Security Engineer(VAPT)

4 months ago


Bengaluru, India KreditBee Full time
We are looking for an outstanding Senior Security Engineer who is highly technical and is responsible for ensuring the security for a broad range of environments, endpoints and technologies in a . Candidate needs to be a self-starter who can independently and collaboratively work with little direction in a fast-moving environment. Ideal candidates for this role will have experience of 2+years.
 Job Responsibilities : • Review and assess the company and third-party partners on overall security posture. • Oversee vulnerability scanning, testing, and validation and make tool/solution recommendations to the security team. • Guides and performs security activities including penetration testing and vulnerability analysis, audits and assessments, code review, static and dynamic testing, and ethical hacking. • Implementing code review processes and tooling and being a trusted advisor to the Engineering teams on secure coding practices. • Work closely with engineers to provide expert advice on secure SDLC (automated and manual code-review), Layer 7 security best practices, and ensuring the remediation of vulnerabilities. • Protect the company and its customers by identifying threats to user experience and user data while proposing mitigations and defenses. • Strong collaboration with Engineering, CloudOps and DevOps teams is essential. • Provide guidance on hardening end-points, containers, APIs, applications, operating systems (e.g., Linux) and AWS cloud environments. • Manage and review perimeter defenses, such as firewalls, WAF- s, and IDPS. • Participate as a key hands-on member in cybersecurity incident response and recovery activities. • Capacity and tolerance for extreme context switching and interruptions while remaining productive and able to provide effective, safe guidance. • Maintain knowledge and skills to keep up with the rapidly changing threat landscape. • Work collaboratively with internal and external departments, vendors, and other key stakeholders. • Be the SME for Application security process • Build the Security team • Manage work efforts end-to-end of the team 
Key Skills we are looking for : • Ability to work with security tooling to find vulnerabilities in the code base and dependencies. Ability to work with Sonarcloud, dependabot or other vulnerability tools. • Ability to find out how to fix problems and provide support for engineers/developers on the team • Have an offensive mindset • Deep understanding of security fundamentals, including operating systems, networking, virtualization, identity and access management, and security countermeasures. • Strong understanding of Application Security testing, Oauth frameworks, OWASP top 10, and Penetration Testing. • Perform iterative threat and vulnerability assessments and pen tests for re-assessing throughout a products' lifetime. • In-depth knowledge of web technologies, protocols, web services, and interfaces required • Knowledge of penetration testing techniques, application security vulnerabilities, OWASP Top 10, SANS 25, CWE, etc. required • Deep understanding of security vulnerabilities and mitigations. • Familiarity using AWS Cloud Services (EC2, DynamoDB, API Gateway, RDS, Lambda, CloudFront, CloudFormation, CloudWatch, Route 53, etc.), micro services programming (AWS Lambda, Docker, etc.) • Deep understanding of OWASP Top 10 and CWE 25; with proven track record and experience in implementing and integrating remediation strategies • Excellent understanding of Cyber Security Operations and Incident Response processes. • Knowledge of TCP/IP network fundamentals • Knowledge of PCI/DSS and its technical controls • Experience with Firewall, IDS/IPS, WAF (Web Application Firewall) preferred • Strong working knowledge of Linux Operating Systems • Good working knowledge of Windows Operating Systems • Scripting skills (e.g., Perl, Python,Go, shell scripting). • Deep understating of API security and its security posture • Knowledge of threat modeling or other risk identification techniques. • Solid understanding of the secure Software Development Lifecycle (sSDLC) best practices to include, but not limited to in IT and IT security testing methods and metrics, penetration testing, threat hunting, system security monitoring, incident response, technical policy monitoring, familiarity with Enterprise Risk Management, and internal/external audit principles and practices. • Experience with fuzzing, static and dynamic code analysis. • Ability to write fully functional exploits for common vulnerabilities such as simple stack overflow, cross-site scripting, or SQL injection. 
Skills : Python, Shell Scripting, SSDLC, PERL, LINUX OS, API Security, TCP/IP Networking
  • Vapt

    6 months ago


    Bengaluru, Karnataka, India Secureinteli Technologies Full time

    **Key Responsibilities** 2. Analyzing and interpreting scan results, identifying potential vulnerabilities, and providing actionable recommendations for remediation. 3. Collaborating with cross-functional teams to prioritize and address identified vulnerabilities in a timely manner. 4. Developing and maintaining comprehensive documentation of assessment...

  • Security Engineer

    1 month ago


    Bengaluru, India MNR Solutions Full time

    Core Security Skills : - Network Security, including firewall configurations, intrusion detection/prevention systems (IDS/IPS)- Vulnerability assessment and penetration testing (VAPT)- Incident response and threat hunting- Security Information and Event Management (SIEM) tools (e.g., Splunk, QRadar, ArcSight)- Knowledge of secure coding practices and code...

