Position: Security Platform Engineer Tool Configuration Data Unification
Job Type :- Remote IST
Experience :- 6 - 8 years
Position Overview
We are seeking a Security Platform Engineer specializing in Tool Configuration and Data Unification to bring deep security domain expertise to the hands-on configuration of our scanning and aggregation stack.
This role is responsible for unifying the output of multiple security scanners into a single, coherent vulnerability language. You will tune what each tool detects, define how findings are normalized and deduplicated, and design the data model that transforms raw scanner output into defensible, evaluated vulnerability records.
Working alongside DevSecOps engineers and GRC engineers, you will own the intelligence and structure of the security data pipeline determining what flows through it and how it is shaped to support FedRAMP compliance, audit evidence requirements, and actionable vulnerability management at scale.
Key Responsibilities
- Own scanner configuration and tuning across the detection fleet:
- Scan policies
- Coverage scope
- Severity mappings
- Signal quality for
- Trivy
- Semgrep
- Qualys
- Tenable
- AWS Inspector
- CrowdStrike
- Dependabot
- Design the deduplication and correlation strategy in DefectDojo, including:
- Keying logic that recognizes the same vulnerability across:
- Image scans
- Runtime scans
- Host scans
- Dependency scans
- Grouping rules that collapse duplicate findings into single actionable issues
- Target: ~70% ticket reduction
- Define the unified findings data model, including:
- Field schema
- Asset identity
- Component mapping
- AWS Reachability Analyzer
- Service mesh
- eBPF-based signals
- Feed internet-reachability determinations (IRV/NIRV) per finding.
- Configure runtime visibility using CrowdStrike Falcon Cloud Security.
- Reconcile runtime observations against image scan results to eliminate the rebuilt-but-not-redeployed gap.
- Partner with GRC engineers to ensure the data model captures all information required by the:
- LEV IRV PAIN evaluation engine
- Audit evidence requirements
- Experience writing custom scanner parsers or findings transformation code in Python.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Security Platform Engineer Tool Configuration & Data Unification (Noida)
🏢 Sparix Global
📍 Noida
Reply to this offer
Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.