IT security Engineer at Yext · Hyderabad · 5 - 10 years · ₹5L - ₹15L / yr (ESOP available) · Profitable · Posted 25 May 2022

Responsibilities:
The Senior Information Security Engineer is responsible for the implementation, execution and maintenance of technology solutions to mitigate risk, to protect the IT and Engineering environments by reducing the probability of, and to minimize the effects of, damage caused by malware, malicious activities and security events.
The individual will help protect the company by deploying, tuning, and managing security tools across the computing environment, as well as provide security incident response cycle support. They should have a passion and skills for identifying the latest cyber threats. The individual will:
Basic Qualifications
- Working knowledge of infrastructure-as-code and CI/CD pipelines tools (i.e. Jenkins, Teamcity, CircleCI etc..)
- Lead and participate in major day-to-day operational aspects of the security engineering team including improvement of current security controls while constantly identifying areas of needed improvement
- Deep hands-on security experience with cloud providers, such as AWS, GCP, Azure
- Understanding of automated security testing approaches and tools
- Experience with proactive integration of security into the development process
- Lead continuous improvement efforts of out security tools and systems (Concertation on SIEM, IDS, EDR Tools)
- Work with our customers (Security Operations, Incident Response, and Product teams) to incorporate high quality security alerting into their operational workflows
- Improve overall security practitioner efficiency through process automation
- Foster and promote collaboration among all members of the IT, Infrastructure, and Risk Management Departments.
Minimum Qualifications/Requirements
- BS or MS in Computer Science or related field
- Minimum 7+ years of cybersecurity experience
- Must have previous experience performing threat hunting and incident response duties using SIEM tools, cybersecurity management consoles, and ticketing systems
- Experience in deployment, development, and maintenance of SIEM
- Experience writing and using Ansible server administration scripts, and create simple Python, BASH, or Powershell scripts to automate cybersecurity functions
- Scripting experience to automate security operations, alerting, and compliance checks, CI/CD design, deployment, and management
- Experience with managing endpoint response and detection infrastructure and endpoints at the enterprise level, including performing upgrades to the back end application and deploying new agent versions to endpoints
- Understanding the investigative process and performing triage for cybersecurity incidents
- Experience maintaining industry leading security technologies or infrastructure systems in complex technical IT operations environment
- Must be detail-oriented and organized with ability to handle competing demands while meeting deadlines
- Experience in authentication protocols and frameworks to include OAuth, and AWS IAM
- Proactive and motivated; team player with a positive can-do attitude
- Strong analytical/problem-solving skills and cross-functional knowledge across multiple IT operational and security disciplines
- Ability to communicate technical concepts to a broad range of technical and non-technical staff
- Must possess a high degree of integrity, be trustworthy, and have the ability to lead and inspire change

About Yext
About
Connect with the team
Similar jobs (9)
About Us
CLOUDSUFI is a Silicon Valley-based specialist Data Engineering & Cloud Technologies player with top-tier clients, favorable revenue mix, strong financial performance, and robust management. We pride ourselves in helping in the Data Discovery, Insights and Monetization for organizations. We offer quality of work, opportunities to learn new platforms/technologies that will help young engineers put themselves ahead in their careers compared to their peers in the IT Services industry. CLOUDSUFI is a Data Science and Product Engineering company building Products/Solutions for Technology and Enterprise industries leveraging the advent of Cloud Hyper Scalers and AI/ML, NLP technologies.
The organization is built to scale with strong external/ internal tech capabilities and governance standards. Started in 2019, CLOUDUSUFI is a family of 250 members working towards a common goal of making the enterprise data dance.
To know more, please visit https://cloudsufi.com
Our Values
We are a passionate and empathetic team that prioritizes human values. Our purpose is to elevate the quality of lives for our family, customers, partners and the community.
