Cutshort logo
For Employers
Talent Pro  logo
Product Security Engineer (B2B SaaS), Fintech company
Product Security Engineer (B2B SaaS), Fintech company

Product Security Engineer (B2B SaaS), Fintech company at Talent Pro · Bengaluru (Bangalore) · 3 - 8 years · ₹25L - ₹32L / yr · Bootstrapped · Posted 5 Feb 2026

Talent Pro 's logo

Product Security Engineer (B2B SaaS), Fintech company

Mayank choudhary's profile picture
Posted by Mayank choudhary
3 - 8 yrs
₹25L - ₹32L / yr
Bengaluru (Bangalore)
Skills
Cloud security
  • Strong Product Security Engineer profiles
  • Mandatory (Experience 1) – Must have 3+ years of hands-on experience in Security Engineering, preferably in B2B SaaS or Fintech environments.
  • Mandatory (Experience 2) – Strong working knowledge of Cloud Security (AWS), Infrastructure Security, and Application Security.
  • Mandatory (Experience 3) – Must have hands-on experience with compliance frameworks and audits, including SOC 2, GDPR, and ISO 27001.
  • Mandatory (Experience 4) – Experience in setting up, managing, and tracking security tools such as MDM, endpoint agents, and related security tooling.
  • Mandatory (Experience 5) – Background in building and scaling security practices for early-stage startups (preferably Series A–C).
  • Good to Have (Certification 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.


Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Talent Pro

Founded :
2024
Type :
Services
Size
Stage :
Bootstrapped

About

N/A

Company social profiles

bloglinkedin

Similar jobs (10)

Pentabay Softwares
at Pentabay Softwares
1 recruiter
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
Appknox
at Appknox
1 video
6 recruiters
Vasudha Srivastav
Posted by Vasudha Srivastav
Bengaluru (Bangalore)
2 - 4 yrs
Best in industry
Bug Bounty
Exploit Development
Agent Driven Pentesting
Reverse engineering
Penetration testing
+6 more

A BIT ABOUT US

Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.

The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.

Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.

We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.



The Opportunity

To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.


What An Ideal Candidate Would Look Like: 

  • Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
  • Technology Stack: AWS, GCP, Objective C, Java, Python
  • Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities


Minimum Requirements

  • 2-4+ years of experience in application security and vulnerability research
  • Strong foundation in mobile app security - Android or Ios
  • Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
  • Strong understanding of exploit mitigations and proven ability to bypass them
  • Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
  • Develop AI-driven agents to automate dynamic analysis
  • Should be able to Leverage AI/LLMs to augment Pentesting efforts
  • Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables


Good to have Requirements

  • Understanding of AI/ML security risks


Responsibilities

  • Security assessment of web/mobile applications on various platforms
  • Focusing on Mobile Application Security Research for new vulnerabilities
  • Static and Dynamic Code Analysis
  • Develop and interpret security standards and guides
  • Automation of exploit development 
  • Understand and explain the results with impact on business and compliance status
  • Continuously learning and training on latest tools and technique


Work Expectations

Within 1 month

Training on processes, security workflows and develop understanding on internal tools.


Within 3 months

Actively contributing in exploit development and automation of it with the team.


Within 6 months

Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.


Within 1 Year

By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.


Personality traits we really admire

  • A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
  • Great attitude to ask questions, learn and suggest process improvements.
  • Has attention to details and helps identify edge cases.
  • Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
  • Follow timelines and absolute commitment to deadlines.


Interview Process - would be team specific

  • Round 1- CTF round 
  • Round 2 -Profile Evaluation; HR
  • Round 3 -Technical Interview with security team members
  • Round 4 -Technical Interview with the Hiring Manager
  • Round 5 -Technical round with CTO
  • Round 6 -HR Round


Compensation

  • As per Industry Standards


Why Join Us

  • Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
  • Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
  • Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
  • Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.


Read more
Risosu Consulting LLP
at Risosu Consulting LLP
1 candid answer
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
Shipthis Inc
at Shipthis Inc
2 candid answers
Shariba Tasneem
Posted by Shariba Tasneem
Bengaluru (Bangalore)
1 - 3 yrs
₹7L - ₹9L / yr
ISO/IEC 27001:2005
skill iconAmazon Web Services (AWS)
Google Cloud Platform (GCP)
GRC

At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.


Learn more at www.shipthis.co


Role Overview

We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.


What You’ll be Doing


Security Operations

  • Monitor infrastructure, application, and security alerts and assist with incident investigation.
  • Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
  • Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
  • Track security issues and corrective actions through closure.

