KGeN - Security Engineer - Vulnerability Management
1 week ago
Description
What You'll Do (Key Responsibilities) :
Security Strategy & Roadmap
- Develop and execute a comprehensive security roadmap that aligns with business objectives, growth plans, and regulatory requirements.
Security Architecture & Design
- Lead the design and implementation of secure architectures for new and existing systems, applications, and infrastructure, ensuring "security by design" principles are integrated from inception.
Cloud Security Expertise
- Secure our cloud environment(s) (e.g., AWS, GCP), including IAM, network segmentation, data protection, container security (Docker, Kubernetes), and serverless security.
Application Security (AppSec)
- Establish and champion secure software development lifecycle (SSDLC) practices.
- Conduct Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).
- Perform threat modeling, security code reviews, and manage security vulnerabilities within our applications and APIs.
Infrastructure & Network Security
- Implement and manage security controls for our core infrastructure and networks, including firewalls, IDS/IPS, WAFs, VPNs, endpoint detection & response (EDR), and vulnerability management.
Incident Response & Management
- Develop, test, and lead our incident response plan.
- Act as the primary lead for security incidents, from detection and analysis to containment, eradication, recovery, and post-mortem analysis.
Vulnerability Management & Penetration Testing
- Drive proactive vulnerability assessments and manage external penetration testing engagements and bug bounty programs.
- Perform internal penetration tests and red teaming exercises to identify and exploit weaknesses.
- Prioritize and track remediation efforts with engineering teams.
- Risk & Compliance : Identify, assess, and mitigate security risks. Ensure adherence to relevant industry standards and certifications (e.g., ISO 27001, SOC 2, PCI DSS) and navigate data privacy regulations.
- Automation & Tooling : Evaluate, implement, and automate security tools and processes to enhance efficiency and scalability (DevSecOps).
- Security Awareness & Culture : Foster a strong security-aware culture across all teams through training, guidelines, and continuous communication.
- Vendor Security Assessment : Conduct security assessments of third-party vendors and ensure their adherence to our security standards.
What We're Looking For (Required Skills & Experience)
- 3+ years of dedicated experience in a security engineering role, with at least 2 years in a lead or senior capacity, preferably in a fast-paced startup or high-growth environment.
- Deep hands-on expertise across core security domains : Cloud Security, Application Security (AppSec), Infrastructure Security, and Network Security.
- Proven experience with at least one major cloud platform (AWS or GCP) and its native security services.
- Strong understanding of secure coding principles and extensive experience with security vulnerabilities (OWASP Top 10, CWE).
- Proficiency with common penetration testing tools and frameworks such as:
- Web Application Tools : Burp Suite, OWASP ZAP, Nikto.
- Network Scanners : Nmap, Nessus, OpenVAS.
- Exploitation Frameworks : Metasploit.
- Forensics/Packet Analysis : Wireshark.
- Password Crackers : John the Ripper, Hashcat.
- Operating Systems/Distributions : Kali Linux.
- Demonstrated experience with Incident Response procedures and leading security investigations.
- Proficiency in at least one scripting language (e.g., Python, Go, Bash) for security automation and tooling.
- Excellent problem-solving skills and the ability to analyze complex technical and security challenges quickly.
- Proactive and autonomous mindset : Ability to identify security gaps, have a hacker mindset, propose solutions, and drive initiatives with minimal supervision.
- Strong communication skills : Ability to clearly articulate technical security concepts, risks, and recommendations to both technical and non-technical stakeholders.
- Passion for continuous learning and staying abreast of the latest cybersecurity trends, threats, and technologies.
Bonus Points (Nice-to-Have Skills & Experience)
- Experience in a highly regulated industry (e.g., FinTech, Healthcare, E-commerce with high transaction volumes) preferably from background in product companies.
- Experience with Web3/Blockchain security concepts, smart contract auditing, or decentralized systems.
- Relevant Security Certifications (e.g., CISSP, CISM, OSCP, CEH, CCSK, GSEC, etc.).
- Familiarity with compliance frameworks relevant to India, such as IT Act, data localization guidelines, or specific industry body regulations.
- Prior experience building, mentoring, or leading a small security team.
