Security Engineer (Thanjavur)

Security Engineer (Thanjavur)

24 Sep
|
Hamly Business Solutions India Private
|
Thanjavur

24 Sep

Hamly Business Solutions India Private

Thanjavur

Security Engineer – Application & Cloud Security

Location: Thanjavur, Tamil Nadu

Experience: 3–6 Years

Employment Type: Full time

Work Mode: Work from Office

Job Summary

We are looking for a Security Engineer with strong hands-on experience in Application Security, Web and API Penetration Testing, Secure Code Review, and AWS Security.

The candidate will be responsible for identifying and addressing security vulnerabilities across applications, APIs, cloud infrastructure, and development processes. The role will also involve working closely with engineering, product, and QA teams to ensure security is considered throughout the software development lifecycle.

This is an Application and Cloud Security role and does not involve SOC monitoring or rotational shifts.

Key Responsibilities

Application and API Security

Perform Web Application and API Penetration Testing.

Identify vulnerabilities related to authentication, authorization, IDOR, injection, session management, and business logic.

Apply OWASP Top 10 and OWASP API Security Top 10 principles in security testing.

Test multi-tenant application security, RBAC, and access controls.

Document security findings with severity, impact, reproduction steps, and recommended remediation.

Secure Code Review

Conduct security-focused code reviews for applications.

Review Java/Spring Boot and JavaScript/Node.js applications for security vulnerabilities.

Identify authorization issues and other application-level security weaknesses.

Participate in security reviews before application releases.

Cloud and Infrastructure Security





Review and strengthen the organization's AWS security configuration.

Work with AWS IAM, VPC, Security Groups, S3, KMS, and CloudTrail.

Ensure appropriate access controls, encryption, and secrets management.

Define security logging and support incident response activities.

Security Automation and DevSecOps

Integrate SAST, DAST, and SCA tools into CI/CD pipelines.

Review software dependencies and identify relevant security vulnerabilities.

Develop scripts and automation using Python or Bash.

Build repeatable security processes and tools to improve security testing.

Collaboration and Security Governance

Work closely with Product, Engineering, and QA teams.

Support security during product development and release planning.

Establish and maintain security standards and procedures.

Maintain security documentation and evidence required for customers and audits.

Communicate security findings and release decisions to engineering leadership.

Required Qualifications and Skills

3+ years of experience in engineering, with at least 2 years of hands-on Application Security experience.

Strong experience in Web Application and API Penetration Testing.





Good understanding of OWASP Top 10 and OWASP API Security Top 10.

Professional experience with Burp Suite or OWASP ZAP.

Experience with Secure Code Review.

Ability to review Java or JavaScript/Node.js code from a security perspective.

Practical knowledge of AWS security, including IAM, VPC, S3, KMS, and CloudTrail.

Working knowledge of Python or Bash scripting.

Good understanding of Linux and Git.

Strong written and verbal communication skills.

B.E./B.Tech qualification.

Preferred Qualifications

Experience with SAST, DAST, and SCA in CI/CD.

Knowledge of Threat Modelling.

Experience with PostgreSQL Row-Level Security and audit logging.

Certifications such as OSCP, eJPT, eWPTX, AWS Security Specialty, CEH, or equivalent.

Experience with PHI, HIPAA, SOC 2, or ISO 27001.

Experience with API testing tools such as Postman or REST Assured.

Knowledge of load testing tools such as k6 or JMeter.

- Exposure to Azure Security, Terraform, or CloudFormation.

Ideal Candidate The ideal candidate will have strong practical experience in Application Security and Web/API Penetration Testing, along with a good understanding of secure software development and AWS security.

Candidates with experience limited to SOC monitoring, network administration, or firewall management without hands-on Application Security experience may not be suitable for this position.

Application

Interested candidates can share their updated CV along with a redacted vulnerability assessment report or security write-up, if available.

📌 Security Engineer (Thanjavur)
🏢 Hamly Business Solutions India Private
📍 Thanjavur

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (thanjavur) / thanjavur

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (thanjavur) / thanjavur