Vulnerability Management

  • Run and review application and infrastructure vulnerability scans.
  • Maintain a vulnerability register and coordinate remediation with engineering teams.
  • Support VAPT and penetration-testing exercises and validate closure of findings.
  • Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.

Compliance & Governance

  • Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
  • Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
  • Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
  • Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.

MDM & Endpoint Security

  • Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
  • Maintain device inventory and monitor endpoint compliance.
  • Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
  • Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
  • Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.

DevOps, CI/CD & Cloud

  • Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
  • Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
  • Automate repetitive deployment, infrastructure, security, and compliance tasks.
  • Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
  • Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.


Required Fundamentals

  • Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
  • Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
  • Strong troubleshooting, ownership, attention to detail, and willingness to learn.


Desired Qualifications

  • 1–2 years of experience with strong fundamentals are welcome.
  • Basic scripting knowledge in Python, Bash, or similar.
  • Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
  • Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.


We Welcome Candidates:

  • Who can join immediately
  • Female candidates returning to work after a career break are strongly encouraged.


We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.


Job Synopsys

Location: Bangalore

Job Type: Full-time, Permanent

Experience: 1-2 years

Industry: Software Product



Read more
Five exceptions Software Solution
Neha Daka
Posted by Neha Daka
Indore
4 - 8 yrs
₹3.5L - ₹10L / yr
ApplicationSecurity,Cybersecurity, DevSecOps,CI/CD
DAST
SAST
Cloud Computing

Job Title: AppSec / AI Security Engineer


Employment Type: Full-time/ Permanent

Location: Indore (Work from Office)


About the Role

We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.

If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.

 

Key Responsibilities

  • Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
  • Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
  • Develop structured code review workflows incorporating specifications, scan results, and code provenance.
  • Optimize security scanning tools to reduce false positives and drive developer adoption.
  • Investigate and manage security findings using established remediation and documentation processes.
  • Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
  • Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.


Required Skills & Experience

  • Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
  • Experience implementing automated security scanning and enforcement — not just operating existing tools.
  • Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Ability to design, build, and own security automation and governance solutions from the ground up.
  • Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
  • Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
  • Strong analytical mindset and ability to independently assess security risk across internal and external codebases.


Preferred Qualifications

  • ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
  • Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
  • Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
  • Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).


About Company:

Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.

 

For more info, please visit our website:  https://5exceptions.com

Read more
Ampera Technologies
Bengaluru (Bangalore), Chennai
5 - 15 yrs
Best in industry
DevOps
skill iconAmazon Web Services (AWS)

DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.


1. Primary Must-Have Competencies (Core Priorities)


A. AWS Networking & VPC Topology (Top Priority)

  • Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
  • Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
  • Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.


B. AWS Security, IAM Architecture & Compliance

  • Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
  • Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
  • Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.


C. Infrastructure as Code (IaC) & Containerization

  • Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
  • Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).


D. Architecture Documentation & Systems Mapping

  • Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.


2. Secondary Competency (Strong Advantage, Not Mandatory)

  • Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
  • Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.

 

Read more
CLOUDSUFI
at CLOUDSUFI
3 recruiters
Ayushi Dwivedi
Posted by Ayushi Dwivedi
Remote only
8 - 14 yrs
₹40L - ₹50L / yr
Network Security
Application Security
GRC
WAF
SAST
+2 more

About Us

CLOUDSUFI is a Silicon Valley-based specialist Data Engineering & Cloud Technologies player with top-tier clients, favorable revenue mix, strong financial performance, and robust management. We pride ourselves in helping in the Data Discovery, Insights and Monetization for organizations. We offer quality of work, opportunities to learn new platforms/technologies that will help young engineers put themselves ahead in their careers compared to their peers in the IT Services industry. CLOUDSUFI is a Data Science and Product Engineering company building Products/Solutions for Technology and Enterprise industries leveraging the advent of Cloud Hyper Scalers and AI/ML, NLP technologies.

The organization is built to scale with strong external/ internal tech capabilities and governance standards. Started in 2019, CLOUDUSUFI is a family of 250 members working towards a common goal of making the enterprise data dance.

To know more, please visit https://cloudsufi.com


Our Values

We are a passionate and empathetic team that prioritizes human values. Our purpose is to elevate the quality of lives for our family, customers, partners and the community.


