06 Aug
|
Happiest Minds Technologies
|
Bengaluru
06 Aug
Happiest Minds Technologies
Bengaluru
Principal Security Engineer Location: Bengaluru, India Years of Experience: 12+ years Job Summary: We are seeking a highly skilled Principal Security Engineer with extensive experience in Application Security, Cloud Security, and DevSecOps. The ideal candidate will have a proven track record in enterprise and regulated environments, demonstrating expertise in vulnerability assessment and penetration testing (VAPT), threat modeling, and secure software development lifecycle (SDLC) implementation. This role requires a hands-on approach to integrating security into CI/CD pipelines and collaborating with cross-functional teams to ensure secure application deployments.
Responsibilities Conduct comprehensive vulnerability assessments and penetration testing across applications, APIs, web, mobile, and thick-client environments.
Implement secure SDLC practices aligned with industry standards such as OWASP Top 10, NIST, ISO 27001, PTES, and ASVS.
Perform threat modeling using STRIDE methodology to identify and mitigate potential security risks.
Manage the vulnerability lifecycle, including identification, remediation, and reporting of security issues.
Conduct architecture security reviews to ensure compliance with security best practices.
Integrate security tools (SAST/DAST) into CI/CD pipelines using GitHub Actions and DevSecOps methodologies.
Provide guidance on cloud and container security, specifically with Docker and Kubernetes.
Collaborate with engineering, infrastructure, and business stakeholders to develop secure, scalable, and compliant enterprise solutions.
Mandatory Skills
Robust knowledge and experience in Application Security.
12+ years of experience in Application Security, Cloud Security, and DevSecOps.
Hands-on experience with SAST/DAST tools such as Fortify SCA/SSC, Checkmarx, Burp Suite, Invicti (Netsparker), Qualys, and Nessus.
Proven ability to manage vulnerability lifecycle and perform architecture security reviews.
Experience in integrating security into CI/CD pipelines.
Strong background in cloud and container security.
Preferred Skills Experience with compliance and risk management frameworks.
Familiarity with secure application deployment practices.
Excellent communication and leadership skills.
Qualifications Bachelor's degree in Computer Science, Information Security, or a related field.
Relevant security certifications (e.g., CISSP, CISM, CEH) are a plus. If you are a proactive and experienced security professional looking to make a significant impact in a dynamic environment, we encourage you to apply.
Application
Security
📌 TECHNICAL LEAD - Application Security (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru