19 Aug
|
Trigyn Technologies
|
Gurugram
19 Aug
Trigyn Technologies
Gurugram
Job Summary
We are looking for a results-driven cybersecurity leader with 15+ years of hands-on experience in offensive security, Vulnerability Assessment Penetration Testing (VAPT), red teaming, and security remediation. Proven record of identifying critical vulnerabilities, leading remediation programs, and building resilient security postures across enterprise, cloud (AWS, Azure, GCP, OCI), and critical-infrastructure environments. Adept at leading and mentoring security teams, aligning engagements with MITRE ATT CK, OWASP, NIST, and ISO 27001, and translating technical findings into transparent, actionable guidance for executives and engineers alike. Passionate about defending national-scale infrastructure against sophisticated cyber adversaries.
Core Skills and Technologies
- Offensive Security
- Red Team: Metasploit, Cobalt Strike, BloodHound, CrackMapExec, Impacket, Responder, Sliver, Mythic, Evilginx, BeEF, SET, Burp Suite, OWASP ZAP, SQLmap, Acunetix
- Vulnerability Management: Tenable Nessus, Qualys, OpenVAS, Nmap, Nikto, Scout Suite, HCL AppScan, EPSS/KEV-based risk prioritization
- SIEM Detection: Splunk, Microsoft Sentinel, QRadar, Elastic SIEM, Wazuh
- EDR/XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR
- Threat Intelligence
- Hunting: MITRE ATT CK, Cyber Kill Chain, MISP, OpenCTI, AlienVault OTX, VirusTotal, IBM X-Force, GreyNoise
- Cloud Container Security: AWS GuardDuty, Azure Defender, Prisma Cloud, Wiz, Trivy, Falco, Kubernetes security controls
- Malware Analysis Forensics: Ghidra, IDA Free, PE Studio, YARA, Any.Run, Cuckoo Sandbox, Velociraptor, TheHive, Autopsy, FTK Imager
- AppSec Automation: SAST/secure code review (Veracode, Checkmarx), Python, PowerShell, Bash, REST APIs, SOAR (Cortex XSOAR, Tines, Shuffle)
- Governance Frameworks: ISO 27001, NIST CSF, OWASP Top 10, SANS/CIS Critical Controls, KnowBe4 security awareness
Responsibilities
- Guide and oversee SOC operations, strengthening monitoring, alerting, triage, and incident response workflows, and improving detection coverage based on red team and threat intelligence insights.
- Drive Web Application Firewall (WAF) implementation - rule design, policy tuning, and bypass testing - and advise application teams on securing applications and underlying infrastructure through secure design reviews and hardening guidance.
- Perform comprehensive risk calculation and risk scoring by correlating assessment results, vulnerability scan data, penetration testing findings, red team outcomes, and inherited controls to determine overall organizational risk and remediation priorities.
- Provide technical leadership and guidance to application vendors and cloud service providers (CSP) teams to plan, execute, and validate VAPT, red teaming exercises, and data privacy audits, ensuring alignment with security, compliance, and regulatory requirements.
- Validate and assess security configurations, IAM policies, network segmentation, logging, monitoring, and threat detection controls across Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI), AWS, and Azure Cloud to support secure cloud and hybrid environments.
- Lead and mentor a team of cybersecurity professionals in the planning, execution, and reporting of penetration testing and red team engagements, simulating real-world adversary tactics, techniques, and procedures (TTPs) to identify control gaps and improve detection and response capabilities.
- Design and execute full-scope red teaming operations, including reconnaissance, initial access, lateral movement, privilege escalation, persistence, command- and-control, and data exfiltration, aligned with MITRE ATT CK and threat-actor emulation models.
- Collaborate with application vendors,
blue teams, and CSP stakeholders to prioritize risks uncovered during red team and penetration testing engagements, develop mitigation strategies, and validate remediation through retesting and purple team exercises.
- Implement, tune, and manage security controls and defensive technologies, including firewalls, IDS/IPS, endpoint detection and response (EDR), antivirus, and logging solutions to strengthen organizational defenses against advanced attacks.
- Conduct static application security testing (SAST) and secure code reviews using automated tools such as Veracode and Checkmarx, identifying exploitable weaknesses and insecure coding patterns leveraged during red team simulations.
- Produce detailed technical, executive, and red team reports documenting attack paths, exploited vulnerabilities, business impact, detection gaps, and actionable recommendations; identify web application issues such as XSS, CSRF, session fixation, SQL injection, authentication bypass, information leakage, and logic flaws across multiple platforms.
