Cutshort logo
For Employers
vaaragonenterprisescom logo
Manager - Information Security (UK Client)
Manager - Information Security (UK Client)

Manager - Information Security (UK Client) at vaaragonenterprisescom · Gurugram · 8 - 12 years · ₹20L - ₹30L / yr · Bootstrapped · Posted 11 Jun 2026

vaaragonenterprisescom's logo

Manager - Information Security (UK Client)

satish agrawal's profile picture
Posted by satish agrawal
8 - 12 yrs
₹20L - ₹30L / yr
Gurugram
Skills
Information security
GRC
Cyber Security
cloud security
CISM
CISA
CISSP
ISO 27001 LA
ISO/IEC 27001:2005
CyberArk

Position: Manager – Information Security

Experience: 8+ years (with minimum 3 years in leadership roles)

Location: Gurgaon

Qualification: Bachelors in IT/Computer Science; Preferred: MBA, CISSP, CISM, CISA, ISO 27001/27701 Lead Auditor and Lead Implementor


Key Responsibilities:

? Lead the design, implementation, and continuous improvement of the enterprise-wide ISMS and PIMS programs.

? Develop and manage the InfoSec strategy aligned with business goals and regulatory requirements (ISO 27001:2022, ISO 27701:2019, DPDPA, IT Act, CERT-In).

? Oversee security risk assessments, audits, and remediation plans across IT and business units.

? Manage a team of security professionals; mentor, coach, and evaluate performance.

? Collaborate with Legal, Compliance, IT, and Business stakeholders to ensure security by design.

? Lead incident response, RCA, and post-mortem reviews.

? Drive security awareness and training programs across the organization.

? Manage security budgets, vendor relationships, and contract negotiations.


Technical Skills:

? Strong knowledge of IBM QRadar SIEM, GTB DLP, CyberArk PAM, Wiz CNAPP, Sentinel One EDR, Qualys VA and other PT tools.

? Experience in cloud security governance (Preferred on AWS and Azure; Good to have GCP).

? Experience of MITRE ATT&CK, NIST CSF, CIS Controls, OWASP Top 10.




mail updated resume with salary details-

email: etalenthire[at]gmail[dot]com

satish: 88O 27 49 743


website: www.glansolutions.com

Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About vaaragonenterprisescom

Founded :
2023
Type :
Services
Size :
0-20
Stage :
Bootstrapped

About

N/A

Company social profiles

N/A

Similar jobs (10)

company logo
Zeeshan Sheikh
Posted by Zeeshan Sheikh
Kolkata
6 - 10 yrs
₹4L - ₹5L / yr
Cyber Security
Security Information and Event Management (SIEM)
Network Security
Information security management system
Information security

A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.

Key Responsibilities

  • Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Conduct vulnerability assessments, penetration testing, and risk analysis.
  • Monitor and respond to security incidents, ensuring timely resolution and documentation.
  • Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
  • Collaborate with IT and business teams to integrate security into system architecture and processes.
  • Lead incident response drills and disaster recovery planning.
  • Provide guidance and mentorship to junior cybersecurity staff.
  • Stay updated on emerging threats, tools, and technologies.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
  • 5–10 years of proven experience in cybersecurity engineering or related roles.
  • Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
  • Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
  • Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.

Skills

  • Advanced problem-solving and analytical skills.
  • Strong communication and leadership abilities.
  • Ability to manage complex projects and handle escalations effectively.
  • Proactive mindset with adaptability to evolving cyber threats.


Read more
company logo
CyberAlpha ConsultingLLP
Posted by CyberAlpha ConsultingLLP
Noida
2 - 6 yrs
₹3L - ₹6L / yr
GRC
PCI DSS
ISO/IEC 27000-series

Job Summary

We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.


Key Responsibilities

  • Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
  • Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
  • Review policies, procedures, controls, and audit evidence.
  • Identify gaps, risks, observations, and recommend remediation.
  • Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
  • Support clients during certification, surveillance, and external audits.
  • Conduct client meetings, interviews, and control walkthroughs.
  • Coordinate evidence collection and remediation tracking.
  • Develop and review information security policies and procedures.
  • Stay updated with cybersecurity standards, regulations, and best practices.


