04 Oct
|
CMS Computers
|
Delhi
04 Oct
CMS Computers
Delhi
Walk - In Drive at New Delhi location - Security Expert (Cyber security)
Security Expert
Qualification
- B.E./B.Tech./MCA or equivalent qualification.
Experience
- 7+ years of overall experience in the IT industry, with at least 3+ years of relevant experience in Information/Cyber Security.
- Experience in at least 2 projects for Central Government, State Government or PSU organizations.
- Relevant industry-recognized security certifications such as CISSP, CISM, CEH, CCSP or equivalent preferred.
Key Responsibilities
- Define and implement security architecture and controls for the iPIE application, APIs, cloud infrastructure, databases and external integrations.
- Implement and manage security controls covering IAM, RBAC, SSO, authentication, authorization and privileged access.
- Work with Keycloak/SSO, API Gateway, WAF, firewalls, IDS/IPS, SSL/TLS and secure proxy technologies.
- Coordinate Vulnerability Assessment and Penetration Testing (VAPT), security audits, remediation and security hardening.
- Assess application and infrastructure vulnerabilities and ensure timely remediation of identified security risks.
- Define security controls for REST APIs, microservices, web/mobile applications and third-party integrations.
- Ensure appropriate encryption, key management, secrets management, secure communication and data protection mechanisms.
- Support security monitoring, logging, incident detection and integration with SIEM/SOC and other security monitoring tools.
- Review security aspects of cloud infrastructure, containers, databases, DevSecOps pipelines and deployment environments.
- Ensure appropriate security controls for sensitive case, stakeholder, financial, compliance and document-related information handled by iPIE.
- Support development and maintenance of security policies, standards, procedures,
threat models and security documentation.
- Ensure compliance with applicable Government of India security guidelines, CERT-In requirements, data protection requirements and project-specific security policies.
- Coordinate with development, infrastructure, cloud, application and external integration teams to address security requirements throughout the SDLC.
- Conduct security architecture reviews, threat modeling and security risk assessments across applications, APIs, infrastructure and integrations.
- Support security incident response, investigation, remediation and compliance/audit activities.
Technical Skills
- Network Security: Firewall, IDS/IPS, WAF, VPN, Secure Proxy and SSL/TLS.
- Application Security: OWASP, API Security, Secure SDLC, SAST/DAST and VAPT.
- Identity & Access Management: SSO, OAuth 2.0, OpenID Connect, JWT, RBAC and Keycloak.
- Cloud Security: Cloud IAM, encryption, secrets management, security groups/network controls and security monitoring across cloud or Government Cloud environments.
- Security Monitoring: SIEM, SOC, audit logging, vulnerability management and incident response.
- Container/Kubernetes Security: Kubernetes RBAC, network policies, pod security, container security and image vulnerability scanning.
- DevSecOps: Security automation and integration of security controls into CI/CD pipelines, including dependency/SCA scanning, secrets detection and infrastructure-as-code security.
- Software Supply Chain Security: SBOM, dependency vulnerability management and secure software supply-chain practices.
Preferred Experience
- Experience in large-scale Government/PSU platforms involving multiple stakeholders, external system integrations, sensitive data, document management and regulatory/compliance workflows.
Interested candidate can walk - in direct to CMS office in Recent Delhi Location Contact person - Apoorva Iyer
📌 Walk-in || Security Expert (Delhi)
🏢 CMS Computers
📍 Delhi