)
-
Vulnerability Management Engineer
3 days ago
Bengaluru, Karnataka, India HP Full timeAs the world around us becomes more connected and more digital, there are increased opportunities for fraud and disruption due to cybersecurity attacks. The need for companies, products, and services to be secure is more important than ever in this constantly changing landscape.Are you passionate about keeping good people safe from bad actors? We are too We...
-
Vulnerability Management SME
1 day ago
Bengaluru, Karnataka, India Thakral One Full timeExperience as a Vulnerability AnalystUnderstanding of Vulnerability Management principlesUnderstanding of Risk Assessment MethodologiesKnowledge of industry standard scoring models such as CVSS (Common Vulnerability Scoring System) or CCSS (Common Configuration Scoring System)Knowledge of industry standard data models such as CPE (Collection Processing...
-
Vulnerability Management SME
1 day ago
Bengaluru, Karnataka, India Thakral One Full timeExperience as a Vulnerability AnalystUnderstanding of Vulnerability Management principlesUnderstanding of Risk Assessment MethodologiesKnowledge of industry standard scoring models such as CVSS (Common Vulnerability Scoring System) or CCSS (Common Configuration Scoring System)Knowledge of industry standard data models such as CPE (Collection Processing...
-
Bengaluru, Karnataka, India Tietoevry Full timeJob DescriptionJob Title:Mid-Level Threat Intelligence and Vulnerability Management EngineerExperience:1-3 YearsAbout the Role:We are looking for a motivated and detail-oriented cybersecurity professional to join our team as a Threat Intelligence and Vulnerability Management Engineer. This role focuses on supporting the identification and mitigation of...
-
Bengaluru, Karnataka, India Tietoevry Full timeCompany Description We are developers of digital futuresTietoevry is a leading software and digital engineering services company with global market reach and capabilities. We provide customers across different industries with mission-critical solutions through our specialized software businesses Tietoevry Care, Tietoevry Banking and Tietoevry Industry, as...
-
Vulnerability Management Professional
1 day ago
Bengaluru, Karnataka, India IDESLABS PRIVATE LIMITED Full timeHi,Greetings from the IDESLABS,Urgent Requirement for Vulnerability Management,Location:BangaloreEmployment Type:C2HNotice Period:ImmediateJD:Conduct vulnerability scan using Prisma's cloudvulnerabilityscanning features to identify vulnerabilities in cloud resources.Assess and monitor security posture of Kubernetes clusters, including network policies, pod...
-
IT Vulnerability Management Analyst I
1 week ago
Bengaluru, Karnataka, India StoneX Full timeOverviewConnecting clients to markets – and talent to opportunity with 4,300 employees and over 400,000 retail and institutional clients from more than 80 offices spread across five continents, we're a Fortune-100, Nasdaq-listed provider, connecting clients to the global markets – focusing on innovation, human connection, and providing world-class...
-
Security Engineer
3 weeks ago
Bengaluru, Karnataka, India, Karnataka Infogain Full timeTitle: Security Engineer (6+ Years)Job Description:Use CrowdStrike reports to evaluate all security vulnerabilities on both Windows and Linux systems.Analyze the requirements to remediate the security vulnerabilities.Create processes that will remediate the vulnerabilities.Work with the Managed Services team and the BUs to schedule the remediations in within...
-
Security Engineer
2 weeks ago
Bengaluru, Karnataka, India Scapia Full time ₹ 60,000 - ₹ 1,80,000 per yearResponsibilitiesDesign, implement, and maintain security solutions to protect company assets, applications, and infrastructure.Monitor security threats, vulnerabilities, and incidents, responding proactively to mitigate risks.Conduct regular security assessments, penetration testing, and code reviews to identify and address vulnerabilities.Develop and...
-
Technical Account Manager
3 weeks ago
Bengaluru, Karnataka, India, Karnataka Astra Security Full timeAbout Astra: Astra is a cybersecurity SaaS company that makes pentests simple with its AI-led Offensive Pentest Platform. Our continuous vulnerability scanner emulates hacker behavior with over 15,000 security tests, enabling CTOs and CISOs to achieve continuous security at scale, remediate vulnerabilities faster, and seamlessly embed security into DevOps...