Live opening · Posted 5 days ago

Security Engineer

Hamly Business Solutions India Private Limited · Thanjavur, Tamil Nadu, India (On-site)
Linkedin No
You are 5 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 5 days ago
CompanyHamly Business Solutions India Private Limited
LocationThanjavur, Tamil Nadu, India (On-site)
Work modeNo
SourceLinkedin
Listed5 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
17 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,790 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Security Engineer – Application & Cloud Security
Location: Thanjavur, Tamil Nadu
Experience: 3–6 Years
Employment Type: Full-time
Work Mode: Work from Office
Job Summary
We are looking for a Security Engineer with strong hands-on experience in Application Security, Web and API Penetration Testing, Secure Code Review, and AWS Security.
The candidate will be responsible for identifying and addressing security vulnerabilities across applications, APIs, cloud infrastructure, and development processes. The role will also involve working closely with engineering, product, and QA teams to ensure security is considered throughout the software development lifecycle.
This is an Application and Cloud Security role and does not involve SOC monitoring or rotational shifts.
Key Responsibilities
Application and API Security
* Perform Web Application and API Penetration Testing.
* Identify vulnerabilities related to authentication, authorization, IDOR, injection, session management, and business logic.
* Apply OWASP Top 10 and OWASP API Security Top 10 principles in security testing.
* Test multi-tenant application security, RBAC, and access controls.
* Document security findings with severity, impact, reproduction steps, and recommended remediation.
Secure Code Review
* Conduct security-focused code reviews for applications.
* Review Java/Spring Boot and JavaScript/Node.js applications for security vulnerabilities.
* Identify authorization issues and other application-level security weaknesses.
* Participate in security reviews before application releases.
Cloud and Infrastructure Security
* Review and strengthen the organization's AWS security configuration.
* Work with AWS IAM, VPC, Security Groups, S3, KMS, and CloudTrail.
* Ensure appropriate access controls, encryption, and secrets management.
* Define security logging and support incident response activities.
Security Automation and DevSecOps
* Integrate SAST, DAST, and SCA tools into CI/CD pipelines.
* Review software dependencies and identify relevant security vulnerabilities.
* Develop scripts and automation using Python or Bash.
* Build repeatable security processes and tools to improve security testing.
Collaboration and Security Governance
* Work closely with Product, Engineering, and QA teams.
* Support security during product development and release planning.
* Establish and maintain security standards and procedures.
* Maintain security documentation and evidence required for customers and audits.
* Communicate security findings and release decisions to engineering leadership.
Required Qualifications and Skills
* 3+ years of experience in engineering, with at least 2 years of hands-on Application Security experience.
* Strong experience in Web Application and API Penetration Testing.
* Good understanding of OWASP Top 10 and OWASP API Security Top 10.
* Professional experience with Burp Suite or OWASP ZAP.
* Experience with Secure Code Review.
* Ability to review Java or JavaScript/Node.js code from a security perspective.
* Practical knowledge of AWS security, including IAM, VPC, S3, KMS, and CloudTrail.
* Working knowledge of Python or Bash scripting.
* Good understanding of Linux and Git.
* Strong written and verbal communication skills.
* B.E./B.Tech qualification.
Preferred Qualifications
* Experience with SAST, DAST, and SCA in CI/CD.
* Knowledge of Threat Modelling.
* Experience with PostgreSQL Row-Level Security and audit logging.
* Certifications such as OSCP, eJPT, eWPTX, AWS Security Specialty, CEH, or equivalent.
* Experience with PHI, HIPAA, SOC 2, or ISO 27001.
* Experience with API testing tools such as Postman or REST Assured.
* Knowledge of load testing tools such as k6 or JMeter.
* Exposure to Azure Security, Terraform, or CloudFormation.
Ideal Candidate
The ideal candidate will have strong practical experience in Application Security and Web/API Penetration Testing, along with a good understanding of secure software development and AWS security.
Candidates with experience limited to SOC monitoring, network administration, or firewall management without hands-on Application Security experience may not be suitable for this position.
Application
Interested candidates can share their updated CV along with a redacted vulnerability assessment report or security write-up, if available.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App