Equal Opportunity Statement

CLOUDSUFI is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified candidates receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation and national origin status. We provide equal opportunities in employment, advancement, and all other areas of our workplace. Please explore more at https://www.cloudsufi.com/


Role : Full-Time Individual Contributor (IC)

Reporting to : Solution Architect / Program Manager

Location : India Remote (Quarterly visits to Noida office)

Shift : 2PM-11PM IST

12x5 (On call duty)

Experience : 8-14 Years


ABOUT YOU

  • 5+ years’ experience with AWS orchestration via Terraform script
  • 5+ years’ experience with CloudWatch/CloudTrail/Guard Duty
  • 5+ years’ experience with AWS WAF
  • 4+ years’ experience with CloudFlare
  • 3+ years’ experience with DataDog
  • Experience with PagerDuty
  • Ability to make nuanced threat assessments
  • Experience in SOPHOS.
  • Significant experience with PCI, SOC2, SOX, HIPAA, or other compliance regimes
  • Experience in Infrastructure As Code – Ansible / Terraform/ CloudFormation
  • Hands-on experience implementing various security tools in CI/CD pipeline
  • Strong experience with any cloud service provider (AWS Preferred)
  • Implement and oversee technological upgrades, improvements and major changes to the cloud security environment.
  • Develop solutions, install/configure/integrate IT tools and security processes within an application or organization to help improve the overall IT security posture.
  • Set up Static and Dynamic Code Analysis tools, review the results and explain any gaps and potential impact to the teams (development and operations).
  • Penetration testing and container security.
  • Evaluate and analyze threat, vulnerability, impact and risk to security issues discovered from security assessments.
  • Assess current technology architecture for vulnerabilities, weaknesses and for possible upgrades or improvement
  • Creating and managing security strategies
  • Oversee information security audits, whether performed by organization or third-party personnel
  • Develop, maintain and publish up-to-date information security policies, standards and guidelines.
  • Preferred Certification - AWS Security/CISSP/CISM (Certified Information Security Manager)

ABOUT THE ROLE

  • Work independently with vendors and collaborate with colleagues
  • Experience negotiating remediation timelines and/or remediate found issues independently
  • Ability to implement vendor platforms within CI/CD pipelines
  • Experience managing/responding to incidents, collecting evidence, and making decisions.
  • Working with vendors and HM Teams to deploy criteria within WAF and fine tuning it according to applications’ needs
  • Multitasking and continuous ability to provide a high level of concentration for assigned projects.
  • Good working knowledge of AWS security in general and familiarity of the AWS native security tools
  • The candidate should be experienced and articulate, who is not going to get discouraged, despite meeting roadblocks, and will continue promoting security within the company.
  • Ability to create DevSecOps security requirements while working on a project
  • Ability to articulate security requirements during the Architecture meetings and working hand in hand with HM Applications and DevOps Principal Engineers



Read more
One of our US based Client
One of our US based Client
Agency job
via HyrHub by Shwetha Naik
Remote only
4 - 8 yrs
Best in industry
IT security
IT security audit
GDPR

The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.


 KEY RESPONSIBILITIES

 All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.

  • Performs daily health checks as documented by the IT Security team.
  • Supports the Security team by documenting and performing support tasks.
  • Participates in change management, incident management, audit and business continuity processes.
  • Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
  • Participates in internal and external compliance (SOC 2) audits.
  • Recommends security enhancements.

Job specifics:

  • Familiarity with standard security concepts, practices and procedures.
  • Knowledge of Windows operating systems.
  • Strong Documentation, communication skills and attention to detail.
  • Able to work independently and as a part of a team to deliver completed projects on-time.
  • Identifies ways to continuously improve own and/or company performance.
  • Knowledge of security toolsets
  • Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
  • Knowledge of database security.
  • Knowledge of SIEM technology and security event correlation and monitoring.
  • Experience with AWS.             
  • Proficient with computer software including Salesforce 


 EDUCATION & EXPERIENCE  

  • Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
  • Minimum of 3 years of hands-on IT Security & Audit experience.
  • Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.


Read more
Optimo Capital
at Optimo Capital
2 candid answers
Ajinkya Pokharkar
Posted by Ajinkya Pokharkar
Bengaluru (Bangalore)
3 - 8 yrs
₹5.5L - ₹12L / yr
System Administration
IT security
MDM
Endpoint protection
Sophos
+15 more


About the role


We’re hiring an IT Systems Administrator for an NBFC to secure endpoints, SaaS, and networks across ~50 branches, ~250+ field staff, and ~50+ office users.

This is primarily an IT Admin + Security role, with secondary exposure to AWS cloud ops + light DevOps + basic DB access management.


If you’re an IT Admin aiming to break into AWS Cloud Ops + DevOps, this role is a strong next step — you’ll own core IT/security and get hands-on exposure to cloud operations and deployments.


