
Cybersecurity Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in India.
• Execute thorough penetration testing for web applications, APIs, cloud environments, and related infrastructure.
• Facilitate threat modeling sessions for both new and existing products.
• Conduct reviews of secure design and architecture.
• Assess security controls for applications, cloud, and infrastructure, providing actionable recommendations.
• Collaborate with development teams to prioritize, monitor, and resolve security issues.
• Integrate security testing and validation within CI/CD pipelines.
• Create and maintain security tools, scripts, and automation capabilities.
• Incorporate security requirements into the planning, design, development, and deployment phases of products.
• Assist in vulnerability management, including validation, risk assessment, guidance on remediation, and verification of fixes.
• Contribute to the establishment of security standards, secure development guidelines, and product security processes.
• Keep abreast of emerging threats, attack methods, vulnerabilities, and security technologies.
• Offer technical guidance and mentorship to engineering teams.
• Support security audits, compliance initiatives, and collection of evidence.
• Promote continuous enhancement of Product Security and DevSecOps initiatives.
• Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related technical field, or equivalent hands-on experience.
• Over 5 years of experience in Cybersecurity, Application Security, Product Security, Security Engineering, or a related domain.
• Proven experience in conducting both manual and automated penetration testing for web applications, APIs, cloud environments, and associated infrastructure.
• Experience in performing threat modeling and security architecture reviews using frameworks such as STRIDE, PASTA, ATT&CK, or similar.
• Solid understanding of secure software development practices, prevalent attack strategies, OWASP Top 10, and API Security Top 10.
• Ability to identify, validate, and communicate security risks to both technical and non-technical audiences.
• Proficient in one or more programming languages such as Python, Java, JavaScript, C#, PowerShell, Go, or similar.
• Familiarity with Agile development methodologies and the integration of security practices into the Software Development Life Cycle (SDLC).
• Knowledge of DevSecOps principles and the incorporation of security tools into CI/CD processes.
• Strong analytical, problem-solving, communication, and teamwork abilities.
• Capacity to independently lead security initiatives while collaborating with Engineering, Product, Architecture, and Operations teams.
• Experience conducting cloud security assessments in platforms like AWS, Azure, or Google Cloud Platform.
• Familiarity with microservices, APIs, containers, Kubernetes, and serverless computing technologies.
• Knowledge of SAST, DAST, SCA, Container Security, and Infrastructure-as-Code security tools.
• Experience in developing security automation, custom security tools, or pipeline integrations.
• Understanding of secure architecture patterns, identity and access management, cryptography, and zero-trust security concepts.
• Experience in supporting regulatory, compliance, or audit requirements in heavily regulated sectors.
• Possession of security certifications such as OSCP, OSWE, GWAPT, GWEB, CISSP, CCSP, or relevant certifications from Azure, AWS, or GCP.
• Willingness to work during European Shift hours (1pm to 10pm).
• Competitive salary
• Provident fund
• Medical insurance
• Engaging employee programs and local events
• Modern office spaces and flexibility for remote work
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.