Cutshort logo
For Employers
Fonada logo
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

Senior Cybersecurity Specialist at Fonada · Noida · 7 - 10 years · ₹15L - ₹20L / yr · Profitable · Posted 27 May 2026

Fonada's logo

Senior Cybersecurity Specialist

Karandeep Singh's profile picture
Posted by Karandeep Singh
7 - 10 yrs
₹15L - ₹20L / yr
Noida
Skills
Cyber Security
Information security
Network Security
DevSecOps
Ethical Hacking
Penetration testing
GRC
VAPT
skill iconPython
ISO/IEC 27001:2022

About the Role 

We are seeking an experienced Cyber Security Specialist who can operate across both offensive and defensive security disciplines. This dual-role professional will lead Vulnerability Assessment and Penetration Testing (VAPT) engagements, act as the in-house Red Team to simulate real-world adversaries, and own the implementation and continuous improvement of the Information Security Management System (ISMS) aligned with ISO/IEC 27001 and related standards. You will combine hands-on offensive security work with governance, audit readiness, and stakeholder engagement across engineering, IT, legal, and executive leadership. 


Key Responsibilities 

VAPT & Red Team Operations 

  • Plan, scope, and execute end-to-end Vulnerability Assessment and Penetration Testing (VAPT) engagements across web applications, mobile apps, APIs, networks, cloud environments, wireless, and physical infrastructure. 
  • Act as the organization's in-house Red Team, simulating advanced persistent threat (APT) actors through adversary emulation, social engineering, phishing campaigns, and physical intrusion testing where authorized. 
  • Design and execute Red Team operations aligned with MITRE ATT&CK, TIBER-EU, and similar frameworks; develop custom Tactics, Techniques, and Procedures (TTPs). 
  • Conduct manual and automated exploitation, post-exploitation, lateral movement, privilege escalation, and persistence testing in production-like environments. 
  • Develop custom exploits, payloads, scripts, and tooling (Python, PowerShell, Bash, C/C++, Go) to bypass security controls during sanctioned engagements. 
  • Perform source code reviews, threat modeling, and secure architecture reviews of new and existing systems. 
  • Coordinate Purple Team exercises with the Blue Team / SOC to validate detection coverage and improve defensive playbooks. 
  • Produce high-quality VAPT and Red Team reports with executive summaries, technical findings, proof-of-concept exploits, risk ratings (CVSS), and prioritized remediation guidance. 
  • Re-test remediated findings and track closure with engineering and IT teams through to verification. 

ISO Compliance & Governance 

  • Lead the implementation, maintenance, and continual improvement of the ISMS in line with ISO/IEC 27001:2022, including scope definition, Statement of Applicability (SoA), and risk treatment plans. 
  • Own and maintain ISO policies, procedures, controls, and documentation across the organization, ensuring alignment with ISO 27001, ISO 27017, ISO 27018, and ISO 22301. 
  • Plan and coordinate internal and external audits; serve as the primary liaison with certification bodies, auditors, and regulators. 
  • Conduct risk assessments, business impact analyses (BIA), and threat modeling; maintain a central risk register and drive remediation. 
  • Map VAPT and Red Team findings to ISO 27001 Annex A controls and feed results into the risk management lifecycle. 
  • Support compliance with adjacent frameworks: SOC 2, NIST CSF, GDPR, HIPAA, PCI-DSS, and DPDP Act (India), as applicable. 
  • Define and report security and compliance KPIs/KRIs to senior leadership; prepare materials for management reviews and board updates. 
  • Develop and deliver security awareness training, phishing simulations, and role-based secure-coding training. 
  • Drive third-party / vendor risk management, including security questionnaires, contractual clauses, and ongoing monitoring. 
  • Partner with engineering and DevOps to embed security into the SDLC, CI/CD pipelines, and cloud architectures (DevSecOps). 

Incident Response & Continuous Improvement 

  • Support incident response activities: detection, triage, containment, eradication, recovery, and post-incident reviews. 
  • Maintain business continuity and disaster recovery plans; coordinate BCP/DR testing and tabletop exercises. 
  • Stay current on emerging threats, CVEs, attacker techniques, regulatory changes, and ISO standard updates; recommend and drive improvements. 

