Lead Engineer - Cyber / Cloud Security
We are seeking a motivated Cyber Security Lead Engineer with 4+ years of experience to strengthen our security initiatives. The role involves working across application, cloud, infrastructure, and DevSecOps environments, with exposure to LLM and agentic security use cases, while contributing to threat detection, incident response, and security best practices across the organization.
3 - 5 years
-B.Tech/B.E in Computers , -B.Tech/B.E in IT
Conduct penetration testing, vulnerability assessments, and overall security reviews across applications, infrastructure, and cloud environments.
Identify and exploit vulnerabilities, simulate real-world attacks, and provide remediation guidance.
Perform risk assessments, threat modeling, and security posture reviews with clear recommendations.
Integrate security into SDLC, CI/CD pipelines, and Infrastructure-as-Code environments using tools like SAST/DAST/IAST.
Collaborate with engineering, infra, and DevOps teams to build a security-first culture and improve secure design and deployment practices.
Develop and maintain security testing plans, methodologies, and automation.
Monitor systems and cloud environments using SIEM and other tools to detect and respond to threats and incidents.
Stay updated with emerging vulnerabilities, threat landscapes, and security best practices.
Appliction security , Penetration Testing , OWASP Top 10 , Cloud Security , Vulnerability Management
Must have Skills:
Strong understanding of Application Security concepts (OWASP Top 10, SAST, DAST, API Security).
Experience with Cloud Security (AWS/Azure/GCP security services, IAM, networking security).
Knowledge of mobile security testing (OWASP MASVS, tools like MobSF, Frida, Drozer).
Strong expertise in penetration testing and end-to-end vulnerability management lifecycle, including assessment, remediation, and reporting
Proficiency in scripting languages (Python, Bash, or PowerShell) for automation.
Good to Have Skills:
Security certifications (CEH, Security+, OSCP, or equivalent).
Strong knowledge of network protocols, firewalls, and intrusion detection/prevention systems.
Understanding of LLM security and agentic AI security
Hands-on exposure to DevSecOps tools (e.g., SonarQube, Snyk, Trivy, Checkov, GitHub/GitLab security features).
Familiarity with threat hunting methodologies and tools (YARA).