Live opening · Posted 5 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Hiring: Lead Security Engineer – AppSec, VAPT & Security Tools
Location: Noida, Uttar Pradesh
Experience: 5–8 Years
About the Role
We are looking for a hands-on Lead Security Engineer to strengthen our organisation’s technical security capabilities across Application Security, VAPT, Security Tools, Cloud & Infrastructure Security, Vulnerability Management and DevSecOps.
The role will work closely with Engineering, DevOps, Cloud, IT Infrastructure, Product and Compliance teams to identify security risks, embed security across the technology lifecycle and drive remediation to closure.
Key Responsibilities
Security Tools & Technology
Own implementation, configuration, integration and operations of enterprise security tools.
Work across SIEM, EDR/XDR, WAF, SAST, DAST, SCA, API Security, CSPM, IAM/PAM, DLP and Email/Web/Network Security.
Evaluate new security technologies and conduct POCs.
Integrate security tools with ticketing, DevOps, Cloud and incident-management platforms.
Build dashboards covering security alerts, vulnerabilities, coverage and remediation.
Coordinate with OEMs and security partners for implementation, troubleshooting and upgrades.
Application Security & DevSecOps
Establish and operate a Secure Software Development Lifecycle (SSDLC).
Conduct or facilitate Threat Modelling, Architecture Reviews, Secure Code Reviews, SAST/DAST, Dependency Scanning and API/Mobile Security Assessments.
Integrate security controls into CI/CD pipelines and drive DevSecOps practices.
Partner with developers to analyse vulnerabilities, recommend fixes and validate remediation.
Address risks related to open-source components, third-party libraries and exposed secrets.
Promote OWASP Top 10, OWASP API Security Top 10 and secure-coding practices.
VAPT & Vulnerability Management
Plan and manage periodic VAPT across applications, APIs, mobile apps, cloud, servers and network infrastructure.
Review VAPT findings, validate vulnerabilities and eliminate false positives.
Manage vulnerability remediation and track findings against agreed SLAs.
Coordinate retesting and maintain an organisation-wide vulnerability register.
Escalate overdue critical/high-risk vulnerabilities.
Support penetration testing, red-team exercises and security configuration reviews.
Cloud & Infrastructure Security
Assess security configurations across Azure, AWS, GCP, networks, servers, databases and containers.
Review IAM, privileged access, firewall rules, encryption, logging and exposed services.
Establish security baselines and identify configuration deviations.
Work with Cloud and DevOps teams to implement preventive and detective controls.
Monitor internet-facing assets, certificates, domains and externally exposed services.
Security Monitoring & Incident Response
Develop security-monitoring use cases and alerting rules.
Analyse security alerts and support incident investigations.
Assist with containment, evidence collection, root-cause analysis and corrective actions.
Develop and maintain incident-response playbooks.
Support incident-response simulations and tabletop exercises.
Governance, Risk & Compliance
Support ISO 27001, SOC 2, client audits and regulatory assessments.
Provide technical evidence and ensure security controls are documented and tested.
Support application, infrastructure and third-party technology risk assessments.
Track and close audit, VAPT and security observations.
Required Experience & Skills
5–8 years of relevant cybersecurity experience with strong exposure to Security Engineering and Application Security.
Hands-on experience with multiple enterprise security tools.
Strong knowledge of Web, Mobile and API Security Testing.
Experience managing VAPT engagements and vulnerability-remediation programmes.
Understanding of AWS, Azure or Google Cloud security.
Good understanding of application architecture, networks, operating systems, databases and authentication.
Experience working with Engineering, DevOps and Infrastructure teams.
Knowledge of CI/CD, Containers and modern software-development practices.
Working knowledge of OWASP, CVSS, MITRE ATT&CK and CIS Benchmarks.
Familiarity with ISO 27001, SOC 2 and risk-management principles.
Bachelor's degree in Computer Science, IT, Cybersecurity or a related discipline.
Preferred Certifications
OSCP | eWPT | CEH | CSSLP | CASE | CISSP | CISM | Security+ | AWS/Azure/GCP Security | ISO 27001
Certifications are desirable but will not substitute for strong hands-on experience.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.