Required Qualifications 

  • 8+ years of progressive experience in cyber security, with at least 4 years in hands-on offensive security (VAPT, penetration testing, or Red Team) and 3+ years in ISO 27001 implementation and audits. 
  • Proven track record of leading VAPT engagements across web, mobile, API, network, cloud (AWS / Azure / GCP), and wireless environments. 
  • Hands-on experience executing Red Team operations and adversary emulation aligned with MITRE ATT&CK. 
  • Deep proficiency with offensive security tooling: Burp Suite Pro, Metasploit, Cobalt Strike (or open-source equivalents like Sliver, Mythic, Havoc), Nmap, Nessus, Nuclei, BloodHound, Impacket, Responder, and OWASP ZAP. 
  • Strong scripting and exploit development skills in Python, PowerShell, Bash, and at least one compiled language (C/C++, Go, or Rust). 
  • Proven hands-on experience leading an organization through ISO 27001 certification and surveillance audits end-to-end. 
  • Strong working knowledge of ISO/IEC 27001:2022 (including Annex A controls), ISO 27002, ISO 27017, ISO 27018, and ISO 22301. 
  • Solid understanding of security domains: IAM, network security, endpoint security, cloud security, application security (OWASP Top 10, API Security Top 10), and Active Directory attack paths. 
  • Experience with risk assessment methodologies (ISO 27005, NIST 800-30) and the ability to translate offensive findings into business risk. 
  • Strong report-writing, policy-drafting, and executive communication skills. 
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related field (or equivalent experience). 

Preferred Qualifications 

  • Offensive security certifications: OSCP, OSEP, OSWE, OSED, CRTO, CRTP, CRTE, CRTL, GPEN, GXPN, GWAPT, or CEH Practical. 
  • Governance certifications: ISO 27001 Lead Implementer and/or Lead Auditor, CISSP, CISM, CISA, or CRISC. 
  • Cloud security certifications (CCSP, AWS Security Specialty, Azure Security Engineer, or GCP Professional Cloud Security Engineer). 
  • Published CVEs, security research, bug bounty achievements, or contributions to open-source security tools. 
  • Experience with Active Directory / Entra ID red teaming, Kerberos attacks, and modern EDR/XDR evasion techniques. 
  • Experience with container, Kubernetes, and serverless security testing. 
  • Experience implementing or auditing additional frameworks: SOC 2 Type II, NIST CSF, NIST 800-53, HITRUST, or PCI-DSS. 
  • Experience with GRC platforms (Vanta, Drata, Sprinto, ServiceNow GRC, Archer, OneTrust). 
  • Experience in regulated industries: financial services, healthcare, SaaS, or critical infrastructure. 
  • Experience briefing executive leadership, customers, and external auditors on offensive findings and remediation strategy. 


Read more
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos

About Fonada

Founded :
2014
Type :
Products & Services
Size :
20-100
Stage :
Profitable

About

Experience the future of communication with Fonada's Next-Gen CPaaS. Revolutionizing communication solutions for businesses.
Read more

Company social profiles

bloginstagramlinkedintwitterfacebook

Similar jobs (10)

company logo
Bhattacharjee Akash
Posted by Bhattacharjee Akash
Bengaluru (Bangalore), Hyderabad, Pune, Kolkata, Chennai, Mumbai
1 - 10 yrs
₹4L - ₹30L / yr
Security Information and Event Management (SIEM)
Cyber Security
Burp suite
Metasploit
Network Security

We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.


Responsibilities

  • Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
  • Monitor and respond to security events using SIEM tools as part of SOC operations
  • Test application security using Burp Suite and similar tools
  • Support ISO 27001 compliance, audits and security policies
  • Harden network infrastructure, firewalls and access controls
  • Document findings and track fixes with engineering teams


Requirements

  • 1+ years of experience in VAPT, SOC or security engineering
  • Hands-on experience with Burp Suite and SIEM tools
  • Knowledge of the OWASP Top 10 and network security fundamentals
  • Exposure to ISO 27001 or similar frameworks
  • Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Read more
company logo
Vasudha Srivastav
Posted by Vasudha Srivastav
Bengaluru (Bangalore)
2 - 4 yrs
Best in industry
Bug Bounty
Exploit Development
Agent Driven Pentesting
Reverse engineering
Penetration testing
+6 more

A BIT ABOUT US

Appknox is one of the top Mobile Application security companies recognized by Gartner and G2. A profitable B2B SaaS startup headquartered in Singapore & working from Bengaluru.