- Specialize in application-level security and secure coding practices, integrating offensive testing results into the SDLC to improve long-term security maturity.
- Conduct security audits, vulnerability assessments, configuration reviews, and adversary simulations across networks, applications, endpoints, and cloud infrastructure to proactively identify weaknesses.
- Develop and manage offensive security and red teaming projects, ensuring engagements are delivered within scope, timelines, and ethical guidelines while meeting business and regulatory requirements.
- Oversee the selection, deployment, and operation of red team and offensive security tools, ensuring effective coverage across network, application, identity, and cloud attack surfaces.
- Develop and enforce security policies, procedures, and best practices, incorporating insights gained from red team and purple team activities to improve organizational resilience.
- Coordinate and support incident response and purple team exercises, investigate security incidents uncovered during simulations, perform root cause analysis, and deliver post-engagement improvement plans.
- Train and educate technical and non-technical staff on cybersecurity awareness, secure development, and lessons learned from red team engagements, strengthening human-layer defenses.
- Monitor security alerts and detection capabilities during red team operations, evaluate blue team effectiveness, and recommend improvements to monitoring, alerting, and response workflows.
- Stay current with emerging offensive security techniques, adversary tradecraft, zero-day vulnerabilities, and red team tooling, continuously enhancing attack simulation realism.
- Apply and align testing and controls with OWASP Top 10, MITRE ATTCK, NIST, and SANS/CIS Critical Security Controls.
- Demonstrate strong working knowledge of the ISO 27001 framework, including risk assessment, control implementation, and audit readiness.
- Maintain hands-on experience with enterprise firewall technologies such as Check Point, Sophos, and Fortinet, supporting both defensive architecture and red team bypass testing.
- Designed and enforced data protection controls by configuring DLP policies tailored to business use cases; conducted validation testing to identify weaknesses, evasion techniques,
and control gaps during security verification exercises.
- Applied recognized cybersecurity frameworks and benchmarks including OWASP Top 10, NIST guidelines, and SANS/CIS security controls to guide assessment methodologies and remediation strategies.
- Analyzed cryptographic components within applications, focusing on key derivation mechanisms; identified design and implementation weaknesses and produced structured vulnerability assessments with severity ratings and mitigation recommendations.
- Conducted grey-box security testing of web applications, combining limited system knowledge with dynamic testing techniques to uncover exploitable flaws and logic errors.
- Documented technical findings in formal security assessment reports, highlighting attack vectors, risk impact, and corrective actions; discovered vulnerabilities such as XSS, CSRF, session handling issues, injection flaws, data exposure, and business logic weaknesses.
- Executed static application security assessments using commercial analysis platforms to detect insecure coding practices and architectural weaknesses prior to production deployment.
- Assessed vulnerability intelligence feeds and scan outputs, correlating results to determine relevance, exploitability, and risk prioritization for remediation planning.
- Performed application and infrastructure security testing using automated scanners and manual tools including Nmap, directory enumeration utilities, Qualys Guard, Nessus, and HCL AppScan.
- Maintained the confidentiality, integrity, and availability of organizational IT environments by administering access controls, user permissions, backup processes, and recovery mechanisms.
- Supported and secured Active Directory environments, managing replication, trust relationships, and identity-related configurations across multi-domain infrastructures.
- Delivered web application-focused VAPT engagements, assessing authentication, authorization, session management, and input validation controls.
- Executed control-level and infrastructure security assessments covering hardware devices, servers, and network components to identify misconfigurations and exposure points.
- Contributed to security audits, incident handling activities, and penetration testing engagements, supporting both preventive security and post-incident analysis.
- Defined and reviewed information security policies, technology standards, and operational procedures to ensure secure and compliant business operations.
- Hands-on expertise in identifying and exploiting web and application-layer attack vectors, including SQL and XML injections, command execution techniques, PDF-based exploits, HTTP response splitting, CSRF, and vulnerabilities affecting web services and APIs.
- Conducted web application and infrastructure penetration testing using industry-standard tools such as Burp Suite, Acunetix, Nmap, DirBuster, Nessus, and SQLmap, combining automated scanning with manual validation techniques.
- Reviewed application source code and architecture against OWASP Top 10, NIST, and SANS/CIS guidelines, identifying security weaknesses such as cross-site scripting, injection flaws, privilege escalation, and insecure access controls, and provided actionable remediation guidance.
- Proactively discovered and analyzed system and network vulnerabilities using Nessus Security Center and passive vulnerability scanning techniques to minimize attack surface and reduce the likelihood
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Cybersecurity Lead (Gurugram)
🏢 Trigyn Technologies
📍 Gurugram