Role & responsibilities
- Implement and monitor application, API, infrastructure, and cloud security controls.
- Conduct VAPT, security testing, code reviews, and threat assessments.
- Ensure compliance with CERT-In guidelines, OWASP standards, and relevant cybersecurity frameworks.
- Monitor security logs, alerts, and incidents, and coordinate remediation activities.
- Support IAM, RBAC, data protection, and access control initiatives.
- Prepare risk assessments, audit reports, security documentation, and mitigation plans.
- Work with DevOps teams to secure CI/CD pipelines, Kubernetes clusters, containers, and cloud environments.
- Implement encryption standards, secure configurations, and network security controls.
- Support internal/external audits and compliance certification activities.
- Promote secure coding practices and security awareness across teams.
Preferred candidate profile
- Bachelors degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field.
- Solid understanding of Application Security, API Security, and OWASP Top 10.
- Experience in VAPT, penetration testing, security reviews, and risk assessments.
- Knowledge of CERT-In guidelines and cybersecurity compliance requirements.
- Familiarity with SIEM tools such as ELK/EFK, Splunk, Grafana, or Wazuh.
- Understanding of IAM, RBAC, OAuth 2.0, JWT, SSO, and encryption standards.
- Experience securing cloud environments (AWS, Azure, GCP, or Government Cloud) and DevOps pipelines.
- Knowledge of firewalls, IDS/IPS, VPNs, WAF, and network security concepts.
- Strong analytical, documentation, and communication skills.
📌 Security & Compliance Expert (New Delhi)
🏢 EY
📍 New Delhi