Cutshort logo
NIST Jobs in Bangalore (Bengaluru)

11+ NIST Jobs in Bangalore (Bengaluru) | NIST Job openings in Bangalore (Bengaluru)

Apply to 11+ NIST Jobs in Bangalore (Bengaluru) on CutShort.io. Explore the latest NIST Job opportunities across top companies like Google, Amazon & Adobe.

icon
HappyFox

at HappyFox

1 video
6 products
Lindsey A
Posted by Lindsey A
Chennai, Bengaluru (Bangalore)
5 - 12 yrs
₹10L - ₹15L / yr
IT security
Network Security
OWASP
Threat modeling
Exploratory testing
+4 more

About us:

HappyFox is a software-as-a-service (SaaS) support platform. We offer an enterprise-grade help desk ticketing system and intuitively designed live chat software.

 

We serve over 12,000 companies in 70+ countries. HappyFox is used by companies that span across education, media, e-commerce, retail, information technology, manufacturing, non-profit, government and many other verticals that have an internal or external support function.

 

To know more, Visit! - https://www.happyfox.com/

 

Responsibilities:

  • Perform manual and automated application penetration tests and provide suggestions to harden our products
  • Participate regularly in the development and release process to identify and report security vulnerabilities in the code being shipped
  • Conduct regular audits on all Features/APIs of the product and reports vulnerabilities to the development team
  • Keep up with industry trends in the security space
  • Triage inbound vulnerability reports with an appropriate level of urgency and track them until they are resolved by Engineering teams
  • Should be able to understand different elements of our NodeJS, Python and similar stacks and provide guidance on secure software development practices to the team
  • Scale our application security engineering team

 

Requirements:

  • Strong verbal and written communication skills
  • Has worked on Web Application Security Testing for a reasonably complex application. The mobile experience is a plus
  • Good knowledge of secure software development guidelines from authoritative bodies like NIST, OWASP, SANS
  • Hands-on experience in performing manual/automated security assessments with open-source/commercial security tools

 

Read more
Shipsy

at Shipsy

4 candid answers
1 video
Reshika Mendiratta
Posted by Reshika Mendiratta
Bengaluru (Bangalore)
8yrs+
Upto ₹70L / yr (Varies
)
Cyber Security
skill iconAmazon Web Services (AWS)
OWASP
Security Information and Event Management (SIEM)
Security operations
+2 more

About Shipsy


At Shipsy, we aim to revolutionize the logistics and supply chain industry through our innovative SaaS platform. We leverage cutting-edge technology to deliver solutions that enhance efficiency, improve sustainability, and create positive impacts across global supply chains.


Position Overview

We are seeking a skilled Security Operations Engineer to join our security operations team. This role is crucial for protecting our company’s assets, data, and IT infrastructure. The ideal candidate will possess a solid foundation in cybersecurity, experience with incident response, full stack development experience and a proven ability to work effectively within a team environment.


Key Responsibilities:

  • Work with the product, devops, and development teams to identify the right security architecture for implementing new solutions, products, and features. Help develop, implement, and support product security strategy.
  • Work closely with product management, engineering, and DevOps teams to implement, identify, and embed cybersecurity in a secure connected architecture. Deliver general security concepts in the software development lifecycle (Identity and Access Management, encryption, web application security, security logging, pen-testing processes, etc. ).
  • Support security initiatives and serve as a point of contact to build and securely scale cloud platforms (EX. AWS, GCP & AZURE).
  • Manage program risks through effective identification, mitigation, tracking, and reporting of the identified risks.
  • Present strategies, project plans, and more to cross-functional teams delivering risk management solutions that add value.
  • Experience in introducing security testing into software delivery pipelines (CI/CD)
  • Understanding of secure and defensive coding principles, especially OWASP top 10 or similar guidance frameworks
  • Understanding of cloud-native applications and how to deploy them securely
  • Create design specifications and prepare technical documentation and run-books.
  • Support the development of standards by creating templates and patterns for ease of use and increase the productivity of the security program


Requirements:

  • 8 years of industry experience with at least 4 years experience in DevSecOps automation and tooling. 
  • Proven experience with Amazon Web Services (AWS), including IAM, AWS Shield, AWS WAF (Web Application Firewall), and Amazon Inspector to enhance security measures and compliance within the cloud environment.
  • Expertise in security tools and technologies, such as vulnerability scanners, penetration testing tools, and security information and event management (SIEM) systems. 
  • Strong understanding of DevSecOps principles and practices. 
  • Excellent communication, collaboration, and problem-solving skills. 
  • Ability to work independently and as part of a team. 
  • Experience collecting metrics, measuring systems, and interpreting data to make decisions. 