Equal Opportunity Statement
CLOUDSUFI is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified candidates receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation and national origin status. We provide equal opportunities in employment, advancement, and all other areas of our workplace. Please explore more at https://www.cloudsufi.com/
Role : Full-Time Individual Contributor (IC)
Reporting to : Solution Architect / Program Manager
Location : India Remote (Quarterly visits to Noida office)
Shift : 2PM-11PM IST
12x5 (On call duty)
Experience : 8-14 Years
ABOUT YOU
- 5+ years’ experience with AWS orchestration via Terraform script
- 5+ years’ experience with CloudWatch/CloudTrail/Guard Duty
- 5+ years’ experience with AWS WAF
- 4+ years’ experience with CloudFlare
- 3+ years’ experience with DataDog
- Experience with PagerDuty
- Ability to make nuanced threat assessments
- Experience in SOPHOS.
- Significant experience with PCI, SOC2, SOX, HIPAA, or other compliance regimes
- Experience in Infrastructure As Code – Ansible / Terraform/ CloudFormation
- Hands-on experience implementing various security tools in CI/CD pipeline
- Strong experience with any cloud service provider (AWS Preferred)
- Implement and oversee technological upgrades, improvements and major changes to the cloud security environment.
- Develop solutions, install/configure/integrate IT tools and security processes within an application or organization to help improve the overall IT security posture.
- Set up Static and Dynamic Code Analysis tools, review the results and explain any gaps and potential impact to the teams (development and operations).
- Penetration testing and container security.
- Evaluate and analyze threat, vulnerability, impact and risk to security issues discovered from security assessments.
- Assess current technology architecture for vulnerabilities, weaknesses and for possible upgrades or improvement
- Creating and managing security strategies
- Oversee information security audits, whether performed by organization or third-party personnel
- Develop, maintain and publish up-to-date information security policies, standards and guidelines.
- Preferred Certification - AWS Security/CISSP/CISM (Certified Information Security Manager)
ABOUT THE ROLE
- Work independently with vendors and collaborate with colleagues
- Experience negotiating remediation timelines and/or remediate found issues independently
- Ability to implement vendor platforms within CI/CD pipelines
- Experience managing/responding to incidents, collecting evidence, and making decisions.
- Working with vendors and HM Teams to deploy criteria within WAF and fine tuning it according to applications’ needs
- Multitasking and continuous ability to provide a high level of concentration for assigned projects.
- Good working knowledge of AWS security in general and familiarity of the AWS native security tools
- The candidate should be experienced and articulate, who is not going to get discouraged, despite meeting roadblocks, and will continue promoting security within the company.
- Ability to create DevSecOps security requirements while working on a project
- Ability to articulate security requirements during the Architecture meetings and working hand in hand with HM Applications and DevOps Principal Engineers
Role Overview
We are looking for an experienced Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure. The role requires a strong understanding of network security principles, hands-on experience with security technologies, and the ability to troubleshoot complex network and security issues.
The ideal candidate will work closely with network, infrastructure, cloud, application, and security teams to ensure secure, resilient, and highly available network environments. The candidate should be comfortable handling security incidents, performing root-cause analysis, implementing security controls, and contributing to continuous improvement of the organization's network security posture.
Key Responsibilities
- Design, implement, configure, and maintain enterprise network security infrastructure.
- Manage and support network security technologies including firewalls, VPNs, IDS/IPS, secure gateways, and network access controls.
- Configure and maintain security policies, access rules, NAT, VPN tunnels, and related network security controls.
- Monitor network traffic and security events to identify potential threats, anomalies, and unauthorized access.
- Troubleshoot complex network connectivity and security-related issues and perform root-cause analysis.
- Investigate and respond to network security incidents in coordination with security and infrastructure teams.
- Review firewall and network security rules regularly and ensure they follow established security standards and business requirements.
- Support secure connectivity across data centers, corporate networks, remote locations, cloud environments, and third-party networks.
- Participate in network security assessments, vulnerability remediation, and security hardening activities.
- Implement and maintain network segmentation and access-control mechanisms.
- Work with internal teams to assess security requirements for new applications, infrastructure, and network changes.
