For infosec engineer. Security Assessments & Assurance
- Perform Vulnerability Assessments (VA) and coordinate Penetration Testing (VAPT) activities for applications, infrastructure, cloud environments, and endpoints.
- Conduct configuration reviews against industry benchmarks such as CIS standards.
- Review security controls for current applications, systems, and technology implementations.
- Validate remediation of security findings and track closure with stakeholders.
Vulnerability Management
- Manage the end-to-end vulnerability management lifecycle.
- Analyze security findings from internal and external scans.
- Prioritize vulnerabilities based on risk and business impact.
- Track remediation timelines and report overdue findings.
Security Reviews
- Conduct application security reviews and secure architecture assessments.
- Participate in threat modeling exercises.
- Review security requirements for cloud and SaaS deployments.
- Provide recommendations for secure design and implementation
Required Skills & Qualifications Experience
- 3–6 years of experience in Information Security, Cyber Security, Application Security, or Vulnerability Management.
Technical Skills
- Strong understanding of:
- Network Security
- Web Application Security
- Cloud Security (AWS / Azure / GCP)
- Authentication & Access Management
- Security Architecture Principles
- Hands-on experience with:
- Vulnerability Assessment tools (Qualys, Nessus, Tenable, Rapid7)
- Web Application Security tools (Burp Suite, OWASP ZAP)
- Security review methodologies
- Security configuration standards (CIS Benchmarks)
- Familiarity with:
- SIEM platforms
- EDR/XDR solutions
- DLP technologies
- WAF and network security controls
Security Knowledge
- OWASP Top 10
- MITRE ATT&CK; Framework
- NIST Cybersecurity Framework
- Security Testing Methodologies
- Secure SDLC Concepts
📌 Engineer - InfoSec (Mumbai)
🏢 Crisil
📍 Mumbai