Required Skills

  • Strong understanding of Information Security, GRC, Risk & Compliance.
  • Good knowledge of ISO 27001:2022 and SOC 2.
  • Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
  • Strong analytical, documentation, communication, and report-writing skills.
  • Ability to independently manage client engagements.


Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
  • 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
  • Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.


Read more
company logo
Ranjith Ammu
Posted by Ranjith Ammu
Hyderabad
7 - 9 yrs
₹20L - ₹30L / yr
Netskope
CASB/SSE
EPM
Mimecast

The role primarily focuses on the administration and operational support of security platforms, with a heavy emphasis on Netskope. 


You will:


  • Administer and optimize security platforms including Netskope (CASB/SSE), CyberArk EPM,  Mimecast, and others​
  • Monitor, analyze, and respond to security events generated by these platforms, ensuring timely triage and resolution​
  • Develop, tune, and maintain security policies (DLP, web controls, email security, endpoint privilege management) to reduce risk and false positives​
  • Lead troubleshooting and root cause analysis for security incidents and platform issues across endpoint, cloud, and email security domains​
  • Collaborate with engineering, IT, and business teams to implement security controls and drive remediation of identified risks​
  • Integrate security tools with ServiceNow for incident management, request workflows, and automated response actions​
  • Build and maintain operational dashboards and reporting for security posture, tool effectiveness, and KPIs​
  • Support onboarding of new applications, users, and use cases into Netskope, Mimecast, and CyberArk EPM​
  • Contribute to security architecture decisions and continuous improvement of tooling and processes​
  • Develop and maintain runbooks, standard operating procedures, and knowledge base documentation 


You bring:

  • Bachelor’s degree or 5+ years of equivalent experience in Cybersecurity or related field​
  • 7+ years of experience in security engineering or security operations roles​
  • Strong hands-on experience with Netskope (CASB/SSE), CyberArk EPM, and Mimecast administration and operations​
  • Experience integrating and operating workflows within ServiceNow (incident, change, and request management)​
  • Solid understanding of endpoint security, DLP, email security, and cloud security concepts​
  • Experience tuning security tools to reduce false positives and improve detection fidelity​
  • Familiarity with identity and access management concepts, including privilege management and least  privilege principles​
  • Ability to analyze security events and translate findings into actionable remediation steps​
  • Strong cross-functional collaboration and communication skills​
  • Experience developing documentation, runbooks, and operational processes​
  • Ability to manage multiple priorities and operate effectively in a fast-paced environment 

 

MUST HAVE: Netskope Subject Matter Expertise (SME) 


  • Netskope expertise is non-negotiable. 
  • Candidates must be capable of serving as effective platform administrators. 
  • Candidates should have a deep understanding of security policies within Netskope. 


Responsibilities 


The successful candidate will: 

  • Support Netskope as the primary platform. 
  • Administer and maintain security controls. 
  • Fine-tune DLP policies. 
  • Investigate access-related platform issues. 
  • Support ticket resolution related to Netskope. 
  • Work with feedback coming from the SOC team. 
  • Manage policy adjustments to reduce false positives. 


Read more
company logo
Yashaswini Bangera
Posted by Yashaswini Bangera
Mumbai
5 - 7 yrs
₹8L - ₹15L / yr
ISO/IEC 27001:2005
Information security governance
Compliance
Risk Management
Stakeholder management

We are seeking an experienced Governance, Risk & Compliance (GRC) Lead to spearhead the

design, implementation, and maintenance of our ISO 27001 Information Security Management

System (ISMS). This is a hands-on leadership role responsible for establishing a robust security

governance framework, achieving ISO 27001 certification, and embedding a culture of

continuous security improvement across the organization.

Key Responsibilities

● ISMS Implementation & Certification: Lead end-to-end ISO 27001 implementation

from gap analysis through to successful Stage 1 and Stage 2 certification audits;

manage external auditor relationships

● Risk Management: Develop and operationalize the information security risk

management framework; conduct risk assessments, treatment planning, and risk

acceptance processes.

● Policy & Governance : Author, approve, and maintain the Statement of Applicability

(SoA), information security policies, standards, and procedures aligned with ISO 27001

Annex A controls.

● Control Implementation: Translate ISO 27001 Annex A controls into operational

security measures; coordinate with IT, Accounts, HR, Backoffice, and business units to

implement and validate controls.

● Compliance Monitoring: Establish continuous monitoring, internal audit programs, and

KPIs/KRIs to measure ISMS effectiveness; manage non-conformities and corrective

actions.

● Third-Party Risk: Oversee vendor security assessments and ensure supply chain

security controls meet organizational and ISO 27001 standards.

● Stakeholder Management: Report ISMS performance, risks, and compliance status to

senior leadership and the board; act as primary liaison for external auditors and

regulators.

Required Qualifications

● 5+ years of experience in information security governance, risk, and compliance

● Proven track record of leading at least one full ISO 27001:2022 certification cycle (gap

analysis → certification)

● Deep expertise in ISO 27001:2022 standard, Annex A controls, and ISMS

documentation requirements

● Strong understanding of risk assessment methodologies (e.g., ISO 27005, NIST RMF,

OCTAVE, FAIR)

● Familiarity with internal audit practices and managing external certification bodies

● Excellent stakeholder management and ability to influence across technical and non-

technical teams

● Strong documentation and communication skills — able to translate complex standards

into actionable guidance

Preferred Qualifications

● Experience implementing ISMS in fintech, healthcare, or regulated industries

● Experience with SOC 2, GDPR, NIST CSF, PCI-DSS, or other compliance frameworks

● Background in cloud security (AWS, Azure, GCP) and DevSecOps environments

● Knowledge of automation for compliance evidence collection and control testing

● Certifications: CISM, CRISC, CISA, ISO 27001 Lead Auditor, or ISO 27001 Lead

Implementer

Why Join Us

● Opportunity to build the security governance function from the ground up

● High-visibility role with direct impact on customer trust and market differentiation

● Collaborative environment that values security as a business enabler, not a blocker

Company Profile:

We are a one-stop financial services shop, widely known for quality of its advice, personalized

service and cutting-edge technology. We started our journey in 2008. Currently we are serving

more than 50,000 investors with a team of 100 members. Our core product offering is mutual

fund, FD, Govt. Bonds, Debenture, etc.



Read more
company logo
Vijayshree Purohit
Posted by Vijayshree Purohit
Mumbai
3 - 5 yrs
₹8L - ₹9L / yr
Comp TIA A+
Microsoft
CCNA
Security+
Network +
+1 more

About Nerve Solutions

Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.

We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.


About the Role

We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.

The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.


Roles & Responsibilities

  • Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
  • Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
  • Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
  • Set up user accounts, systems, and required software for new employees and support onboarding activities.
  • Monitor network performance and employee network activities to ensure system security and compliance.
  • Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
  • Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
  • Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
  • Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
  • Assist in implementing information security best practices, security audits, and compliance initiatives.
  • Coordinate with internal teams to ensure IT services effectively support business operations.
  • Stay updated with the latest cybersecurity threats, technologies, and industry best practices.



Required Skills

  • 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
  • Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
  • Experience troubleshooting hardware, software, network, and user-related issues.
  • Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
  • Experience with Active Directory, user access management, and system administration.
  • Familiarity with Microsoft 365 administration is an added advantage.
  • Understanding of backup, disaster recovery, and IT asset management.
  • Strong analytical and problem-solving skills with attention to detail.
  • Good communication and documentation skills.
  • Ability to work independently and collaboratively in a fast-paced environment.



Preferred Qualifications

  • Bachelor's degree in Information Technology, Computer Science, or a related field.
  • Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.


Read more
company logo
Dubai
4 - 10 yrs
₹25L - ₹39L / yr
ISO/IEC 27001:2005
Web3js

IT Compliance Manager – Web3 & Digital Assets

📍 Location: Dubai, UAE

💼 Employment Type: Full-Time

🏢 Department: Technology / Compliance

📊 Experience: 5+ Years

🌐 Industry: FinTech / Web3 / Digital Assets


About the Role

We are looking for an experienced IT Compliance Manager – Web3 & Digital Assets to lead technology compliance, IT governance, risk management, and cybersecurity controls within a regulated FinTech and digital-asset environment.