- Participate in change management, implementation, and post-change validation activities.
- Maintain network security documentation, architecture diagrams, configurations, and operational procedures.
- Contribute to security improvement initiatives, automation, standardization, and operational efficiency.
- Work with vendors and technology partners for issue resolution, upgrades, and technical escalations.
- Ensure network security operations align with organizational policies, industry standards, and compliance requirements.
Required Skills
- Strong experience in network security engineering and enterprise networking.
- Good understanding of TCP/IP, DNS, DHCP, HTTP/HTTPS, routing, switching, VLANs, and network protocols.
- Hands-on experience with enterprise firewalls and security gateways.
- Strong understanding of VPN technologies, IPsec, SSL/TLS, NAT, and access-control policies.
- Experience with IDS/IPS, network monitoring, traffic analysis, and security event investigation.
- Experience troubleshooting network and security issues across complex environments.
- Good understanding of network security architecture, segmentation, and secure connectivity.
- Experience with incident management, change management, and root-cause analysis.
- Familiarity with security best practices, vulnerability management, and network hardening.
- Strong analytical, troubleshooting, and problem-solving skills.
- Good written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
Preferred Skills
- Experience with security technologies from vendors such as Palo Alto, Fortinet, Cisco, Check Point, or similar.
- Exposure to cloud networking and cloud security across AWS, Azure, or GCP.
- Knowledge of Zero Trust, SASE, SD-WAN, or network access control concepts.
- Experience with security monitoring/SIEM platforms.
- Exposure to scripting or automation using Python, PowerShell, or similar technologies.
- Relevant certifications such as CCNA/CCNP Security, PCNSE, Fortinet certifications, or equivalent are an advantage.
Key Competencies
- Network Security Engineering
- Enterprise Network Troubleshooting
- Firewall & VPN Management
- Security Incident Handling
- Network Monitoring & Analysis
- Security Hardening
- Root-Cause Analysis
- Risk & Vulnerability Awareness
- Change & Configuration Management
- Stakeholder Communication
- Problem Solving
- Documentation & Process Discipline
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Cybersecurity Engineer – AI Training Project
About the Opportunity
We’re looking for experienced Cybersecurity Engineers to contribute technical expertise to a customer project focused on improving the capabilities of next-generation AI systems.
In this role, you’ll use your real-world experience in cybersecurity, software engineering, vulnerability assessment, and secure development to create high-quality technical inputs that help AI systems better understand, debug, secure, and reason about complex software.
What You’ll Do
- Analyze, debug, and resolve software bugs, vulnerabilities, and security issues across complex codebases.
- Review source code and identify potential security weaknesses, vulnerabilities, and attack vectors.
- Perform security assessments, vulnerability assessments, penetration testing, and codebase audits.
- Develop and modify software using languages such as Python, Java, Rust, Go, C++, or TypeScript.
- Implement new features and fix existing functionality while maintaining strong security and engineering standards.
- Refactor legacy code to improve security, maintainability, reliability, and performance.
- Work on backend systems and help optimize applications for scalability, performance, and security.
- Analyze real-world security scenarios and translate your expertise into high-quality technical examples and problem-solving tasks.
- Document technical findings, vulnerabilities, debugging approaches, and recommended solutions.
- Provide domain expertise that helps improve how AI systems reason about software engineering and cybersecurity problems.
What We’re Looking For
- Strong professional experience in Cybersecurity / Application Security / Product Security / DevSecOps / Penetration Testing / Vulnerability Management.
- Strong programming experience in one or more of:
- Python
- Java
- Rust
- Go
- C++
- TypeScript
- Proven experience with debugging, troubleshooting, and fixing complex software issues.
- Hands-on experience with penetration testing, vulnerability assessment, security auditing, or application security.
- Understanding of secure software development practices and modern security threats.
- Strong knowledge of data structures, algorithms, software architecture, and code quality.
- Ability to review unfamiliar codebases and quickly understand how systems work.
- Strong written communication and the ability to explain complex technical findings clearly.