The primary goal of Appknox is to help businesses and mobile developers secure their mobile applications with a focus on delivery speed and high-quality security audits.

Appknox has helped secure mobile apps at Fortune 500 companies with major brands spread across regions like India, South-East Asia, Middle-East, US, and expanding rapidly. We have secured 300+ Enterprises globally.

We are a 65+ incredibly passionate team working to make an impact and helping some of the biggest companies globally. We work in a highly collaborative, very fast-paced work environment. If you have what it takes to be part of the team, we are excited and let’s speak further.



The Opportunity

To join the security team engaging with multiple clients, helping them with end to end security audits, also research about new topics and vulnerabilities to be added to the scanner, present it in conferences.


What An Ideal Candidate Would Look Like: 

  • Skills - Application Penetration Testing (Web, iOS and Android), experience with IoT testing, source code audits.
  • Technology Stack: AWS, GCP, Objective C, Java, Python
  • Responsibilities: Engage with clients for scoping call, perform security audits, remediation call with clients to patch the issues, research on new technologies/vulnerabilities


Minimum Requirements

  • 2-4+ years of experience in application security and vulnerability research
  • Strong foundation in mobile app security - Android or Ios
  • Proven track record of discovering and disclosing CVEs in mobile platforms or popular applications (provide - github/bug bounty profiles)
  • Strong understanding of exploit mitigations and proven ability to bypass them
  • Should be able to architect automated detection logic for new vulnerabilities and integrate them into our security products
  • Develop AI-driven agents to automate dynamic analysis
  • Should be able to Leverage AI/LLMs to augment Pentesting efforts
  • Ability to work independently in a fast-paced environment, balancing deep research with practical deliverables


Good to have Requirements

  • Understanding of AI/ML security risks


Responsibilities

  • Security assessment of web/mobile applications on various platforms
  • Focusing on Mobile Application Security Research for new vulnerabilities
  • Static and Dynamic Code Analysis
  • Develop and interpret security standards and guides
  • Automation of exploit development 
  • Understand and explain the results with impact on business and compliance status
  • Continuously learning and training on latest tools and technique


Work Expectations

Within 1 month

Training on processes, security workflows and develop understanding on internal tools.


Within 3 months

Actively contributing in exploit development and automation of it with the team.


Within 6 months

Expected to achieve Subject Matter Expert status on our core security products. We expect you to validate your findings against real-world conditions, with a strong emphasis on translating internal discoveries into actionable bug bounty submissions and earned CVEs to benchmark your impact against the external security community.


Within 1 Year

By the end of your first year, you will be expected to produce and submit a piece of novel, peer-reviewed security research. This deliverable must be of a quality suitable for top-tier industry conferences.


Personality traits we really admire

  • A confident and dynamic working persona, which can bring fun to the team, and a sense of humour, is an added advantage.
  • Great attitude to ask questions, learn and suggest process improvements.
  • Has attention to details and helps identify edge cases.
  • Highly motivated and coming up with fresh ideas and perspectives to help us move towards our goals faster.
  • Follow timelines and absolute commitment to deadlines.


Interview Process - would be team specific

  • Round 1- CTF round 
  • Round 2 -Profile Evaluation; HR
  • Round 3 -Technical Interview with security team members
  • Round 4 -Technical Interview with the Hiring Manager
  • Round 5 -Technical round with CTO
  • Round 6 -HR Round


Compensation

  • As per Industry Standards


Why Join Us

  • Freedom & Responsibility: If you are a person who enjoys challenging work & pushing your boundaries, then this is the right place for you. We appreciate new ideas & ownership as well as flexibility with working hours.
  • Great Salary & Equity: We keep up with the market standards & provide pay packages considering updated standards. Also as Appknox continues to grow, you’ll have a great opportunity to earn more & grow with us. Moreover, we also provide equity options for our top performers.
  • Holistic Growth: We foster a culture of continuous learning and take a much more holistic approach to train and develop our assets: the employees. We shall also support you all on that journey of yours.
  • Transparency: Being a part of a start-up is an amazing experience, one of the reasons being open communication & transparency at multiple levels. Working with Appknox will give you the opportunity to experience it all first-hand.


