Saviynt at Codnatives · Bengaluru (Bangalore) · 7 - 12 years · ₹5L - ₹20L / yr · Profitable · Posted 9 Jul 2026

If you mean "I am with Saviynt JD" and you're asking for help understanding or preparing for a Saviynt Job Description (JD), please paste the JD here and I'll explain it or help you prepare.
If you're looking for a typical Saviynt IAM Engineer/Developer JD, it usually includes responsibilities such as:
- Implementing and configuring Saviynt Identity Governance and Administration (IGA).
- Managing user lifecycle (Joiner, Mover, Leaver processes).
- Developing and maintaining workflows, approval processes, and access request catalogs.
- Creating connectors and integrating applications using REST APIs, JDBC, LDAP, Active Directory, etc.
- Writing SQL queries and troubleshooting identity and access issues.
- Managing certifications, role management, segregation of duties (SoD), and compliance.
- Working with IAM technologies such as Active Directory, Azure AD, SSO, and MFA.
- Collaborating with security, infrastructure, and application teams.

Similar jobs (10)
Job Title: AppSec / AI Security Engineer
Employment Type: Full-time/ Permanent
Location: Indore (Work from Office)
About the Role
We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.
If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.
Key Responsibilities
- Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
- Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
- Develop structured code review workflows incorporating specifications, scan results, and code provenance.
- Optimize security scanning tools to reduce false positives and drive developer adoption.
- Investigate and manage security findings using established remediation and documentation processes.
- Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
- Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.
Required Skills & Experience
- Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
- Experience implementing automated security scanning and enforcement — not just operating existing tools.
- Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
- Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
- Ability to design, build, and own security automation and governance solutions from the ground up.
- Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
- Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
- Strong analytical mindset and ability to independently assess security risk across internal and external codebases.
Preferred Qualifications
- ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
- Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
- Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
- AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
- Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
- Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).
About Company:
Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.
For more info, please visit our website: https://5exceptions.com
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
About Nerve Solutions
Nerve Solutions is a team of engineers building products for real-time risk management and surveillance in financial markets. Our solutions enable market participants to identify, monitor, and quantify risks and anomalies in live markets, allowing them to take corrective action at sub-second speeds.
We also develop products for automated trading and have become a trusted technology partner to some of the largest financial services organizations in the region.
About the Role
We are looking for a proactive and detail-oriented IT & Information Security Engineer to manage and maintain the organization's IT infrastructure while ensuring the security, availability, and reliability of our systems. The role involves providing technical support, administering hardware and software, strengthening cybersecurity practices, monitoring network activities, and implementing security controls to safeguard organizational assets.
The ideal candidate should have strong infrastructure knowledge, a security-first mindset, and the ability to troubleshoot technical issues while continuously improving the organization's IT environment.
Roles & Responsibilities
- Manage and maintain the organization's IT infrastructure, including hardware, software, servers, and network systems.
- Provide technical support to employees by troubleshooting hardware, software, network, and system-related issues.
- Configure, deploy, and maintain desktops, laptops, peripherals, printers, and other IT equipment.
- Set up user accounts, systems, and required software for new employees and support onboarding activities.
- Monitor network performance and employee network activities to ensure system security and compliance.
- Implement and maintain endpoint security solutions, antivirus tools, firewalls, and access control mechanisms.
- Perform regular system updates, security patching, vulnerability assessments, and preventive maintenance.
- Identify infrastructure risks and recommend security enhancements to minimize vulnerabilities.
- Maintain documentation for IT assets, software licenses, network configurations, security policies, and system inventories.
- Assist in implementing information security best practices, security audits, and compliance initiatives.
- Coordinate with internal teams to ensure IT services effectively support business operations.
- Stay updated with the latest cybersecurity threats, technologies, and industry best practices.
Required Skills
- 2–4 years of experience in IT Infrastructure, System Administration, or Information Security.
- Strong knowledge of Windows operating systems, networking, servers, and IT infrastructure.
- Experience troubleshooting hardware, software, network, and user-related issues.
- Knowledge of network security, endpoint protection, firewalls, VPNs, and vulnerability management.
- Experience with Active Directory, user access management, and system administration.
- Familiarity with Microsoft 365 administration is an added advantage.
