05 Oct
|
42Gears
|
Bengaluru
Responsibilities:
● Design and implement security architecture solutions aligned with business requirements and industry best practices.
● Conduct security assessments and vulnerability analysis to identify and remediate gaps in existing infrastructure.
● Develop comprehensive documentation, including threat models and architecture diagrams, to standardize security across the organization.
● Collaborate with cross-functional teams to integrate security controls directly into the software development lifecycle (SDLC).
● Evaluate and pilot emerging security technologies to maintain a proactive defense posture against evolving threats.
● Mentor junior team members and lead security awareness initiatives to foster a culture of collective responsibility.
● Architect secure cloud solutions that ensure continuous compliance with organizational policies and cloud-native best practices.
● Perform cloud hardening by evaluating infrastructure configurations and implementing rigorous security benchmarks.
● Oversee IAM strategies across multi-cloud environments (AWS/GCP) to enforce strict least-privilege access and identity governance.
● Automate security guardrails through Infrastructure as Code (IaC) to ensure consistent security deployment across all environments.
● Design centralized logging and monitoring frameworks to provide the visibility required for effective threat detection and response.
● Integrate SAST, DAST, and SCA tools into CI/CD pipelines to automate the detection of vulnerabilities in custom code and third-party libraries.
● Develop security blueprints for containerized environments (Kubernetes/Docker) covering image signing, pod security, and runtime protection.
● Define Data Loss Prevention (DLP) architectures to monitor and control the movement of sensitive data across cloud and hybrid environments.
● Map technical security controls to regulatory frameworks (SOC2, ISO 27001, GDPR) to ensure the architecture meets audit requirements.
Critical skills/ competencies:
● Security Frameworks: Proficient in NIST CSF, ISO 27001, and SOC2 control mapping.
● Cloud Architecture: Security design knowledge for AWS (EC2, S3, VPC, Lambda, IAM),
Azure (VMs, KMS,Storage, App Services), and GCP (Compute Engine, Cloud Storage,
Identity Management) environments.
● Threat Modeling: Expert in STRIDE/PASTA methodologies and infrastructure risk assessment.
● Identity & Access: Advanced IAM governance, Zero Trust architecture, and JIT access.
● Container Security: Hardening and orchestration security for Docker and Kubernetes.
● DevSecOps: Integrating SAST/DAST/SCA gating into automated CI/CD pipelines.
● Network Security: Implementing micro-segmentation, WAF, and API Security Gateways.
● Data Protection: Centralized secrets management (Vault) and PKI/Encryption standards.
● Security Observability: Architecting SIEM/SOAR telemetry for high-fidelity detection.
● Application Security: Deep knowledge of OWASP Top 10 and secure coding practices.
● Compliance: Technical auditing against FedRAMP, HIPAA,PCI-DSS standards cloud security assessment methodologies.
In addition, preference will be given to candidates who possess any of the following certifications:
● CISSP (Certified Information Systems Security Professional) or similar advanced security certification
● CISM (Certified Information Security Manager) or GIAC Security Essentials (GSEC)
● Cloud architect certifications such as AWS Solutions Architect Professional, Azure Solutions
Architect Expert, or Google Cloud Skilled Cloud Architect.
● Kubernetes security certifications (CKA, CKAD) or cloud-native security certifications.
● Experience with enterprise security frameworks and governance standards (NIST, ISO
27001, SOC 2)
📌 Senior Security Engineer-2 (Bengaluru)
🏢 42Gears
📍 Bengaluru