SME IT security (Secunderabad)

SME IT security (Secunderabad)

05 Aug
|
HCL Technologies
|
Secunderabad

05 Aug

HCL Technologies

Secunderabad

SME - IT security

Experience: Not Available to Not Available years

Location: Hyderabad, India

Skills: STRIDE, Java, C#, JavaScript, TypeScript, Python, application security, DevSecOps, product security, threat modeling, web architectures, service-oriented architectures, APIs, security controls, input validation, authentication, authorization, secure logging, error handling, CI/CD

Job Summary
We are looking for a security engineer who can lead structured threat modeling (using STRIDE) and also implement or review targeted application changes as part of vulnerability remediation. Formal threat‑modeling exercises are performed periodically (for example, annually) across several key services, with ongoing collaboration with engineering to keep understanding and documentation current, and to translate CVEs and other findings into concrete fixes in code and configuration.

Key Responsibilities
• Perform STRIDE‑based threat modeling for multiple applications and services, including data‑flow diagrams, identification of threats, and risk/ranking.
• Work with engineering, architecture, and product teams to understand current designs, review documentation, and keep the threat models aligned with real implementations.
• Review security findings and public or vendor‑reported vulnerabilities (CVEs), assess their impact on the applications and underlying services, and define appropriate remediation steps.
• Implement or review small, focused application changes (for example: input validation, authentication and authorization logic, logging, error handling,



configuration) needed to address vulnerabilities.
• Collaborate with DevOps/DevSecOps teams so that fixes are tested and delivered through CI/CD pipelines, and that security checks are built into the development lifecycle.
• Maintain clear, concise security documentation per product or service (current threat model, key risks, and implemented mitigations).

Skill Requirements
• Experience in application security, DevSecOps, or product security, including hands‑on threat modeling (ideally with STRIDE).
• Ability to read and safely modify backend or service code (for example, in one or more languages such as Java, C#, JavaScript/TypeScript, Python, or similar).
• Proven experience taking CVEs or other vulnerability reports and turning them into specific code/configuration changes.
• Familiarity with web and service‑oriented architectures, APIs, and common security controls (authentication/authorization, input validation, secure logging, error handling).
• Comfortable working from existing design documents and asking clarifying questions to map data flows and trust boundaries accurately.
• Solid communication skills and ability to explain threats, risks, and proposed fixes to both technical and non‑technical stakeholders.

Other Requirements
• Experience integrating security tooling and checks into CI/CD pipelines.
• Exposure to real‑time or event‑driven applications (for example, voice/IVR, messaging, or streaming systems), or strong interest in learning these domains.

📌 SME IT security (Secunderabad)
🏢 HCL Technologies
📍 Secunderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: sme it security (secunderabad) / secunderabad

Subscribe to this job alert:

Get the latest job offers by email for: sme it security (secunderabad) / secunderabad