Qualifications

  • Bachelor's degree in Computer Science, a related technical field, certifications, or equivalent practical experience



Good to have:

  1. Experience in JavaScript, Node, React , Python & Database administration.
  2. AWS Management, Security, Scalability, Reliability, Cost Optimization Education and Certifications
  3. AWS Certified Security – Specialty or equivalent practical experience


Read more
HSR Layout , Bangalore
2 - 6 yrs
₹4L - ₹10L / yr
Web application security
Penetration testing
Source Code review

1. Perform security assessment of web applications, Android, iOS mobile applications, Source Code Review

2. In-depth knowledge of security vulnerabilities not just limited to OWASP Top 10

3. False Positive removal and manual application testing      

4. Working exp of Python, Java, .Net etc         
5. Experience of using MF Fortify is a must

6. Proactively identify vulnerabilities and recommend fixes

7. Ownership of the tasks, Adapt to technologies/languages/platforms/frameworks of the time                                                                                     

8. Experience in using security tools to carry out manual as well as automated security assessments

9. Experience working with common product flows like payment gateway integration, authentication etc.                                                          

10. Client handling exp

11. Should be able to address client queries, work on proposals etc                                                        

12. Independent, self-motivated and comfortable working in a fast-paced environment with teams ranging from product to engineering teams

Read more
OYO Rooms

at OYO Rooms

20 recruiters
Shraddha Jhamb
Posted by Shraddha Jhamb
Bengaluru (Bangalore), Delhi, Gurugram, Noida, Ghaziabad, Faridabad, Hyderabad
4 - 6 yrs
₹5L - ₹20L / yr
Penetration testing
skill iconAmazon Web Services (AWS)
Azure
OSCP
LCEH
+1 more

About The Company -

OYO Hotels & Homes is the world’s third largest and fastest-growing chain of leased and franchised hotels, homes & spaces managing over 1 million exclusive rooms across 800 cities and 80 countries. OYO was founded on the mission that everyone deserves a quality living and working space and we are very passionate about this mission. Technology and Innovation plays a critical role in this mission and therefore today we employ World Class engineers, product managers and designers across core markets & geographies. If you are looking for a high pace environment, itching to create a large impact through technology impacting 100s of millions of customers across the globe, we love to hear from you.

 

Key Responsibilities:

 

  • Conducting application(Web & Mobile) and infrastructure penetration testing assessments.
  • Deploy, improve and utilize SAST/DAST/SCA and other cybersecurity solutions to detect & prevent security vulnerabilities.
  • Work closely with the business, product and Development/engineering teams to provide input and guidance on developing secure products and help teams adopt shift-security-to-left practices.
  • Work closely with the DevOps team to secure the cloud environment.
  • Developing and maintaining cybersecurity process activities including security requirements engineering, threat modelling, code reviews and cyber risk assessment.
  • Improve and automate cybersecurity processes within the CI/CD pipelines.
  • Continuously review and identify security improvement opportunities in existing products, processes, services and workflows to ensure the people, products and technology in the organization are protected against current and future cybersecurity threats.
  • Deliver awareness sessions on Secure Development to engineering/development teams
  • Drive continuous improvement activities to define, measure, visualize and improve key cyber security metrics related to Application Security.
  • Preparing and launching social engineering campaigns;

 

Key Skills:

 

