Cutshort logo
For Employers
Our client company is into Computer software. (YB1) logo
Security Assessment
Our client company is into Computer software. (YB1)
Security Assessment

Security Assessment at Our client company is into Computer software. (YB1) · Bengaluru (Bangalore) · 6 - 8 years · ₹40L - ₹50L / yr · Posted 22 Nov 2021

Multi Recruit's logo

Security Assessment

at Our client company is into Computer software. (YB1)

Agency job
6 - 8 yrs
₹40L - ₹50L / yr
Bengaluru (Bangalore)
Skills
Penetration Testing
Security Assessment
Vulnerability management
Penetration testing
Vulnerability Management
  • Manage security tools(Snyk, Fossa, Trivy).
  • Manage vulnerability programs. Triage vulnerabilities, assign priorities and owners, follow up on the mitigation 
  • Monitor license violations.  
  • Perform Security Assessments and Threat Modeling
  • Security Incident Response. Be part of a security-on-call team in PagerDuty, act as incident commander, perform Root Cause Analysis.
  • Drive security initiatives(Web Application Security, Least-privilege principle, Secrets Management, Key Management, PKI and Certificate Management, Anti-fraud protection).
  • Given our fast pace and startup nature, things change over time and your job responsibilities will too.

You'll need:

  • Web application security experience.
  • Familiarity with a modern SaaS infrastructure and application development.
  • Manual and/or automated Penetration Testing (white box, black box & grey box).
  • Good understanding of security risk(OWASP Top 10).
  • Pen-testing: burp suite/ postman, etc.
  • Vulnerability management: Snyk, fossa, NexusIQ, WhiteHat security, aqua security, GitHub security, etc.
  • Familiarity with major security protocols.
  • Collaboration, transparency, and integrity.
  • BS/MS degree; 5+ years of relevant experience.

Nice to have:

  • Experience in scripting languages(BASH, Python, JS, etc).
  • CEH, CSSLP, GIAC, OSCP, OSCE, or other related industry-recognized certifications.
  •  
Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

Similar jobs (6)

Risosu Consulting LLP
at Risosu Consulting LLP
1 candid answer
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
Bengaluru (Bangalore), Hyderabad, Pune, Kolkata, Chennai, Mumbai
1 - 10 yrs
₹4L - ₹30L / yr
Security Information and Event Management (SIEM)
Cyber Security
Burp suite
Metasploit
Network Security

We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.


Responsibilities

  • Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
  • Monitor and respond to security events using SIEM tools as part of SOC operations
  • Test application security using Burp Suite and similar tools
  • Support ISO 27001 compliance, audits and security policies
  • Harden network infrastructure, firewalls and access controls
  • Document findings and track fixes with engineering teams


Requirements

  • 1+ years of experience in VAPT, SOC or security engineering
  • Hands-on experience with Burp Suite and SIEM tools
  • Knowledge of the OWASP Top 10 and network security fundamentals
  • Exposure to ISO 27001 or similar frameworks
  • Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Read more
Appknox
at Appknox
1 video
6 recruiters
Vasudha Srivastav
Posted by Vasudha Srivastav
Bengaluru (Bangalore)
2 - 4 yrs
Best in industry
Bug Bounty
Exploit Development
Agent Driven Pentesting
Reverse engineering
Penetration testing
+6 more

A BIT ABOUT US

Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.

The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.

Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.

We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.



The Opportunity

To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.


What An Ideal Candidate Would Look Like: 

  • Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
  • Technology Stack: AWS, GCP, Objective C, Java, Python
  • Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities


Minimum Requirements

  • 2-4+ years of experience in application security and vulnerability research
  • Strong foundation in mobile app security - Android or Ios
  • Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
  • Strong understanding of exploit mitigations and proven ability to bypass them
  • Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
  • Develop AI-driven agents to automate dynamic analysis
  • Should be able to Leverage AI/LLMs to augment Pentesting efforts
  • Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables


Good to have Requirements

  • Understanding of AI/ML security risks


Responsibilities

  • Security assessment of web/mobile applications on various platforms
  • Focusing on Mobile Application Security Research for new vulnerabilities
  • Static and Dynamic Code Analysis
  • Develop and interpret security standards and guides
  • Automation of exploit development 
  • Understand and explain the results with impact on business and compliance status
  • Continuously learning and training on latest tools and technique


Work Expectations

Within 1 month

Training on processes, security workflows and develop understanding on internal tools.


Within 3 months

Actively contributing in exploit development and automation of it with the team.


Within 6 months

Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.


Within 1 Year

By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.