Read more
company logo
Sandhiya M
Posted by Sandhiya M
Chennai
1 - 5 yrs
₹2L - ₹8L / yr
ISO9001
ISO27001
Security Information and Event Management (SIEM)
Cyber Security
skill iconAmazon Web Services (AWS)
+4 more

Hi Folks, we are currently Hiring for Security Engineer.

Gemini said


Hiring: Security Engineer

Company : Pentabay Softwares

Location : Anna salai, Mount Road

Mode: Fulltime


Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.


The Mission

You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.


Key Responsibilities


Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.

Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.

DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.

Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.

Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.


What You Bring


Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).

Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).

Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.

Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).

Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.

Auditing space like ISO27001 , ISO9001 prefered


Why Pentabay?

At Pentabay, we offer more than just a job; we offer a security-first engineering culture.

Growth: A dedicated learning budget for certifications and conferences.

Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.


Send resumes to : sandhiya.m at pentabay.com

Read more
company logo
Vandana Saxena
Posted by Vandana Saxena
Pune, Bengaluru (Bangalore), Noida, Hyderabad, Chennai, trivendam, Chandigarh, Kolkata, Mumbai
5 - 8 yrs
₹12L - ₹18L / yr
Vulnerability assessment
Vulnerability management
Burp suite
Fortify
sonarqube
+2 more

Responsibilities

  • Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
  • Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
  • Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
  • Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
  • Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
  • Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
  • Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
  • Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
  • Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
  • Provide input into policies and standards related to application and cloud security controls.


Qualifications and Education Requirements

  • Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
  • 5-7 years of relevant experience in application security and/or vulnerability management.
  • Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
  • Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
  • Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
  • Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
  • Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
  • Excellent documentation, communication, and stakeholder engagement skills.


Desired Skills

  • Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
  • Experience using the ServiceNow platform for vulnerability or incident tracking.
  • Proficiency in Azure cloud and Azure DevOps environments.
  • Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.
Read more
company logo
amit verma
Posted by amit verma
Remote only
5 - 15 yrs
₹30L - ₹70L / yr
Cyber Security
Web application security
Penetration testing
skill iconPython
skill iconJava
+2 more

Cybersecurity Engineer – AI Training Project


About the Opportunity

We’re looking for experienced Cybersecurity Engineers to contribute technical expertise to a customer project focused on improving the capabilities of next-generation AI systems.

In this role, you’ll use your real-world experience in cybersecurity, software engineering, vulnerability assessment, and secure development to create high-quality technical inputs that help AI systems better understand, debug, secure, and reason about complex software.


What You’ll Do

  • Analyze, debug, and resolve software bugs, vulnerabilities, and security issues across complex codebases.
  • Review source code and identify potential security weaknesses, vulnerabilities, and attack vectors.
  • Perform security assessments, vulnerability assessments, penetration testing, and codebase audits.
  • Develop and modify software using languages such as Python, Java, Rust, Go, C++, or TypeScript.
  • Implement new features and fix existing functionality while maintaining strong security and engineering standards.
  • Refactor legacy code to improve security, maintainability, reliability, and performance.
  • Work on backend systems and help optimize applications for scalability, performance, and security.
  • Analyze real-world security scenarios and translate your expertise into high-quality technical examples and problem-solving tasks.
  • Document technical findings, vulnerabilities, debugging approaches, and recommended solutions.
  • Provide domain expertise that helps improve how AI systems reason about software engineering and cybersecurity problems.


What We’re Looking For

  • Strong professional experience in Cybersecurity / Application Security / Product Security / DevSecOps / Penetration Testing / Vulnerability Management.
  • Strong programming experience in one or more of:
  • Python
  • Java
  • Rust
  • Go
  • C++
  • TypeScript
  • Proven experience with debugging, troubleshooting, and fixing complex software issues.
  • Hands-on experience with penetration testing, vulnerability assessment, security auditing, or application security.
  • Understanding of secure software development practices and modern security threats.
  • Strong knowledge of data structures, algorithms, software architecture, and code quality.
  • Ability to review unfamiliar codebases and quickly understand how systems work.
  • Strong written communication and the ability to explain complex technical findings clearly.


