02 Sep
|
IRIS KPO Resourcing
|
Chennai
02 Sep
IRIS KPO Resourcing
Chennai
Hello Eveyone,
I am writing this Job Post to brief about the job opportunity with IRIS KPO Resourcing Pvt Ltd (IRIS Software Group) for Senior information security Engineer - Vulnerability Management
Please find the and specifications for your references,
Please share your interest for the job opportunity with your updated resume.
Shift timing : UK Business Hours (2:00 PM - 11:00 PM IST)
Web Link : https://www.iris.co.uk/
LinkedIN : https://www.linkedin.com/company/iris-outsourcing-and-
global-product-development-centre/posts/?feedView=all
Location : Remote (Work From Home)
Employment Type : Full-Time | Permanent
Desired Candidature:
You bring a strong technical background in application security, vulnerability management or software engineering, with a transparent understanding of how vulnerabilities arise and how they should be remediated. Practical experience with security tooling such as SAST, DAST, SCA and secrets scanning matters here, ideally integrated into modern CI/CD environments. Just as valuable is the judgement to assess vulnerabilities in context, weighing exploitability, internet exposure, asset criticality, available exploits and compensating controls rather than taking scanner output at face value.
You are also comfortable with software supply chain security, including frameworks such as SLSA, dependency security and secure build pipelines.
Your background includes a solid grounding in public cloud security, particularly across AWS and/or Azure. You recognise the vulnerabilities that recur in cloud environments, from overly permissive identities and exposed services to insecure storage, vulnerable workloads and configuration drift.
What you will do
- Own the end-to-end vulnerability management lifecycle across our products and supporting technology, from identification and validation through prioritisation, remediation tracking, risk acceptance and reporting.
- Triage and validate findings from multiple sources, including SAST, DAST, SCA, secrets scanning, penetration testing and web application scanning.
- Work closely with Engineering and Product teams to drive remediation of vulnerabilities, helping teams understand technical risk, agree appropriate remediation actions and meet defined remediation timelines.
- Partner with teams responsible for integrating security tooling into our CI/CD pipelines, helping improve the quality, coverage and effectiveness of that tooling.
- Develop and continuously improve risk-based vulnerability prioritisation, considering exploitability, asset exposure, business criticality, threat intelligence and compensating controls rather than relying solely on scanner severity.
- Identify recurring vulnerability patterns and root causes, working with engineering teams to reduce systemic weaknesses rather than repeatedly fixing individual findings.
- Continuously improve vulnerability management processes, dashboards and workflows, bringing strong technical ownership and ideas for making the programme more scalable and effective.
- Support the security review of software supply chain risks, including dependency management, build pipeline security and relevant secure software development practices.
- Review and validate findings from cloud security and CSPM platforms, helping Infrastructure and Engineering teams prioritise and remediate cloud vulnerabilities and configuration weaknesses.
- Research emerging cloud threats, vulnerabilities and misconfiguration patterns and recommend appropriate mitigations.
- Support the implementation and improvement of cloud security controls and security baselines where required.
What we expect from a candidate:
- Strong communication skills.
- Strong hands-on experience in Application Security and Vulnerability Management.
- A good technical understanding of vulnerabilities and not just experience raising tickets or sending remediation emails.
- Ideally a software development / engineering background, or at minimum enough coding knowledge to understand how vulnerabilities arise and discuss remediation options with developers.
- Experience with tools and findings from SAST, DAST, SCA, secrets scanning, penetration testing and GitHub security tooling.
- The ability to validate and prioritise vulnerabilities for engineering teams, challenge false positives, understand exploitability and help teams decide what genuinely needs fixing first.
- Some exposure to cloud security / CSPM, ideally AWS or Azure, would be a strong advantage.
- Experience in financial services, payroll, fintech, SaaS or a software/product development company would be particularly relevant and wll be an added advantage.
📌 Senior information security Engineer - Vulnerability Management (Chennai)
🏢 IRIS KPO Resourcing
📍 Chennai