Personality traits we really admire

  • A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
  • Great attitude to ask questions, learn and suggest process improvements.
  • Has attention to details and helps identify edge cases.
  • Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
  • Follow timelines and absolute commitment to deadlines.


Interview Process - would be team specific

  • Round 1- CTF round 
  • Round 2 -Profile Evaluation; HR
  • Round 3 -Technical Interview with security team members
  • Round 4 -Technical Interview with the Hiring Manager
  • Round 5 -Technical round with CTO
  • Round 6 -HR Round


Compensation

  • As per Industry Standards


Why Join Us

  • Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
  • Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
  • Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
  • Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.


Read more
Pentabay Softwares
at Pentabay Softwares
1 recruiter
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
One of our US based Client
One of our US based Client
Agency job
via HyrHub by Shwetha Naik
Remote only
4 - 8 yrs
Best in industry
IT security
IT security audit
GDPR

The Security Analyst assists the Data Security team to help ensure the security of the company and its clients. Looking for immediate joiners.


 KEY RESPONSIBILITIES

 All employees are expected to use good business judgment and appropriate discretion and decision making while performing responsibilities of the position, and to incorporate EVA’s Core Beliefs in their daily work.

  • Performs daily health checks as documented by the IT Security team.
  • Supports the Security team by documenting and performing support tasks.
  • Participates in change management, incident management, audit and business continuity processes.
  • Plans and implements security policies and procedures to protect computer systems, networks and data from unauthorized access.
  • Participates in internal and external compliance (SOC 2) audits.
  • Recommends security enhancements.

Job specifics:

  • Familiarity with standard security concepts, practices and procedures.
  • Knowledge of Windows operating systems.
  • Strong Documentation, communication skills and attention to detail.
  • Able to work independently and as a part of a team to deliver completed projects on-time.
  • Identifies ways to continuously improve own and/or company performance.
  • Knowledge of security toolsets
  • Knowledge of compliance activities (GDPR, SOC 2, ISO:27001).
  • Knowledge of database security.
  • Knowledge of SIEM technology and security event correlation and monitoring.
  • Experience with AWS.             
  • Proficient with computer software including Salesforce 


 EDUCATION & EXPERIENCE  

  • Bachelor’s Degree in computer science, mathematics, Information Systems or equivalent experience preferred.
  • Minimum of 3 years of hands-on IT Security & Audit experience.
  • Professional IT Security Certifications are strongly preferred, such as Security+, CISSP, CISM, CISA, GSEC, etc.


Read more
Agami Tech
at Agami Tech
3 recruiters
Digish Shah
Posted by Digish Shah
Mumbai
1 - 3 yrs
Best in industry
RHCSA
Linux/Unix
Cloud Computing
VMWare
Firewall
+5 more

Location : Mumbai


Big Picture (The Opportunity) :

Are you looking for an opportunity to advance your Career? & If you are able to maintain a positive attitude even when everything goes wrong, if you are detail oriented and self motivated with a passion to learn and improve your skills and knowledge, we have a perfect job for you !

What do we want from you ? (Our Expectations) :

  • Zero to 2 years experience in Linux Operating System.
  • Flexible working hours - able to support occasional nights, weekends, and call-ins, able to quickly adapt to a constantly changing faced paced environment. Open to travel to sites.
  • An ideal person who is excited and motivated about running and supporting a production - grade critical infrastructure and looks for opportunities to improve processes with automation.


What are you required to do ? (Your Responsibilities) :

  • Proactively maintain and develop all linux infrastructure technology to maintain a 24*7*365 uptime service.
  • Engineering of systems administration-related various solutions for our various SAAS products and projects as well as operational needs.
  • Proactively monitoring system performance and capacity planning.
  • Providing technical support to customers for Applications, Operating systems, and networking.
  • Will also be the first point of contact for our clients, where installations are placed on a permanent basis, for basic troubleshooting and problem solving.
  • Fault finding, analysis and logging information for reporting of performance exceptions.
  • Maintain best practices on managing systems and services across all environments.

 

 

Skills & Qualification Required (Add Value) :

  • Graduate - Preferred to have Bachelor‘s Degree in Engineering, Computer Science or related field.
  • He / She should be familiar with the installation and configuration of Linux operating systems and setup and operation of TCP/IP networking on Linux systems also familiar with Internet concepts including SMTP, IMAP, POP, HTTP, DNS, LDAP and related protocols.
  • You should possess excellent communication skills .
  • Knowledge of Email concepts, Helpdesk Concept , VoIP Concept , Cloud computing will be an added advantage.
Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos