16 Aug
|
Important Group
|
Kolkata
16 Aug
Important Group
Kolkata
The Security Consultant is responsible for assessing, designing,
implementing, and maintaining information security controls to protect
organizational systems, networks, and data. The role ensures compliance with
security standards, manages cyber risks, and supports secure digital
transformation initiatives.
Key Responsibility:
1. Security Assessment & Risk Management
- Architect
enterprise-wide Application Security (AppSec) programs across complex,
distributed enterprise environments—embedding SAST, DAST, and SCA into
CI/CD pipelines to enable secure-by-design architecture and reduce
vulnerabilities.
- Define
secure architecture patterns and guardrails, integrating AppSec controls
into DevSecOps pipelines to standardize risk management across
distributed engineering teams.
- Collaborated
with Customer Security teams to embed security architecture principles
to produce secure project environment.
- Experience in Application Security governance frameworks,
aligning with NIST, ISO 27001, and PCI DSS to achieve compliance posture
and audit readiness
- Conduct
security risk assessments, vulnerability assessments, and threat
modeling across applications, infrastructure, and networks.
- Identify
security gaps and provide risk-based mitigation recommendations.
- Perform
periodic security posture reviews and maturity assessments.
2. Security Architecture & Solution Design
- Design
and review secure architecture for applications, cloud, and on-premise
systems.
- Ensure
security-by-design principles are embedded in system development and
integration.
- Review
technical designs to ensure alignment with security standards and best
practices.
3.
Application & Infrastructure Security
- Support
and define application security testing (SAST, DAST, API security
testing).
- Support
secure coding practices and review source code for vulnerabilities.
- Assess
infrastructure security including servers, databases, networks, and
endpoints.
4. Cloud & DevSecOps Security
- Implement
and review cloud security controls for AWS, Azure, or GCP environments.
- Integrate
security tools into CI/CD pipelines (DevSecOps).
- Lead full-lifecycle
SIEM deployments, from HLD/LLD design through to steady-state
operations.
- Produce detailed
solution proposals, policies, and procedures to support secure, reliable
SIEM services
- Ensure secure configuration,
identity access management, and logging in cloud platforms.
5. Security Operations & Incident Management
- Support
security incident detection, response, and investigation activities.
- Perform
root cause analysis and recommend corrective and preventive actions.
- Coordinate
with SOC, IT, and business teams during security incidents.
6. Compliance & Governance
- Ensure
compliance with security frameworks and regulations (ISO 27001, NIST,
GDPR, etc.).
- Support
internal and external security audits and risk assessments.
- Develop
and maintain security policies, standards,
and procedures.
7. Awareness & Stakeholder Engagement
- Provide
security guidance to development, infrastructure, and business teams.
- Conduct
security awareness sessions and training programs.
- Act
as a trusted advisor on security best practices and emerging threats.
8. Continuous Improvement & Reporting
- Stay
updated with latest cyber security threats, vulnerabilities, and trends.
- Prepare
security assessment reports, dashboards, and risk summaries for
management.
- Recommend
continuous improvements to enhance organizational security posture.
Requirements
Qualification: Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field.
Qualified Certificate Preferred:
- CISSP (Certified Information Systems
Security Professional).
- CISM (Certified Information Security
Manager).
- CEH (Certified Ethical Hacker).
- ISO/IEC 27001 Lead Implementer or Lead
Auditor.
- AWS / Azure / GCP Security Certification.
- CompTIA Security+ (added advantage).
Years of Exp: 8-13 years of experience in information security, cyber security
consulting, or related roles
Job Specific Skill:
- Strong knowledge of cyber security
principles, tools, and frameworks.
- Hands-on experience with vulnerability
assessment and penetration testing tools.
- Experience in application, infrastructure,
and cloud security.
- Knowledge of security compliance and
regulatory standards.
- Understanding of networking, operating
systems, and databases.
- Strong documentation, reporting, and
stakeholder communication skills.
📌 Senior Lead Engineer - Security Consultant (Kolkata)
🏢 Important Group
📍 Kolkata