- Understanding of backup, disaster recovery, and IT asset management.
- Strong analytical and problem-solving skills with attention to detail.
- Good communication and documentation skills.
- Ability to work independently and collaboratively in a fast-paced environment.
Preferred Qualifications
- Bachelor's degree in Information Technology, Computer Science, or a related field.
- Certifications such as CompTIA A+, Network+, Security+, Microsoft, CCNA, or equivalent will be an added advantage.
DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.
1. Primary Must-Have Competencies (Core Priorities)
A. AWS Networking & VPC Topology (Top Priority)
- Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
- Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
- Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.
B. AWS Security, IAM Architecture & Compliance
- Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
- Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
- Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.
C. Infrastructure as Code (IaC) & Containerization
- Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
- Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).
D. Architecture Documentation & Systems Mapping
- Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.
2. Secondary Competency (Strong Advantage, Not Mandatory)
- Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
- Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.
Azure AD + Windows & SQL Administrator
Location: Faridabad, Haryana
Experience: 8+ Years
Employment Type: Full-time
Role Overview
We are looking for an experienced Azure AD / Microsoft Entra ID + Windows & SQL Administrator with 8+ years of hands-on experience in managing enterprise infrastructure and hybrid Microsoft environments.
The candidate will be responsible for administration, troubleshooting, security, monitoring, backup, patching, and maintenance of Azure AD/Entra ID, Active Directory, Windows Server, and Microsoft SQL Server environments.
Required Skills
- Strong hands-on experience with Microsoft Azure AD / Entra ID.
- Strong knowledge of Active Directory and Azure AD Connect / Entra Connect.
- Extensive experience in Windows Server Administration – 2016/2019/2022.
- Strong experience with Microsoft SQL Server Administration.
- Hands-on experience with SQL Backup, Restore, Patching, and Performance Tuning.
- Good knowledge of DNS, DHCP, and Group Policy (GPO).
- Strong PowerShell scripting and automation skills.
- Experience working with Hybrid Identity and Azure Infrastructure.
- Strong troubleshooting and problem-solving skills.
- Ability to work in an enterprise/global infrastructure environment.
The recruiter has not been active on this job recently. You may apply but please expect a delayed response.
Enterprise Integration Engineer, ServiceNow / Splunk (Freelance)
Positions: 2
Experience: Ideally 5-9 years.
Mission
Build secure enterprise connectors and governed tool interfaces between the AI platform and IT operational systems.
Priority skills
We particularly want candidates with a combination of:
ServiceNow + Splunk + API engineering
ServiceNow experience should include REST APIs, Incidents, Problems, Changes, Knowledge, work notes, authentication/OAuth and ITSM workflows.
Splunk experience should ideally include SPL, REST/Search APIs, indexes, sourcetypes, saved searches, alerts and operational integrations.
Confluence REST API and Rally/Broadcom Agile Central experience are additional advantages.
Engineering fundamentals
- Python and/or Java
- REST APIs
- OAuth2
- Enterprise authentication
- Service identities
- Rate limiting
- API throttling
- Retry patterns
- Idempotency
- Async/event processing
- Audit logging
- Least-privilege security
A candidate who combines ServiceNow + Splunk + Python/API engineering + GenAI integration experience should be treated as a particularly strong profile.
Required Technical Skill Set
MS Azure, M365, PowerShell
No of Requirements
1
Desired Experience Range
5 to 10 Years
Location of Requirement
Bangalore/Hydrabad
Desired Competencies (Technical/Behavioral Competency)
Must-Have
· Hands-on experience in Automating solutions in Power shell at L3 level
· Experience in monitoring, troubleshooting, and executing Azure Runbooks for operational automation
· Working knowledge of Microsoft 365 Groups management and support
· String Experience in M365 License Management
· Strong understanding of Agile methodologies, with experience working in Scrum or Kanban environments
· Knowledge of Azure monitoring and diagnostics tools (Log Analytics, Application Insights, Alerts)
· Good understanding of application security, reliability, and performance optimization in cloud environments
· Excellent problem-solving, collaboration, and communication skills
· Proficiency in DevOps practices, including CI/CD pipeline implementation and maintenance (Azure DevOps or GitHub Actions)
Good-to-Have
· AZ-204
· Good understanding of M365 Security and Compliance features, including retention, audit, and data governance policies
IT Systems Engineer
Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure
Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership
Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at
scale.