Key responsibilities (Primary: IT Admin + Security)

  • Manage endpoint security for laptops and mobiles (policies, patching, encryption, antivirus/EDR); drive MDM implementation now/future (e.g., Intune/Jamf).
  • Administer Google Workspace (Gmail/Drive/Calendar): users, groups, permissions, SSO, MFA, sharing controls.
  • Own joiner–mover–leaver lifecycle: provisioning/deprovisioning, access controls, periodic access reviews.
  • Secure branch connectivity: VPN, internal Wi-Fi, internet usage controls; coordinate troubleshooting and standardization across branches.
  • Manage HO security stack: firewall operations, rule changes with change control, monitoring/log review (basic but consistent).
  • Secure SaaS tools (CRM/HRMS/comms like Slack/Zoom): role-based access, MFA enforcement, offboarding, integration/OAuth controls.
  • Maintain IT asset inventory: procurement coordination, issuance/return, audits, warranty/AMC, license renewals; remote lock/wipe for lost devices.
  • Handle security incidents: phishing, account compromise, device loss/theft — contain, investigate, recover, and prevent recurrence.
  • Run backups and basic DR testing; maintain SOPs/documentation and train staff on cyber hygiene.
  • Provide hands-on user support: laptop builds, software installs, Outlook/Excel issues, VPN/Wi-Fi troubleshooting, escalations and vendor coordination.


Secondary responsibilities (AWS + DevOps + DB ops support)

  • Support AWS administration: IAM users/roles/policies, MFA, access key hygiene, basic log review (e.g., CloudTrail).
  • Manage AWS access controls: security groups/firewall rules, IP allowlists/whitelisting (admin tools, databases, vendor access).
  • Assist engineering with DevOps operations:
  • CI/CD support (deployment coordination, rollbacks, environment configuration)
  • Secrets/credentials management and rotation (no shared creds)
  • DNS + SSL/TLS certificates, basic monitoring/alerting coordination
  • Bonus: Docker/Kubernetes and Terraform exposure
  • Basic database operations (admin-lite):
  • DB user creation, roles/permissions, least-privilege access
  • IP allowlisting/whitelisting for DB access via VPN/approved sources
  • Backup/restore verification coordination and basic monitoring signals (connections/storage)


Requirements

  • 3+ years in IT security / systems administration (BFSI or branch-heavy org preferred).
  • Hands-on with Google Workspace or Microsoft 365 administration.
  • Must have hands-on experience leading or executing an email suite migration (e.g., Google Workspace ↔ Microsoft 365), including mailbox migration, DNS cutover, MX/SPF/DKIM/DMARC reconfiguration, and user transition management.
  • Strong endpoint/security fundamentals: encryption, patching, AV/EDR, remote support, device compliance.
  • Comfortable with networks: VPN/Wi-Fi/LAN troubleshooting; firewall basics and change discipline.
  • Strong operational discipline: asset tracking, vendor management, documentation, ticketing, user communication.
  • Practical AWS familiarity (IAM, access controls, logging) and ability to support DevOps workflows.


Nice to have

  • Experience implementing MDM at scale (Intune/Jamf/SureMDM).
  • Exposure to SOC2 / ISO27001 evidence, controls, and audit workflows.
  • Scripting for automation (PowerShell/Bash/Python).
  • Familiarity with managed databases and secure access patterns.


Read more
Resources Valley
at Resources Valley
1 recruiter
Manind Gupta
Posted by Manind Gupta
Jaipur
1 - 4 yrs
₹2L - ₹8L / yr
Cyber Security
cyber

Cyber Security Expert


We are seeking a highly skilled Cyber Security Expert with strong expertise in AI-driven

security tools and ethical hacking techniques. The ideal candidate will safeguard our digital

infrastructure, proactively identify vulnerabilities, and design intelligent defense mechanisms

against evolving cyber threats.

Key Responsibilities

• Threat Analysis: Identify, assess, and mitigate potential risks across systems and

networks.

• AI Security Tools: Deploy and manage AI-based solutions for intrusion detection,

anomaly monitoring, and predictive threat modelling.

• Ethical Hacking: Conduct penetration testing, simulate cyber-attacks, and recommend

remediation strategies.

• Incident Response: Lead investigations, contain breaches, and implement recovery

measures.

• Compliance & Governance: Ensure adherence to data protection laws, industry

standards, and organizational policies.

• Training & Awareness: Educate employees on best practices and emerging threats.


Required Skills & Qualifications

• Proven hands-on experience with AI-powered security platforms (e.g., SIEM, SOAR,

ML-based anomaly detection).

• Strong knowledge of ethical hacking tools (Metasploit, Burp Suite, Kali Linux, etc.).

• Expertise in network security, firewalls, IDS/IPS, and endpoint protection.

• Familiarity with cloud security (AWS, cloud platform).

• Proficiency in scripting languages (Python, Bash, PowerShell) for automation.

• Solid understanding of cryptography, authentication protocols, and secure coding

practices.



Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos