04 Aug
|
Nuclay
|
Gurugram
About the Role
We run a PHP (Laminas) application on AWS that processes cardholder data and must maintain PCI DSS Level 1 compliance annually. We need a deep, hands-on security specialist to find and close the gaps at our critical junctions — the application's trust boundaries, our identity and data controls, and the cardholder data environment (CDE) — and keep them closed as we scale.
This is a security-led, hands-on role . You should be as comfortable reviewing a Laminas controller for a broken access-control or deserialization flaw as scoping the CDE for a QSA. Accountability for our security posture and PCI readiness sits with you.
What You'll Own
- Application security (PHP/Laminas): Deep code review (manual + tooling), threat-modeling of auth/session/payment flows, and remediation of OWASP Top 10 and PHP-specific bugs (SQLi, XSS, CSRF, broken access control, SSRF, insecure deserialization/object injection). Govern the Composer supply chain and establish a secure SDLC the dev team can follow.
- PCI DSS Level 1: Own readiness end to end — CDE scoping, network segmentation, QSA coordination, ROC/AOC evidence, quarterly ASV scans, and annual penetration + segmentation testing. Depth on Requirement 6 and the v4.0 client-side/anti-skimming controls. Handle PAN masking, encryption, tokenization, and key management.
- Cloud security (AWS): Harden IAM (least-privilege), VPC segmentation, KMS, S3,
and secrets; keep the CDE segmented. Deploy and tune GuardDuty, Security Hub, Config, Inspector, CloudTrail, and WAF with compliant logging. Build detection and incident-response runbooks.
- Pipeline security: Embed SAST, DAST, SCA, secrets detection, and IaC scanning (Terraform/CloudFormation) into CI/CD, and automate evidence collection for continuous compliance.
Must-Have Experience
- 10–15 years in security with proven, hands-on depth in application security (we'll probe this hard)
- Hands-on PHP security review; Laminas / Zend Framework strongly preferred
- Deep practical command of the OWASP Top 10 and secure auth/session/access-control design
- Direct PCI DSS Level 1 experience — CDE scoping, segmentation, and a QSA-led ROC (not just familiarity)
- Strong AWS security across IAM, VPC, KMS, and AWS-native security services
- Penetration testing, vulnerability management, and threat modeling
- IaC (Terraform/CloudFormation) and CI/CD security integration
- Python/scripting for automation
- Excellent communication — gets developers to act on findings and explains risk to non-technical stakeholders
Good to Have
- AWS Certified Security – Specialty ; CISSP / CCSP / OSCP
- Payment/fintech or regulated-setting experience; tokenization or payment-gateway familiarity
- Cloud forensics and incident response
- Docker / Kubernetes (EKS/ECS) security
📌 Senior Application & Cloud Security Engineer (AWS · PHP/Laminas · PCI DSS Level 1) (Gurugram)
🏢 Nuclay
📍 Gurugram