HamburgerMenu
hirist

Job Description

Location : Hyderabad (Hybrid/On-site)


Experience : 6+ Years


Department : DevsecOps/ Secruity


Employment Type : Full-time

Job description :

We are seeking a talented Security Engineer to join our team. The ideal candidate should have a strong background in production security, DevSecOps, and extensive experience with SDLC practices and multiple security tools, including but not limited to Qualys, Black Duck, and JFrog X-ray. As a Security Engineer, you will be responsible for ensuring robust security practices and implementing cutting-edge security measures to protect our systems and data.

Key Responsibilities :

Vulnerability Management :

- Own end-to-end vulnerability lifecycle for a given Business Unit consisting of multiple enterprise level products. (SaaS & on-prem).

- Triage, track, Correlate and remediate vulnerabilities from tools like Black Duck, Prisma Cloud, Qualys, Jfrog Xray etc. Understanding the working of these tools and mapping in a common tool.

- Co-ordinate with business security leads to plan patching strategies and risk mitigation.

Security Automation :

- Integrate security scanning tools into common tools.

- In progress and SLA tracking for all the vulnerabilities and work closely with respective business units.

- Develop dashboards and reports for compliance and leadership visibility.


- Write high level design to automate a few of the manual work.

Collaboration & Governance :

- Work cross-functionally with product teams, and stakeholders.

- Contribute to security policies, standards, and best practices.

- Participate in incident response and post-mortem analysis.

Education & Awareness :

- Publish security advisories on high-priority vulnerabilities (CVEs).

- Helping Junior team members on security aspects.

- Kubernetes, container build pipeline, and repository platform knowledge is a plus.


- Familiarity with vulnerability scoring models like CVSS,EPSS,BDSA

Key Technologies :

- Security Tools : Black Duck, Prisma Cloud, Qualys, Snyk, Coverity, SonarQube, Burpsuite

- DevOps Stack : Jenkins, Kubernetes, Helm, Docker

- Programming : Python, Shell, YAML, JSON (Good to have)

- Cloud Platforms : AWS, GCP (Understanding basics of Cloud)

Success Metrics :

- Reduction in high/critical vulnerabilities within SLA by working with security champion


- Increasing automation for doing mundane tasks

- Cross-team security engagement and support effectiveness

- Strong communication skills.

info-icon

Did you find something suspicious?