness training and initiatives.
- Understanding of Technology & Security Risk Management and Vendor Risk Management Framework
Technical Skills and Capabilities (Primary – Must Have):
- 4-5 years' experience working in IT Security in multiple capacities.
- Hands-on experience with application security tools such as Burp Suite, IBM AppScan, Acunetix, HP WebInspect, NTOSpider, Postman, and others.
- Strong expertise in manual and automated web application security testing and a deep understanding of OWASP Top 10 and business logic vulnerabilities.
- Solid experience testing RESTful and SOAP APIs, analyzing request/response flows, and validating secure implementation.
- Strong knowledge of secure coding principles, common attack vectors (OWASP, SANS Top 25, WASC), and mitigation techniques.
- Familiarity with CI/CD pipelines and integrating security testing into DevOps workflows (preferred).
- Proficiency in both Black Box and White Box testing methodologies.
Certifications (Preferred):
- Certified Ethical Hacker (CEH), OSCP, eWPT, or equivalent security certifications are preferred.
- Certification like ISO 27001, CISA, CRISC, CISM, CISSP etc. would be an added advantage.
Competencies:
- The ability to multitask, act under pressure and quickly identify and deal with priority matters under tight deadlines. Attention to detail is essential.
- The ability to handle multiple inquiries at any one time, often under considerable deadline pressure.
Desired Skills:
- Strong analytical and problem-solving skills with the ability to prioritize and manage multiple tasks.
- Excellent communication skills – capable of articulating technical issues and recommendations clearly to both technical and business stakeholders.
- Demonstrated ownership and accountability – proactive in identifying issues, taking initiative, and driving closure.
- Ability to work independently as well as in a cross-functional team environment
The Location: Gurgaon, India
-
Associate II, Information Security Engineer
7 days ago
Gurgaon, Haryana, India S&P Global Full time ₹ 10,00,000 - ₹ 25,00,000 per yearAbout the Role:OSTTRA IndiaThe Role: Associate II, Information Security EngineerThe Team: The OSTTRA Technology team is composed of Capital Markets Technology professionals, who build, support and protect the applications that operate our network. The technology landscape includes high-performance, high-volume applications as well as compute intensive...
-
Information Security Engineer II
7 days ago
Gurgaon, Haryana, India Rackspace Technology Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob description:This role focuses on ensuring that Linux-based systems and infrastructure adhere to relevant security standards, internal policies, and regulatory requirements.We are seeking a mid-level Linux Engineer to deliver Dedicated/cloud engineering services to Rackspace's clients and typically assist with the daily operations, monitoring, hardening...
-
Information Security Engineer
1 week ago
Gurgaon, Haryana, India EDGE Executive Search Full time ₹ 12,00,000 - ₹ 36,00,000 per yearOur client is a global company in the fintech sector andwork in the area of derivatives and OTC products, which are the most complex parts of the financial market. They are the market leader in derivatives post-trade processing, bringing innovation, expertise, processes and networks together to solve the post-trade challenges of global financial...
-
Cloud Security Engineer II
23 hours ago
Gurgaon, Haryana, India Insight Full time ₹ 9,00,000 - ₹ 12,00,000 per yearRequisition Number: 102328 Cloud Security Engineer II - Zscaler & Email Security Location: This is a hybrid opportunity in Delhi NCR, Hyderabad, Gurugram area.Insight at a Glance14,000+ engaged teammates globally with operations in 25 countries across the globe.Received 35+ industry and partner awards in the past year$9.2 billion in revenue#20 on...
-
Information Security
2 weeks ago
Gurgaon, Haryana, India MapMyBusiness Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Title: Information Security & Data Protection Officer (DPO) – ManagerLocation: Gurugram / OnsiteExperience: 6–7 yearsDuration - 6 monthEmployment Type: Full-TimeBudget - 1.4LPMAbout the RoleWe are seeking a highly skilled and motivated InfoSec/DPO Manager to lead our organization's information security, data protection, and compliance initiatives....
-
Information Security Engineer
1 week ago
Gurgaon, Haryana, India Growth Catalyst Group of Companies - Advatix | XPDEL | Archway Full time ₹ 10,00,000 - ₹ 25,00,000 per yearPosition Name - Security & IT-GRC AnalystSummary - Individual will primarily be responsible to research, evaluate, design, configure, implement, maintain and monitor the security systems and product solutions and triage security incidents related to such platforms. The role will also be responsible for general security administration duties including O365...
-
Information Security Auditor
24 hours ago
Gurgaon, Haryana, India Maruti Suzuki Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob Description cum Position Title: Information Security Auditor (Deputy Manager/Assistant Manager) About the Role We are seeking a detail-oriented and proactive Information Security Auditor to join our team. The role involves conducting information security audits and related activities for internal & external stakeholders, including vendors, dealers, and...
-
Sr. Information Security
2 weeks ago
Gurgaon, Haryana, India ALIQAN Technologies Full time ₹ 12,00,000 - ₹ 25,00,000 per yearJob Title: Information Security & Data Protection Officer (DPO) – ManagerLocation: GurgaonExperience: 6–7 yearsEmployment Type: 6 months contract + extAbout the RoleWe are seeking a highly skilled and motivated InfoSec/DPO Manager to lead our organization's information security, data protection, and compliance initiatives. The ideal candidate will...
-
Cloud Security Engineer
1 week ago
Gurgaon, Haryana, India Insight Enterprises Full time ₹ 4,00,000 - ₹ 12,00,000 per yearCloud Security Engineer II Requisition Number: 101835 Cloud Security Engineer II – Zscaler Location: This is a hybrid opportunity in Delhi NCR, Bangalore, Hyderabad, Gurugram area. Insight at a Glance14,000 engaged teammates globally with operations in 25 countries across the globe. Received 35 industry and partner awards in the past...
-
Cloud Security Engineer
1 week ago
Gurgaon, Haryana, India Insight Enterprises Full time ₹ 15,00,000 - ₹ 25,00,000 per yearCloud Security Engineer II Requisition Number: 102328 Cloud Security Engineer II - Zscaler & Email Security Location: This is a hybrid opportunity in Delhi NCR, Hyderabad, Gurugram area. Insight at a Glance14,000 engaged teammates globally with operations in 25 countries across the globe. Received 35 industry and partner awards in the past year ...