  • Expertise in application(Web & Mobile) and infrastructure penetration testing.
  • Strong experience with Azure or AWS cloud environments and its security controls.
  • Experience with microservices architectures & distributed Platforms
  • Strong experience with using Agile software development and securing CI/CD pipeline.
  • Coding Experience in Scripting & programming languages (such as Terraform, Java, Python, Ruby, etc.)
  • Knowledge of how modern web & mobile apps are designed, developed and deployed across different platforms;
  • Knowledge of common exploitation techniques and mitigations.
  • Experience in implementing and managing a vulnerability management program (process and technology).
  • Experience and knowledge of implementing a DevSecOps ecosystem and strong understanding of Dynamic and Static Application Security Testing (DAST & SAST).
  • Understanding of the main cybersecurity tools (SIEM, IPS, XDR, etc.).
  • Strong understanding of OWASP, PTES and other penetration testing methodologies.
  • Understanding of global security frameworks and standards like NIST, ISO 27001, GDPR, PCI etc.
  • Strong knowledge in preparing and launching social engineering campaigns.
  • Ability to program or script in your preferred language
  • Good understanding of network and OS principles
  • Strong written and spoken English skills and ability to write high-quality reports
  • An Information Security qualification e.g CSSLP, CEH, OSCP, or similar certification

 

Cultural Traits common to all OYO Leaders -

 

● Dealing with Ambiguity and Adaptability – we are a large, but fast-growing company today with not enough existing process or rules of engagements; and environment changes rapidly due to new businesses, geographies and strategic partnerships etc. You need to be able to create organization out of chaos, operate in an environment with minimal structure and adapt to change quickly while maintaining high velocity

● Ownership – anything between you and your job is also your job

● Bias for Action – speed matters a lot, so does quality. Ideal leader will be pragmatic, action-oriented and know the right balance between competing priorities

● Hunger to change the world – you need to be ambitious and willing to do more. If you believe you have already achieved your best and primarily looking to impart that vast knowledge, we aren’t the right place for you

 

Job Locations: We have a Pan India presence with Tech centers based out of Gurugram, Bangalore & Hyderabad. However currently we are working from our home.

 

Read more
technoforte software pvt. ltd.
Hema Chandwani
Posted by Hema Chandwani
Bengaluru (Bangalore)
5 - 8 yrs
₹9L - ₹15L / yr
Shell Scripting
Cyber Security
Endpoint protection
Web application security
Information security
+1 more

Desired Skills

To have skills:

·       Proven technical expertise in cyber security domains, i.e. endpoint security, application security testing.

·       Knowledge and experience in public cloud solutions.

·       Knowledge on network security, networking concepts and architectural implementations.

·       Knowledge on vulnerability testing and define proper remediation’s.
Experience with application, database, and infrastructure security.

·       Shell scripting experience - Shell/Bash/Python.

·       Working experience of Linux operation.

 

Desire to have skills:

·       One or more of the following cyber security certifications: CEH, CISSP, OSCP, SSCP  CCSP.

·       Excellent problem solving, and follow-up skills.

·       Ability to convey technical security concepts to non-technical audiences.

Read more
Olacabs.com

at Olacabs.com

6 recruiters
Agency job
via zyoin by RAKESH RANJAN
Bengaluru (Bangalore)
8 - 12 yrs
₹18L - ₹30L / yr
Web application security
Mobile security
Infrastructure
Roles and Responsibilities 
    • Manage a team of highly skilled security engineers
    • Responsible for the security of all Ola applications. 
    • Enforce Security in SDLC,  and ensure any identified vulnerabilities are fixed before a feature goes to production.
    • Participate in the design review discussions to identify any security loophole, and recommend a secure design solution. 
    • Partner with engineering leaders across the company to help them prioritize security issues in their products.
    • Run the Ola’s Bug Bounty program effectively. 
    • Develop a roadmap for future work to enhance security, derive a project plan, and ensure the completion of the project within the timelines. 
    • Mentor the team members and work towards their career growth. 

     

    Minimum Qualifications

    • 7+ years of work experience in security engineering, including 2+ years of proven hands-on technical management experience of security engineers. 
    • Experience recruiting and managing technical teams, including performance management.
    • Technical experience across security disciplines – web/mobile app security, infrastructure security, security operations center. 
    • Experience building relationships with stakeholders and business leaders.
    • Must have Coding experience at least in one language.
    • Knowledge of standards like PCI-DSS, ISO27001, GDPR etc. 