Nice to Have

  • Experience with OWASP, API security, cloud security, DevSecOps, or threat modeling.
  • Experience performing security assessments on production applications or enterprise systems.
  • Experience with tools such as Burp Suite, Metasploit, Nmap, Wireshark, SAST/DAST tools, or vulnerability scanners.
  • Contributions to open-source security or software projects.
  • Experience working with AI/ML systems, LLMs, data annotation, or AI training projects.
  • Relevant security certifications such as OSCP, OSWE, CEH, CISSP, Security+, or equivalent practical experience.


Engagement

  • Role: Cybersecurity Engineer
  • Work: Remote(Contract)
  • Experience: Mid-level to Senior
  • Programming: Required
  • Cybersecurity expertise: Required


Why Join?

This is an opportunity to apply your existing cybersecurity expertise to an emerging area of technology. Your practical experience debugging software, identifying vulnerabilities, securing applications, and solving complex engineering problems will directly contribute to improving the capabilities of next-generation AI systems.


If you enjoy breaking down complex technical problems, finding vulnerabilities, fixing software, and thinking deeply about how systems work, this project could be a strong fit.

Read more
company logo
Zeeshan Sheikh
Posted by Zeeshan Sheikh
Kolkata
6 - 10 yrs
₹4L - ₹5L / yr
Cyber Security
Security Information and Event Management (SIEM)
Network Security
Information security management system
Information security

A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.

Key Responsibilities

  • Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
  • Conduct vulnerability assessments, penetration testing, and risk analysis.
  • Monitor and respond to security incidents, ensuring timely resolution and documentation.
  • Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
  • Collaborate with IT and business teams to integrate security into system architecture and processes.
  • Lead incident response drills and disaster recovery planning.
  • Provide guidance and mentorship to junior cybersecurity staff.
  • Stay updated on emerging threats, tools, and technologies.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
  • 5–10 years of proven experience in cybersecurity engineering or related roles.
  • Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
  • Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
  • Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.

Skills

  • Advanced problem-solving and analytical skills.
  • Strong communication and leadership abilities.
  • Ability to manage complex projects and handle escalations effectively.
  • Proactive mindset with adaptability to evolving cyber threats.


Read more
company logo
Neha Daka
Posted by Neha Daka
Indore
4 - 8 yrs
₹3.5L - ₹10L / yr
ApplicationSecurity,Cybersecurity, DevSecOps,CI/CD
DAST
SAST
Cloud Computing

Job Title: AppSec / AI Security Engineer


Employment Type: Full-time/ Permanent

Location: Indore (Work from Office)


About the Role

We're embedding security and AI governance into the core of our software development lifecycle. This role owns the design and implementation of automated security scanning, code provenance, and governance processes to ensure AI-generated code meets the highest security and compliance standards.

If you're a self-driven engineer who enjoys building security automation from the ground up and weaving security seamlessly into development pipelines, this role is for you.

 

Key Responsibilities

  • Build and integrate security controls into CI/CD pipelines — including automated scanning for source code, dependencies, secrets, and Infrastructure as Code (IaC) — with enforcement gates on every merge.
  • Design and implement code provenance tracking to capture AI-generated code, the AI models used, and reviewer approvals as part of the development pipeline.
  • Develop structured code review workflows incorporating specifications, scan results, and code provenance.
  • Optimize security scanning tools to reduce false positives and drive developer adoption.
  • Investigate and manage security findings using established remediation and documentation processes.
  • Contribute to AI governance standards, including secure usage of AI tools and governance of AI-generated code.
  • Conduct independent security reviews of internally developed, third-party, and vendor-supplied code to ensure compliance with security standards.


Required Skills & Experience

  • Strong hands-on experience in Application Security, with proven expertise securing CI/CD pipelines.
  • Experience implementing automated security scanning and enforcement — not just operating existing tools.
  • Strong knowledge of SAST, SCA, secret scanning, DAST, and IaC security scanning.
  • Strong understanding of cloud infrastructure, with hands-on or working knowledge of AWS and Azure, is preferred.
  • Ability to design, build, and own security automation and governance solutions from the ground up.
  • Strong judgment in balancing security with developer productivity by minimizing unnecessary alerts.
  • Excellent communication skills, with the ability to explain security risks in clear, business-friendly language.
  • Strong analytical mindset and ability to independently assess security risk across internal and external codebases.