Nice to Have
- Experience with OWASP, API security, cloud security, DevSecOps, or threat modeling.
- Experience performing security assessments on production applications or enterprise systems.
- Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, SAST/DAST tools, or vulnerability scanners.
- Contributions to open-source security or software projects.
- Experience working with AI/ML systems, LLMs, data annotation, or AI training projects.
- Relevant security certifications such as OSCP, OSWE, CEH, CISSP, Security+, or equivalent practical experience.
Engagement
- Role: Cybersecurity Engineer
- Work: Remote(Contract)
- Experience: Mid-level to Senior
- Programming: Required
- Cybersecurity expertise: Required
Why Join?
This is an opportunity to apply your existing cybersecurity expertise to an emerging area of technology. Your practical experience debugging software, identifying vulnerabilities, securing applications, and solving complex engineering problems will directly contribute to improving the capabilities of next-generation AI systems.
If you enjoy breaking down complex technical problems, finding vulnerabilities, fixing software, and thinking deeply about how systems work, this project could be a strong fit.
IT Systems Engineer
Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure
Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership
Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at
scale.
The Mission
About Metadome.ai
Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the
Metaverse Standards Forum and the VR/AR Association.
About the Role
We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.
This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.
Core Responsibilities
● Identity & Access Management — JumpCloud:
○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.
○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.
○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.
○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.
○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.
● Google Workspace Administration — GWS:
○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.
○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,
and sharing / visibility policies.○
○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.
Endpoint & Threat Protection — Sophos:
○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and
servers.
○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.
○ Maintain endpoint encryption, web / application control, and device-hardening standards.
○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.
Network, Firewall & Wi-Fi:
○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.
○ Administer enterprise Wi-Fi and wired networks (switches, access points), including
RADIUS-backed authentication.
○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.
○ Implement network monitoring, intrusion detection, and centralized logging.
Hardware, Software & Asset Management:
○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and
decommissioning.
○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.
○ Maintain an accurate hardware and software inventory and asset register.
○ Manage software deployment, patch management, and license compliance.
Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:
○ Operate and continuously improve the company's Information Security Management System
(ISMS).
○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control
implementation, evidence collection, and continuous monitoring.
○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA
assessments.
○ Serve as a primary point of contact during external audits and customer security reviews.
○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response
runbooks.
○ Drive security-awareness and phishing-simulation programs across the organization.
IT Operations & Support:
○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.
○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.
○ Manage backups, disaster recovery, and business-continuity testing.
○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within
budget.
○ Maintain documentation, runbooks, and standard operating procedures.
○ Own and report on the IT budget and asset allocation.
Required Skills & Experience
● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems
below rather than purely supervisory exposure.
● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.
● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.
● Sophos — hands-on endpoint / XDR administration and threat response.
● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.
● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one
full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.
Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.
System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.
Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.
Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.
Preferred Qualifications
●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.
●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.
●Scripting and automation for IT operations (Bash, PowerShell, or Python).
●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.
●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.
Why Join Us
You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running
flawlessly.
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.
KEY RESPONSIBILITIES
All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.
- Performs daily health checks as documented by the IT Security team.
- Supports the Security team by documenting and performing support tasks.
- Participates in change management, incident management, audit and business continuity processes.
- Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
- Participates in internal and external compliance (SOC 2) audits.
- Recommends security enhancements.
Job specifics:
- Familiarity with standard security concepts, practices and procedures.
- Knowledge of Windows operating systems.
- Strong Documentation, communication skills and attention to detail.
- Able to work independently and as a part of a team to deliver completed projects on-time.
- Identifies ways to continuously improve own and/or company performance.
- Knowledge of security toolsets
- Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
- Knowledge of database security.
- Knowledge of SIEM technology and security event correlation and monitoring.
- Experience with AWS.
- Proficient with computer software including Salesforce
EDUCATION & EXPERIENCE
- Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
- Minimum of 3 years of hands-on IT Security & Audit experience.
- Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.