     

    BS/MS in Computer Science or equivalent experience

Read more
Bengaluru (Bangalore)
6 - 8 yrs
₹40L - ₹50L / yr
Penetration Testing
Security Assessment
Vulnerability management
Penetration testing
Vulnerability Management
  • Manage security tools(Snyk, Fossa, Trivy).
  • Manage vulnerability programs. Triage vulnerabilities, assign priorities and owners, follow up on the mitigation 
  • Monitor license violations.  
  • Perform Security Assessments and Threat Modeling
  • Security Incident Response. Be part of a security-on-call team in PagerDuty, act as incident commander, perform Root Cause Analysis.
  • Drive security initiatives(Web Application Security, Least-privilege principle, Secrets Management, Key Management, PKI and Certificate Management, Anti-fraud protection).
  • Given our fast pace and startup nature, things change over time and your job responsibilities will too.

You'll need:

  • Web application security experience.
  • Familiarity with a modern SaaS infrastructure and application development.
  • Manual and/or automated Penetration Testing (white box, black box & grey box).
  • Good understanding of security risk(OWASP Top 10).
  • Pen-testing: burp suite/ postman, etc.
  • Vulnerability management: Snyk, fossa, NexusIQ, WhiteHat security, aqua security, GitHub security, etc.
  • Familiarity with major security protocols.
  • Collaboration, transparency, and integrity.
  • BS/MS degree; 5+ years of relevant experience.

Nice to have:

  • Experience in scripting languages(BASH, Python, JS, etc).
  • CEH, CSSLP, GIAC, OSCP, OSCE, or other related industry-recognized certifications.
  •  
Read more
Bengaluru (Bangalore)
3 - 7 yrs
₹5L - ₹15L / yr
Network Security
Web application security
Cyber Security
Description :

We are looking for candidates with the below experience.

- Mandatory experience on any of

a) Cylance Protect and Optics

b) Crowdstrike Falcon Insight

c) Sentinel One ActiveEDR

d) Carbon Black EDR

- Hands-on experience in security incident response lifecycle and its phases

- Should have experience in L1 and L2 in EDR

- Hands-on experience in event and log analysis on Windows endpoints

- Overall experience: 3-7 years, Relevant experience: 2+ years

Please note : Candidate should have experience in the below skills must :

- EDR Experience

- EDR Product Worked on and which level of support they are working on

- Incident Response

- Malware Analysis

- Flexible for shifts
Read more
Hyderabad, Pune, Bengaluru (Bangalore)
10 - 16 yrs
₹15L - ₹30L / yr
Network Security
Security
Web application security
skill iconJava
skill iconPython
- 10+ Years of experience in a technical position helping enterprise customers.

- 5+ Years of leading an engagement.

- 5+ Years developing and implementing security operations and technology in large, complex enterprises in multiple industry verticals, across a wide range of technology platforms.

- 4+ Years on any Cloud Platform (AWS, Azure, Google, others).

- Master's or Bachelor's degree in Information Science / Information Technology, Computer Science.

- Deep hands-on experience leading the design, development and deployment of business software at scale.

- Experience with service-oriented architectures, private and public clouds and web services security.

- Strong skills in security principles such as least privilege access, defense in depth, preventative vs detective controls, Infrastructure and Network Security, Data protection, and Incident response.

- Professional experience and good technical knowledge of application security, system security, network security, authentication/authorization protocols, and cryptography.

- Experience advising customers on architectures meeting industry standards such as PCI DSS, ISO 27xxx, SOC, HIPAA, GDPR, and NIST/DoD frameworks.

- Experience with enterprise risk management methods and techniques to drive successful outcomes in a global enterprise environment.

- Good understanding of Enterprise Networks, Security and Identity Access Management.

- Configuration management using CloudFormation and/or Chef/Puppet.

- Experience with agile approaches and Experience in DevOps or DevSecOps, and how they impact risk management and compliance.

- Hands-on technical expertise in technology automation, implementation, integration, and/or deployment using scripting and/or IaaC.

- Knowledge of professional software engineering practices & best practices for the full software development life cycle, including coding standards, code reviews, source control management, libraries building, build processes, testing, and operations.