Preferred Qualifications

  • ~4+ years of experience in Application Security, Security Engineering, DevSecOps, or a related field.
  • Experience with AI-generated code security, LLM security risks, prompt injection, code provenance, or AI governance.
  • Hands-on experience with tools such as Semgrep, CodeQL, Snyk, Gitleaks, TruffleHog, Prowler, Trivy, or similar.
  • AWS certification (Solutions Architect Associate preferred), or willingness to obtain one within 90 days.
  • Security certifications such as OSCP, GWAPT, CSSLP, or equivalent.
  • Experience writing custom detection rules or security policies (e.g., custom Semgrep rules).


About Company:

Five Exceptions Software Solutions Private Limited is an offshore software development company run by a 15+ year experience team. We are a software development team with extensive experience in developing amazing products, websites, and mobile apps. The company has expertise in different technology spectrums. We provide a better work environment to grow technically and professionally.

 

For more info, please visit our website:  https://5exceptions.com

Read more
company logo
Faisal AshrafNomani
Posted by Faisal AshrafNomani
Bengaluru (Bangalore), Chennai
5 - 15 yrs
Best in industry
DevOps
skill iconAmazon Web Services (AWS)

DevOps & Cloud Security Specialist to architect enterprise-grade AWS networking, implement strict IAM security boundaries (HIPAA/GDPR compliance), automate infrastructure via IaC, and maintain crystal-clear technical documentation.


1. Primary Must-Have Competencies (Core Priorities)


A. AWS Networking & VPC Topology (Top Priority)

  • Advanced VPC Architecture: Mastery in designing multi-VPC topologies, isolated subnets, custom Route Tables, NAT Gateways, Transit Gateways, and Cross-Region VPC Peering.
  • Private Network Security: Extensive experience using VPC Endpoints (Gateway & Interface/PrivateLink) to keep internal AWS traffic completely off the public internet.
  • Traffic Ingestion & Edge Security: Expertise in AWS WAF (custom rules, bot control, rate limiting), API Gateway throttling, ALB configuration, and Route 53 global routing.


B. AWS Security, IAM Architecture & Compliance

  • Enterprise IAM Governance: Expertise in AWS Organizations, IAM Identity Center (SSO), Permission Boundaries, Service Control Policies (SCPs), and temporary role assumption across multi-account setups.
  • Data Protection & Key Management: Deep knowledge of AWS KMS (customer-managed keys, envelope encryption at rest and in transit) and AWS Secrets Manager.
  • Audit & Compliance: Setting up centralized logging pipelines (CloudTrail, GuardDuty, AWS Config, CloudWatch Audit Logs) for strict HIPAA/GDPR compliance.


C. Infrastructure as Code (IaC) & Containerization

  • Terraform / AWS CDK: Must write production-grade, modular IaC templates from scratch—enforcing network topology and security guardrails directly in code.
  • Container Orchestration: Hands-on setup and management of AWS ECS (Fargate) or EKS (Kubernetes) and automated CI/CD pipelines (GitHub Actions, GitLab CI).


D. Architecture Documentation & Systems Mapping

  • Technical Documentation: Ability to author clean, standardized architecture diagrams (e.g., C4 model, Draw.io, Lucidchart) and maintain comprehensive runbooks, incident response plans, and compliance documentation.


2. Secondary Competency (Strong Advantage, Not Mandatory)

  • Backend Software Development: Hands-on experience or a background in writing/debugging backend code in Node.js, Python, or Go.
  • Note: The primary responsibility is cloud infrastructure, security, and automation. However, the ability to read backend code, debug API bottlenecks, or assist developers with microservice integrations is a major bonus.

 

Read more
company logo
Mayank Choudhary
Posted by Mayank Choudhary
icon

The recruiter has not been active on this job recently. You may apply but please expect a delayed response.

