Role- Information Security Engineer
Location- Bangalore Hybrid 2 Days Onsite
Company- InCred
Job Description
● Evaluating, Testing, and integrating security tools, standards, and associated processes as per the
security framework.
● Identify, prioritize, and track security incidents and manage related platforms such as SIEM ( Wazuh
, Blusapphire, Qualys ) , DLP ( Email and Application), EDR and other security tools
● Ability to run automated and manual scans on tools like - Burpsuite and Nessus Improving and
supporting application security tool deployments including static analysis and runtime testing tools.
● Assist in creating and managing the framework for Information Security in alignment with
industry best practices (ISO 27001, NIST CSF, OWASP top 10)
● Improve the cyber security program governance processes including cyber security risk
reporting (recommending recent report formats, reporting technologies and collaborating with
team members to build-out reports/dashboards) and governance committee
● Develop of cyber security standards,
including incorporating industry practices and
applicable compliance requirements
● Monitor and report compliance with cyber security standards and security rules of relevant
cyber security and regulatory privacy requirements
● Improving and supporting application security tool deployments including static analysis and runtime
testing tools.
● Create and manage process to guide development and testing teams on proactively finding
application security risks
● Improving and maintaining secure development standards.
● Supporting the application architecture/design review processes whenever application security
expertise is needed.
● Oversee and improve third-party information security risk management programs to assess
risks associated with the usage of third-parties/vendors. Assist in 3rd party security due-
diligence reviews
● Conduct periodic penetration testing services of application and Network related infrastructure.
Closure