The ideal candidate will have strong experience in IT GRC, technology risk, cybersecurity governance, Web3/blockchain, digital assets, and regulatory compliance, with UAE regulatory experience being highly preferred.


Key Responsibilities

  • Manage IT governance, compliance frameworks, policies, procedures, and technology risk assessments.
  • Support compliance with UAE virtual asset and financial-services regulations, including VARA, DFSA, FSRA, and UAE Central Bank requirements, where applicable.
  • Assess technology risks across blockchain infrastructure, crypto wallets, custody, APIs, cloud platforms, databases, smart contracts, and dApps.
  • Review controls related to crypto deposits, withdrawals, transfers, wallet operations, and transaction monitoring.
  • Develop and monitor controls aligned with ISO 27001, SOC 2, NIST, PCI DSS, and relevant regulatory requirements.
  • Coordinate IT audits, regulatory audits, compliance assessments, evidence collection, and remediation activities.
  • Maintain technology risk registers, control assessments, compliance reports, and management dashboards.
  • Partner with Engineering, Product, Security, Legal, Risk, AML/KYC, Finance, and Operations teams.
  • Embed compliance and technology-risk requirements into product development, system changes, and technology architecture.
  • Support regulatory licensing, assessments, and ongoing compliance requirements for digital-asset services.


Requirements

  • Bachelor's degree in IT, Computer Science, Cybersecurity, Finance, Risk Management, or a related discipline.
  • 5+ years of experience in IT Compliance, IT GRC, Technology Risk, Cybersecurity Governance, or a related field.
  • Experience in FinTech, banking, payments, cryptocurrency, blockchain, digital assets, or financial services.
  • Strong understanding of Web3, blockchain networks, crypto wallets, digital-asset transactions, custody, and smart-contract risks.
  • Hands-on experience with IT governance, risk assessments, control testing, audits, and compliance frameworks.
  • Strong knowledge of ISO 27001, SOC 2, NIST, PCI DSS, ITGC, or similar frameworks.
  • Experience working with auditors, regulators, and cross-functional technology teams.
  • Strong analytical, documentation, communication, and stakeholder-management skills.

UAE / Web3 Experience – Preferred

  • Experience with VARA, DFSA, FSRA, UAE Central Bank, or other UAE financial regulators.
  • Experience supporting VASP licensing or regulatory approvals.
  • Previous experience in crypto exchanges, digital-asset platforms, blockchain companies, Web3 startups, or FinTech organizations.
  • Understanding of AML/KYC, transaction monitoring, custody, wallet security, and digital-asset controls.

Preferred Certifications

  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001 Lead Auditor / Lead Implementer
  • CAMS

Key Skills

IT GRC | IT Compliance | Technology Risk | Web3 Governance | Blockchain Risk | Digital Asset Compliance | VASP Licensing | UAE Regulatory Compliance | ITGC | Cybersecurity Governance | ISO 27001 | SOC 2 | NIST | PCI DSS | IT Audit | Risk Assessment | Crypto Transaction Monitoring | Stakeholder Management


Read more
company logo
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
company logo
Priyanka Khandelwal
Posted by Priyanka Khandelwal
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Jaipur
5 - 10 yrs
₹7L - ₹10L / yr
ISO/IEC 27001:2005
Information security
CISM
Compliance
SOC 2
+9 more

Location: Jaipur, Rajasthan (Work From Office)

Experience: 5+ Years

Job Type: Full-Time


We're looking for an IT Compliance Officer to lead information security and compliance initiatives across our SaaS products and IT infrastructure. You'll ensure compliance with industry standards while strengthening our security and governance framework.


Key Responsibilities

  • Manage compliance for SOC 2, ISO 27001, GDPR, and ITGC.
  • Coordinate security audits, VAPT, and risk assessments.
  • Develop and maintain security policies, SOPs, and compliance documentation.
  • Ensure data protection, access control, and incident response best practices.
  • Collaborate with IT, Development, QA, and Product teams to improve security controls.
  • Conduct compliance training and stay updated on cybersecurity regulations.


