31 Aug
|
Utthunga
|
Vasanthanagar
31 Aug
Utthunga
Vasanthanagar
Job DescriptionJob Title NSenior Cybersecurity Engineer | NnExperience N4-6 years' Experiencen NJob Description Nnn Strong experience implementing and monitoring IEC 62443-4-1 Secure Development Lifecycle requirements. N Strong understanding ofSecure Development Lifecycle processes, software security assurance, and cybersecurity compliance. N Hands-on experience conducting STRIDE Threat Modelling and secure architecture reviews. N Strong experience performing penetration testing for Web Applications, Mobile Applications, and Thick Client/Desktop Applications. N Strong understanding ofOWASP Top 10, secure coding principles, application security testing methodologies, and common software vulnerabilities. N Strong knowledge of vulnerability assessment, vulnerability management, and industry-standard risk scoring methodologies such as CVSS. N Hands-on experience with application security tools such as Burp Suite, OWASP ZAP, SonarQube, Black Duck, Wireshark, and common Kali Linux security tools. N Positive understanding of software development and secure development practices using one or more technologies such as .NET/C#, Java, Python, or C++. N Strong understanding ofweb technologies, REST APIs, authentication and authorization mechanisms, encryption, secure communications, and networking concepts including HTTP, HTTPS, TCP/IP, and TLS. N Good understanding of security controls such as encryption, secure authentication, secure session management, defense-in-depth, least privilege, and Zero Trust principles. N Experience working in Agile/Scrum development environments with cross-functional software engineering teams. N Experience developing and reviewing security documentation, standards, procedures, and compliance evidence. N Excellent analytical, problem-solving, communication, and stakeholder management skills.
N Ability to mentor junior engineers and promote secure development best practices across project teams. NnnMinimum Qualification Nn Bachelor’s degreein computer science, Information Technology, Electronics, Cybersecurity, or a related Engineering discipline. N 3–5 years of experiencein Application Security/Product Security (preferred over network security). N Qualified cybersecurity certifications such as CEH, CompTIA Security+, CompTIA PenTest+, or equivalent are preferred. NnnRoles & Responsibilities Nnn Drive and monitor Secure Development Lifecycle (SDL) implementation across software development projects in compliance with prescribed cybersecurity standards. N Ensure project compliance with IEC 62443-4-1 Secure Development Lifecycle requirements by creating/maintaining compliance artifacts and client-defined cybersecurity processes. N Contribute to all stages of the Secure Development Lifecycle, including Security Requirements Analysis, Secure Design, Secure Implementation, Security Testing, and Secure Deployment. N Support STRIDE-based Threat Modelling activities for software products and collaborate with architects and development teams to identify and mitigate security risks. N Ensure project teams adhere to secure coding standards by supporting manual code reviews and automated security scanning activities. N Coordinate and analyze Static Application Security Testing (SAST) and Software Composition Analysis (SCA) results using approved security tools, and work with development teams to remediate identified findings.
N Develop security test plans covering penetration testing, security requirements verification, threat validation testing, vulnerability assessment, and regression testing. N Design and maintain comprehensive security test cases and test suites aligned with project requirements and cybersecurity standards. N Perform manual penetration testing of web applications, mobile applications, and thick client applications, validate identified vulnerabilities, and verify remediation effectiveness. N Review, analyze, document, and track security defects through successful closure while ensuring timely reporting and retesting. N Perform vulnerability analysis for internally identified issues, automated scan findings, third-party disclosures, and customer-reported vulnerabilities using industry-standard risk assessment methodologies. N Participate in Agile sprint planning to identify, estimate, and track security-related activities and user stories. N Collaborate closely with software developers, testers, and project teams to embed security throughout the software development lifecycle. N Participate in customerdiscussions and technical reviews to communicate project security posture, compliance status, security risks, and remediation activities. N Represent projects during internal quality audits and external cybersecurity assessments by providing compliance evidence and addressing audit observations. N Conduct security awareness sessions and technical guidance for development teams on secure development practices and emerging security threats. N Continuously stay updated with evolving cybersecurity threats, vulnerabilities, tools, technologies, and industry best practices. NnnMandatory Skills NIEC 62443-4-1, Threat Modeling, Threat Analysis, OWASP Zap, Burp Suite, Sonarqube, Blackduck, WireShark, Kali Linux N
📌 Cyber Security Specialist (Vasanthanagar)
🏢 Utthunga
📍 Vasanthanagar