- Demonstrated ability to mentor other software developers to maintain architectural vision and software quality.

- Experience taking a lead role developing complex software systems that have successfully been delivered to customers.

- Ability to travel to customer sites as needed.

PREFERRED QUALIFICATIONS:

- AWS Solutions Architect Certified.

- AWS Security Speciality Certified.

- CISSP, CCSP, CISM, and/or other comparable certifications.
Read more
Swiggy

at Swiggy

1 video
13 recruiters
Suresh Kaushik
Posted by Suresh Kaushik
Bengaluru (Bangalore)
3 - 12 yrs
₹25L - ₹60L / yr
Network Security
Penetration testing
skill iconProgramming
Security architecture
Computer Security
+2 more
Job Description Roles and Responsibilities: • Exploit security flaws and vulnerabilities with attack simulations on multiple application platforms like Android, iOS and Web. • Ability to flow from black box to grey box to white box tests. • Ability to effectively work with the engineering teams to provide technical risk. assessment of technologies in networks, applications, code reviews in the release management cycle. • Ability to perform vulnerability assessments and penetration testing, utilizing tools - commercial and open source. • Perform, review and analyze security vulnerability data to identify applicability and false-positives. • Conduct penetration testing in line with Open Web Application Security Project (OWASP) • Write technical reports that include suggested resolution for identified problem areas and perform operational risk assessment. Required Skills and Abilities: • OWASP top 10 • Security Pen Testing methodologies including automated scans and manual methods • Tools including Burp, Nexpose, NMap, Whois etc. is a plus • Good Hands-On with Linux Debian Flavors and security hardening of the same • Understanding of Web Servers and HTTP 1.0/1.1 Protocol • Troubleshooting web servers like Apache, Nginx and other reverse proxy platforms • Basic understanding of NodeJS, Python and JAVA • TCP/IP networking including IP classes, subnets, NAT • SSL Handshake and Certificates - Understanding • DNS, and DHCP, Network troubleshooting • Remote access methods • Backup and disaster recovery methodologies • Network analysis tools • Good Hands-on using Linux Debian Flavors • Experience with security issues in Cloud Technologies (AWS) is a plus • Ability to grasp new technology concepts quickly • Good documentation skills • Ability to work in a team environment and interact with people • Knowledge and understanding of basic information security principles • Should be aware of the latest Major Application Zero-day vulnerabilities • Should be able to understand security alerts and take necessary actions accordingly Education and Experience: • Bachelor’s degree in information technology related field
Read more
AMBC Technologies Pvt Ltd
Ponmuthumari Mohan
Posted by Ponmuthumari Mohan
Bengaluru (Bangalore)
3 - 9 yrs
₹8L - ₹12L / yr
Web application security
oscp
vapt
Fortify
OWASP

Requirements:

  • Overall experience in the field of Information risk and security related initiatives/ projects.
  • Experience in the areas of Infrastructure Security Audit, IT Security, Vulnerability Assessment, Risk Assessment, Web Application Security, Network Security Review, Network Architecture Review, Mobile Application Security Testing, Configuration Review, Source Code Review, Wireless Pentest, Process Review etc.
  • Ability to understand business concepts and integrate business risk elements into security operations.
  • Experience in conducting VAPT.
  • Experience with web application vulnerability scanning tools (e.g., IBM AppScan, HP Web inspect, Acunetix, NTO Spider, BurpSuite Pro).
  • Strong ethics and understanding of ethics in business and information security.
  • Should have exposure to Code review, Network VA/PT and App VA/PT work.
  • Understanding and familiarity with common code review methods and standards.
  • Experience with code scanning toolsets such as Fortify and Ounce.
  • Understanding of HTTP and web programming.
  • Knowledge of OWASP tools and methodologies, common security requirements within ASP.NET application, standard SDLC practices.
  • Knowledge of Network Security technology in areas of Firewall, IPS, VPN, Gateway security solutions (proxy, web filtering).
  • In-depth understanding on Common Vulnerability Exposure (CVE)/ Cert advisory database.
Read more
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Why apply via Cutshort?
Connect with actual hiring teams and get their fast response. No spam.
Find more jobs
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort