Live opening · Posted 2 days ago

Lead Cyber Security

SuperOps · Chennai, Tamil Nadu, India (On-site)
Linkedin No
You are 2 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 2 days ago
CompanySuperOps
LocationChennai, Tamil Nadu, India (On-site)
Work modeNo
SourceLinkedin
Listed2 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
11 min from Linkedin publishing this role to us finding it
13 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
33,810 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

As a Senior Application & Cloud Security Engineer (IC3), you will take end-to-end technical ownership of our application security posture across Web, Mobile (iOS/Android), and Cloud (AWS) environments. You will be responsible for threat modeling, conducting deep-dive vulnerability assessments (VAPT), embedding automated security gates into CI/CD pipelines, engineering advanced AWS WAF custom rules & perimeter defenses, and leveraging Observability/SIEM platforms for proactive threat detection and incident monitoring.
Key Responsibilities & Core Scope
Web & Mobile Application Security (AppSec)
Web Application Security: Conduct comprehensive manual and automated vulnerability assessments (VAPT) across web platforms and microservice APIs based on OWASP Top 10 and OWASP API Security Top 10.
Mobile Application Security (iOS & Android): Perform static and dynamic security assessments aligned with OWASP Mobile Application Security (MASVS) — auditing secure data storage, certificate pinning, biometric authentication, deep linking, reverse-engineering resistance, and third-party SDK security.
Secure SDLC & DevSecOps Automation: Integrate, tune, and scale SAST, DAST, and SCA tools (e.g., Semgrep, Checkmarx, Veracode, Snyk, SonarQube, OWASP ZAP, Burp Suite) inside GitHub Actions / GitLab CI pipelines with minimal developer friction.
Threat Modeling: Lead collaborative threat modeling sessions (STRIDE / MITRE ATT&CK) with developers and architects during sprint planning and architectural design phases.
Vulnerability Remediation: Work directly with product engineering teams to provide code-level remediation guidance, root-cause analysis, and verification testing.
AWS Security Hardening: Architect and maintain hardened AWS multi-account structures (AWS Organizations, Control Tower, SCPs) aligned with CIS AWS Foundations Benchmarks.
IAM & Secrets Management: Design least-privilege IAM policies, role-based access controls, automated credential rotation, and secure key management via AWS KMS and Secrets Manager.
Container & Kubernetes Security: Enforce runtime protection, image scanning, and network policies for Docker containers and Kubernetes (EKS/ECS) workloads.
Infrastructure as Code (IaC) Security: Automate Terraform security auditing using tools such as Checkov, tfsec, and Trivy before deployments hit production.
Perimeter Defense & WAF Customization
AWS WAF Engineering: Architect, deploy, and fine-tune AWS WAF and Amazon CloudFront security configurations across all edge endpoints.
Custom Rule Development: Write custom regex rules, rate-limiting policies, IP set filtering, and bot control rules to mitigate Layer 7 DDoS, credential stuffing, scraping, and zero-day vulnerabilities.
Security Observability Platforms: Monitor security telemetry across platforms such as Elastic/OpenSearch, AWS CloudWatch, or Coralogix.
Threat Detection & Alerting: Aggregate and correlate security logs (VPC Flow Logs, CloudTrail, ALB logs, WAF logs, GuardDuty findings) to build high-fidelity detection rules and actionable alert dashboards.
Incident Response Support: Assist in triaging security events, performing log forensics, and automating alert escalations to reduce Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR).
Compliance Alignment: Provide technical evidence and enforce controls for SOC 2 Type II, ISO 27001, and CIS Benchmarks.
Tooling & Cost Efficiency: Optimize security tool utilization, eliminate redundancy, and identify cloud architecture cost savings.
Mandatory Qualifications (Must-Haves):
Experience: 6–9 years in Application Security, Cloud Security, and DevSecOps.
AppSec Mastery: In-depth knowledge of Web & Mobile (Android/iOS) security testing, API penetration testing, and secure code review.
AWS Cloud Security: Hands-on experience securing AWS services (IAM, VPC, KMS, GuardDuty, Security Hub, S3, EKS/ECS).
WAF & Edge Defense: Proven experience configuring AWS WAF / CloudFront, including authoring custom WAF rules, rate limiting, and bot protection.
Observability Experience: Practical experience querying and setting up alerts in modern observability/SIEM tools (e.g., Datadog, Splunk, ELK, CloudWatch, Sumo Logic).
CI/CD Integration: Experience automating SAST/DAST/SCA scanners inside CI/CD pipelines (GitHub Actions, GitLab, Jenkins).
Threat Modeling: Solid track record using STRIDE and MITRE ATT&CK frameworks for architecture reviews.
Bonus / Good-to-Have (Optional):
Certifications: Relevant offensive/security certifications: OSCP, AWS Certified Security – Specialty, eWPTX, CEH, or CISSP.
Emerging Tech: Experience or research in AI/LLM Security (OWASP LLM Top 10, Prompt Injection defense, RAG security).
Prior experience managing, administering, or launching a Responsible Disclosure Program (VDP) or Bug Bounty program (e.g., HackerOne, Bugcrowd, or internal security policy) is a strong added advantage.

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App