Bengaluru (Bangalore)
3 - 7 yrs
₹40L - ₹45L / yr
Cloud security

Strong Product Security Engineer / Security Engineer / Application Security Engineer / DevSecOps Engineer profiles

2

Mandatory (Experience 1) – Must have minimum 4+ years of hands-on Application/Product Security or Security Engineering experience,

3

Mandatory (Experience 2) – Strong hands-on experience in AWS Cloud Security, Infrastructure Security, and Application Security, with the ability to identify and address security risks at the application/code level.

4

Mandatory (Experience 3) – Must have hands-on experience in secure SDLC/DevSecOps, including code review, API security, CI/CD security automation, vulnerability management, VAPT/penetration testing, and security tooling.

5

Mandatory (Experience 4) – Must have hands-on experience with security audits and compliance frameworks, including SOC 2, GDPR, and ISO 27001, preferably having participated in or driven audits.

6

Mandatory (Experience 5) – Experience setting up, managing, and tracking security tools such as MDM, endpoint agents, security monitoring/scanning tools, secrets/access management, and related security tooling.

7

Mandatory (Experience 6) – Must demonstrate strong coding/development understanding with the ability to read/write code and assess security of APIs, applications, databases, and distributed systems; not just operate security tools.

8

Preferred (Experience 1) – Relevant security certifications such as CISSP, CEH, OSCP, or equivalent.

Read more
company logo
CyberAlpha ConsultingLLP
Posted by CyberAlpha ConsultingLLP
Noida
2 - 6 yrs
₹3L - ₹6L / yr
GRC
PCI DSS
ISO/IEC 27000-series

Job Summary

We are looking for a Senior Compliance Analyst to manage and support cybersecurity compliance, GRC, risk assessments, audits, and client engagements. The candidate will evaluate security controls, identify compliance gaps, review evidence, and provide practical recommendations.


Key Responsibilities

  • Conduct Compliance Audits, Gap Assessments, and Risk Assessments.
  • Assess controls against ISO 27001, SOC 2, PCI DSS, ISO 27701, ISO 42001, HIPAA, GDPR, DPDP, etc.
  • Review policies, procedures, controls, and audit evidence.
  • Identify gaps, risks, observations, and recommend remediation.
  • Prepare Risk Registers, SoA, Control Matrices, Audit Reports, and Compliance Reports.
  • Support clients during certification, surveillance, and external audits.
  • Conduct client meetings, interviews, and control walkthroughs.
  • Coordinate evidence collection and remediation tracking.
  • Develop and review information security policies and procedures.
  • Stay updated with cybersecurity standards, regulations, and best practices.


Required Skills

  • Strong understanding of Information Security, GRC, Risk & Compliance.
  • Good knowledge of ISO 27001:2022 and SOC 2.
  • Understanding of cybersecurity controls, IT infrastructure, cloud security, IAM, vulnerability management, and security operations.
  • Strong analytical, documentation, communication, and report-writing skills.
  • Ability to independently manage client engagements.


Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field.
  • 2–6 years of relevant experience in GRC, IT Audit, Cybersecurity Compliance, or Consulting.
  • Certifications such as ISO 27001 LA/LI, CISA, CISSP, CRISC, or relevant GRC certifications are preferred.


Read more
Why apply to jobs via Cutshort
people_solving_puzzle
Personalized job matches
Stop wasting time. Get matched with jobs that meet your skills, aspirations and preferences.
people_verifying_people
Verified hiring teams
See actual hiring teams, find common social connections or connect with them directly.
ai_chip
Move faster with AI
We use AI to get you faster responses, recommendations and unmatched user experience.
Did not find a job you were looking for?
icon
Search for relevant jobs from 10000+ companies such as Google, Amazon & Uber actively hiring on Cutshort.
companies logo
companies logo
companies logo
companies logo
companies logo
Get to hear about interesting companies hiring right now
Company logo
Company logo
Company logo
Company logo
Company logo
Linkedin iconFollow Cutshort
Users love Cutshort
Read about what our users have to say about finding their next opportunity on Cutshort.
Shubham Vishwakarma's profile image

Shubham Vishwakarma

Full Stack Developer - Averlon
I had an amazing experience. It was a delight getting interviewed via Cutshort. The entire end to end process was amazing. I would like to mention Reshika, she was just amazing wrt guiding me through the process. Thank you team.
Companies hiring on Cutshort
companies logos