  • Security Engineer

    2 weeks ago


    Bengaluru, India MNR Solutions Full time

    Job Description : Location : Bangalore (2 days in ITPL Whitefield, Bangalore & 1 day in Decathlon Anubhava, Bangalore)Way OF Working : 3 days from officeMandatory Skill :- Technical knowledge of at least one major public cloud like AWS, GCP, Azure etc- AWS is Preferred - Experience of vulnerability assessments, Penetration Testing, Web, Mobile Application &...


  • Bengaluru, India Swiggy Full time

    Job Profile : Software Development Engineer III - Security Engineering- Location : Bangalore | KarnatakaYears of Experience : 6 - 8yrsAbout the Team & The Role :Swiggy is looking for a skilled, motivated, and collaborative Lead Security Engineer with a strong security mindset to join our Security team. In this role, you will serve as an expert and mentor to...

  • VAPT Engineer

    4 months ago


    Bengaluru, India Scrut Automation Full time

    Job Role: VAPT Engineer Responsibilities Conduct Vulnerability Assessments of Application and Network Devices using various open-source and commercial tools Conduct penetration tests and launch exploits using Burpsuite, Nessus, etc penetration testing distribution tools sets Research and maintain proficiency in Application and Computer...


  • Bengaluru, India NETSACH GLOBAL Full time

    Greetings from Netsach - A Cyber Security Company.Job OverviewWe are seeking a skilled Pentester/VAPT Consultant to strengthen our cybersecurity team. The role involves conducting penetration testing and vulnerability assessments to identify security weaknesses in systems, networks, and applications. Responsibilities include simulating cyberattacks,...


  • Bengaluru, Karnataka, India Wipro Limited Full time

    Bengaluru, India - GSH - 3121953 **Job Description**: **Security Risk Assessor Job description** **Roles and responsibilities**: - Performing security design reviews, identifying security issues at design phase and reviewing change requests. - Performing threat modelling and analysing wider security impact and advising security controls. - Capable to...

  • Security Intern

    5 months ago


    Bengaluru, India Apna Full time

    **Security Engineering Intern** **Responsibilities**: - Gain knowledge and understanding of cloud security and infrastructure. - Collaborate with the team to design, develop, and implement security solutions. - Conduct security research and keep up-to-date with the latest security trends and technologies. - Work on automation and CI/CD pipelines for...


  • Bengaluru, India Optym Full time

    Company Overview:Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, India Optym Full time

    Company Overview:Founded in 2000, Optym is building Saa S solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, Karnataka, India Optym Full time

    At Optym, we're looking for a highly skilled Senior Network Security Engineer to join our team and help us maintain the security of our network infrastructure. As a key member of our IT team, you'll be responsible for configuring, managing, and monitoring local office and datacenter networking.Key Responsibilities:Configure and manage local office and...


  • Bengaluru, India Optym Full time

    Company Overview:Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, India RSA Security Full time

    RSA - Application Security Engineer (Location: Hybrid/ Remote India) RSA offers mission-driven security solutions that provide organizations with a unified approach to managing digital risk that hinges on integrated visibility, automated insights and coordinated actions. RSA solutions are designed to effectively detect and respond to advanced...


  • Bengaluru, Karnataka, India Mouser Electronics Full time

    Job Summary:Mouser Electronics is seeking an experienced IT Security System Administrator III: Network Defender to join our team. This role requires a deep understanding of network security protocols and the ability to analyze complex system vulnerabilities.The ideal candidate will have 4+ years of experience in Information Security (VAPT) and a Bachelor of...


  • Bengaluru, India Tata Consultancy Services Full time

    TCS is Hiring VAPT for Bangalore LocationSkill: Vulnerability Assessment & Penetration TestingExperience: 4-12 yearsLocation: BangaloreInterview Mode: Walk-inJob DescriptionMust-Have1. CI/CD integration of SAST(Sonar Qube, Fortify, checkmarx, Veracode etc.,) and DSAT tools (OWASP ZAP DAST, Webinspect, Appscan, etc., Dependency-check (Jira plugin) and...


  • Bengaluru, India Optym Full time

    Company Overview:Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, India Optym Full time

    Company Overview:Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, India Optym Full time

    Company Overview: Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas,...


  • Bengaluru, India Tata Consultancy Services Full time

    TCS is Hiring VAPT for Bangalore LocationSkill: Vulnerability Assessment & Penetration TestingExperience: 4-12 yearsLocation: BangaloreInterview Mode: Walk-inJob DescriptionMust-Have1. CI/CD integration of SAST(SonarQube, Fortify, checkmarx, Veracode etc.,) and DSAT tools (OWASP ZAP DAST, Webinspect, Appscan, etc., Dependency-check (Jira plugin) and...


  • Bengaluru, Karnataka, India Ambient Security Full time

    Ambient Security is an innovative cybersecurity startup on a mission to revolutionize enterprise security by reducing the risk of privileged account takeovers and cyber attacks.We're seeking highly skilled software engineers at all levels to lead the design and implementation of cutting-edge technologies in security, large-scale distributed systems, AI, and...