Requirements

  • 5+ years of experience in IT Compliance, Information Security, or IT Audit (preferably in a SaaS/Product company).
  • Strong knowledge of SOC 2, ISO 27001, ITGC, VAPT, Risk Management, and Compliance Audits.
  • Experience with security documentation, audit processes, and risk assessments.
  • Excellent analytical, communication, and documentation skills.


Preferred: ISO 27001 Lead Auditor, CISA, CISM, CompTIA Security+, or Six Sigma certification.


Apply Now

Application Form: https://zfrmz.com/pAKb2ynfomIsuNwRfRbV?utm_source=cutshort

Read more
company logo
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
company logo
Bengaluru (Bangalore)
5.5 - 12 yrs
₹4L - ₹35L / yr
skill iconAmazon Web Services (AWS)
Cloud Security
AWS IAM
GuardDuty
CloudTrail
+1 more

Company Description

Appiness Interactive Pvt. Ltd. is a Bangalore-based product development and UX firm that specializes in digital services for startups to fortune-500s. We work closely with our clients to create a comprehensive soul for their brand in the online world, engaged through multiple platforms of digital media. Our team is young, passionate, and aggressive, not afraid to think out of the box or tread the un-trodden path in order to deliver the best results for our clients. We pride ourselves on Practical Creativity where the idea is only as good as the returns it fetches for our clients.


Role Overview

We are looking for an experienced Senior Cloud Security Engineer with 7+ years of experience, including strong hands-on expertise in AWS Cloud Security. The candidate will be responsible for designing, implementing, assessing, and continuously improving security across AWS cloud environments. The role requires strong knowledge of cloud security architecture, IAM, network security, threat detection, vulnerability management, incident response, security monitoring, encryption, and DevSecOps.


This is a highly technical position. Hands-on technical expertise will be given significantly more importance than communication skills. Good written and verbal communication is sufficient.


Key Responsibilities

  • Design and implement secure AWS cloud architectures.
  • Establish and maintain AWS security best practices and security controls.
  • Implement IAM, RBAC, least-privilege access, MFA, federation and privileged access controls.
  • Secure AWS networking including VPCs, Security Groups, NACLs, routing, private/public subnets and VPC endpoints.
  • Implement and manage AWS security services including:
  • AWS IAM
  • AWS KMS
  • AWS CloudTrail
  • Amazon GuardDuty
  • AWS Security Hub
  • AWS Config
  • AWS WAF
  • AWS Secrets Manager
  • Monitor and investigate security events, threats and suspicious activities.
  • Lead or participate in cloud security incident response and root-cause analysis.
  • Conduct vulnerability assessments and coordinate remediation.
  • Perform AWS security posture reviews and identify misconfigurations.
  • Review cloud architectures and provide security recommendations.
  • Implement encryption and data protection controls.
  • Secure CI/CD pipelines and support DevSecOps practices.
  • Review Infrastructure as Code for security risks.
  • Implement security automation wherever possible.
  • Work with engineering, DevOps and infrastructure teams to embed security into the development lifecycle.
  • Establish security standards, policies and controls for AWS environments.
  • Support compliance requirements and security audits.
  • Mentor junior engineers and provide technical guidance.


Mandatory Technical Skills


Must Have

  • 7+ years of overall IT/Security/Cloud experience
  • Strong AWS Cloud Security experience
  • Hands-on AWS security architecture
  • AWS IAM
  • IAM policies, roles, permissions and least privilege
  • AWS networking security
  • VPC, Security Groups and NACLs
  • CloudTrail and security logging
  • GuardDuty
  • Security Hub
  • KMS and encryption
  • Vulnerability management
  • Cloud security monitoring
  • Incident response
  • Security hardening
  • Security architecture/design


Good to Have

  • AWS Organizations / SCP
  • Terraform / CloudFormation
  • DevSecOps
  • CI/CD security
  • Docker/Kubernetes security
  • SAST/DAST/SCA
  • SIEM tools
  • Python/Bash/PowerShell scripting
  • CIS Benchmarks
  • NIST
  • ISO 27001
  • SOC 2
  • AWS security certifications
Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos