Lead cyber security (Chennai Metropolitan Area)

Lead cyber security (Chennai Metropolitan Area)

08 Sep
|
JobCrexa
|
Chennai Metropolitan Area

08 Sep

JobCrexa

Chennai Metropolitan Area

As a Senior Application & Cloud Security Engineer (IC3), you will take end-to-end technical ownership of our application security posture across Web, Mobile (i OS/Android), and Cloud (AWS) environments. You will be responsible for threat modeling, conducting deep-dive vulnerability assessments (VAPT), embedding automated security gates into CI/CD pipelines, engineering advanced AWS WAF custom rules & perimeter defenses, and leveraging Observability/SIEM platforms for proactive threat detection and incident monitoring.

Key Responsibilities & Core Scope

Web &

• Mobile Application Security (App Sec) Web Application Security: Conduct comprehensive manual and automated vulnerability assessments (VAPT) across web platforms and microservice APIs based on OWASP Top 10 and OWASP API Security Top 10.

Mobile Application

Security (i OS &

• Android): Perform static and dynamic security assessments aligned with OWASP Mobile Application Security (MASVS) — auditing secure data storage, certificate pinning, biometric authentication, deep linking, reverse-engineering resistance, and third-party SDK security. Secure SDLC &

- Dev Sec Ops Automation: Integrate, tune, and scale SAST, DAST, and SCA tools (e.g., Semgrep, Checkmarx, Veracode, Snyk, Sonar Qube, OWASP ZAP, Burp Suite) inside Git Hub Actions / Git Lab CI pipelines with minimal developer friction.

Threat Modeling: Lead collaborative threat modeling sessions (STRIDE / MITRE ATT&

- CK) with developers and architects during sprint planning and architectural design phases.

Vulnerability Remediation: Work directly with product engineering teams to provide code-level remediation guidance, root-cause analysis, and verification testing.

AWS Security Hardening: Architect and maintain hardened AWS multi-account structures (AWS Organizations, Control Tower, SCPs)



aligned with CIS AWS Foundations Benchmarks. IAM &

- Secrets Management: Design least-privilege IAM policies, role-based access controls, automated credential rotation, and secure key management via AWS KMS and Secrets Manager. Container &
- Kubernetes Security: Enforce runtime protection, image scanning, and network policies for Docker containers and Kubernetes (EKS/ECS) workloads. Infrastructure as Code (Ia C) Security: Automate Terraform security auditing using tools such as Checkov, tfsec, and Trivy before deployments hit production.

Perimeter

Defense &

• WAF Customization AWS WAF Engineering: Architect, deploy, and fine-tune AWS WAF and Amazon Cloud Front security configurations across all edge endpoints.

Custom Rule Development: Write custom regex rules, rate-limiting policies, IP set filtering, and bot control rules to mitigate Layer 7 DDo S, credential stuffing, scraping, and zero-day vulnerabilities.

Security Observability Platforms: Monitor security telemetry across platforms such as Elastic/Open Search, AWS Cloud Watch, or Coralogix.

Threat

Detection &

• Alerting: Aggregate and correlate security logs (VPC Flow Logs, Cloud Trail, ALB logs, WAF logs, Guard Duty findings) to build high-fidelity detection rules and actionable alert dashboards.

Incident Response Support: Assist in triaging security events, performing log forensics,



and automating alert escalations to reduce Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR).

Compliance Alignment: Provide technical evidence and enforce controls for SOC 2 Type II, ISO 27001, and CIS Benchmarks. Tooling &

- Cost Efficiency: Optimize security tool utilization, eliminate redundancy, and identify cloud architecture cost savings.

Mandatory Qualifications (Must-Haves) Experience: 6–9 years in Application Security, Cloud Security, and Dev Sec Ops.

App Sec Mastery: In-depth knowledge of Web & Mobile (Android/i OS) security testing, API penetration testing, and secure code review.

AWS Cloud Security: Hands-on experience securing AWS services (IAM, VPC, KMS, Guard Duty, Security Hub, S3, EKS/ECS). WAF & Edge Defense: Proven experience configuring AWS WAF / Cloud Front, including authoring custom WAF rules, rate limiting, and bot protection.

Observability Experience: Practical experience querying and setting up alerts in modern observability/SIEM tools (e.g., Datadog, Splunk, ELK, Cloud Watch, Sumo Logic).

CI/CD Integration: Experience automating SAST/DAST/SCA scanners inside CI/CD pipelines (Git Hub Actions, Git Lab, Jenkins).

Threat Modeling: Solid track record using STRIDE and MITRE ATT& CK frameworks for architecture reviews.

Bonus / Good-to-Have (Optional) Certifications: Relevant offensive/security certifications: OSCP, AWS Certified Security – Specialty, e WPTX, CEH, or CISSP. Emerging Tech: Experience or research in AI/LLM Security (OWASP LLM Top 10, Prompt Injection defense, RAG security). Prior experience managing, administering, or launching a Responsible Disclosure Program (VDP) or Bug Bounty program (e.g., Hacker One, Bugcrowd, or internal security policy) is a robust added advantage.

📌 Lead cyber security (Chennai Metropolitan Area)
🏢 JobCrexa
📍 Chennai Metropolitan Area

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: lead cyber security (chennai metropolitan area) / chennai metropolitan area

Subscribe to this job alert:

Get the latest job offers by email for: lead cyber security (chennai metropolitan area) / chennai metropolitan area