The Mission
About Metadome.ai
Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the
Metaverse Standards Forum and the VR/AR Association.
About the Role
We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.
This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.
Core Responsibilities
● Identity & Access Management — JumpCloud:
○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.
○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.
○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.
○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.
○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.
● Google Workspace Administration — GWS:
○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.
○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,
and sharing / visibility policies.○
○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.
Endpoint & Threat Protection — Sophos:
○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and
servers.
○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.
○ Maintain endpoint encryption, web / application control, and device-hardening standards.
○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.
Network, Firewall & Wi-Fi:
○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.
○ Administer enterprise Wi-Fi and wired networks (switches, access points), including
RADIUS-backed authentication.
○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.
○ Implement network monitoring, intrusion detection, and centralized logging.
Hardware, Software & Asset Management:
○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and
decommissioning.
○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.
○ Maintain an accurate hardware and software inventory and asset register.
○ Manage software deployment, patch management, and license compliance.
Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:
○ Operate and continuously improve the company's Information Security Management System
(ISMS).
○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control
implementation, evidence collection, and continuous monitoring.
○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA
assessments.
○ Serve as a primary point of contact during external audits and customer security reviews.
○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response
runbooks.
○ Drive security-awareness and phishing-simulation programs across the organization.
IT Operations & Support:
○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.
○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.
○ Manage backups, disaster recovery, and business-continuity testing.
○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within
budget.
○ Maintain documentation, runbooks, and standard operating procedures.
○ Own and report on the IT budget and asset allocation.
Required Skills & Experience
● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems
below rather than purely supervisory exposure.
● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.
● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.
● Sophos — hands-on endpoint / XDR administration and threat response.
● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.
● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one
full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.
Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.
System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.
Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.
Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.
Preferred Qualifications
●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.
●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.
●Scripting and automation for IT operations (Bash, PowerShell, or Python).
●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.
●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.
Why Join Us
You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running
flawlessly.
Location : Kochi
Candidated must be in Kerala and should be willing to relocate.
Notice Period : up to 30 days
Job Summary
We are seeking a motivated and detail-oriented Junior Azure Cloud Engineer with 2–3 years of experience in Microsoft cloud technologies. The ideal candidate will have hands-on experience in Microsoft Azure infrastructure services and Microsoft 365 administration. This role involves supporting cloud environments, managing identity and security, and assisting in cloud-based deployments and operations.
Key Responsibilities
- Manage and support Azure Entra ID (Azure Active Directory) including user management, group policies, conditional access, and identity governance.
- Configure and maintain Azure networking components such as Virtual Networks (VNet), Subnets, NSGs, VPN, and Load Balancers.
- Deploy and manage Azure Compute services including Virtual Machines, App Services, and related infrastructure.
- Administer Azure Storage services (Blob, File Shares, Backup, etc.).
- Monitor and maintain Microsoft 365 environments including Exchange Online, Teams, and SharePoint Online.
- Administer SharePoint Online sites, permissions, and configurations.
- Manage and monitor security policies using Microsoft 365 Security Center.
- Support cloud governance, compliance, and security best practices.
- Troubleshoot cloud infrastructure and M365-related issues.
- Collaborate with internal teams to support cloud migration and deployment activities.
- Document configurations, processes, and standard operating procedures.
Required Skills & Qualifications
- 2–3 years of hands-on experience in Microsoft Azure cloud services.
- Strong experience with Azure Entra ID, Azure Networking, Azure Storage, and Azure Compute services.
- Experience in Microsoft 365 Administration.
- Hands-on experience in SharePoint Online administration.
- Experience working with Microsoft 365 Security Center.
- Good understanding of cloud security, identity management, and governance.
- Strong troubleshooting and problem-solving skills.
- Good communication and documentation skills.
Nice to Have (Added Advantage)
- Experience with Azure DevOps (CI/CD pipelines, Repos, Boards, etc.).
- Basic scripting knowledge (PowerShell, Azure CLI).
- Azure or Microsoft 365 certifications.
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.







