Sr. Security Consultant (L3) – Netskope & Proofpoint at Service Based · Pune, Pimpri, Mumbai · 8 - 15 years · ₹15L - ₹25L / yr · Posted 29 Jul 2026

Sr. Security Consultant (L3) – Netskope & Proofpoint
at Service Based
Hiring: Sr. Security Consultant (L3) – Netskope & Proofpoint 🚨
📍 Location: Pune (Work from Office)
💼 Experience: 8+ Years
⏳ Notice Period: Immediate Joiners or candidates with up to 30 days' notice period only
We are hiring an experienced Sr. Security Consultant (L3) with strong expertise in Netskope and Proofpoint Email Security.
Mandatory Skills:
✔️ Netskope
✔️ Proofpoint Email Security
✔️ CASB
✔️ DLP (Data Loss Prevention)
✔️ Web Security / Secure Web Gateway (SWG)
Additional Skills:
• RBI • PAC • Proxy • SSL/TLS • VPN • DMARC • SPF • DKIM • Palo Alto • FortiGate

Similar jobs (10)
Job Title: Technical Consultant – Netskope & SSE (L3 Engineer)
Company: Inflow Technologies
Location: Bangalore (Work From Office, 5 days/week)
About Inflow Technologies:
Inflow Technologies, founded in 2005 and headquartered in Bangalore, is a leading value-added IT infrastructure distributor across Networking, Cybersecurity, Unified Communications, AIDC, Surveillance, Server, Storage, and Software. With 20+ locations across India/South Asia and a 120+ member certified technical team, Inflow supports channel partners through the full solution sales cycle. Annual run-rate revenue: USD 700+ Million.
Position Overview:
We're looking for an experienced Technical Consultant (L3 Engineer) specializing in Netskope and Security Service Edge (SSE) technologies. You'll own end-to-end architecture, design, deployment, and optimization of cloud security solutions — acting as a trusted advisor who translates business requirements into secure, scalable technical architectures, and resolves advanced issues through root cause analysis.
Key Responsibilities:
Implementation & Deployment
- Deploy Netskope CASB (API + Proxy), SWG, DLP (Email/Web/Network), ZTNA (Private Access), NPA, and Prime Advantage package
- Configure traffic steering (Client, GRE, IPsec), policy rules (DLP, URL filtering, access control), and dashboard fine-tuning
- Perform agent rollout across Windows, Mac, and Mobile
Architecture & Design
- Design a secure access architecture for remote users, branch offices, and cloud workloads
- Integrate with identity providers (Azure AD, Okta) and existing security stack (Firewall, Proxy, SIEM)
- Integrate Netskope with SIEM (Splunk, QRadar), EDR tools, and email security
- Configure SSO/SAML authentication
Required Qualifications:
- Bachelor's degree in IT/CS or related field
- 6–8 years of experience (L3 level)
- Preferred certifications: Netskope Certified Cloud Security Architect (NCSA), NSK 100/200/300, CCNA/Security+ (good to have)
Interview Process: 2 rounds (Virtual) + Final round (Face-to-Face)
Position: Technical Lead – Forcepoint (Data & Cloud Security)
Company: Inflow Technologies
Location: Bangalore
Work Mode: Work From Office | 5 days/week
Experience Required: Minimum 6 years
Interview Process: 2 rounds (Virtual + Final Face-to-Face)
About Inflow Technologies
Founded in 2005, Inflow is a value-added IT infrastructure distributor covering Networking, Cybersecurity, UC&C, AIDC, Surveillance, Server, Storage & Software across India/South Asia. HQ'd in Bangalore with 20+ locations, backed by a 120+ certified technical team, and ~USD 700M+ annual run-rate revenue.
Position Overview
Acting as the Forcepoint subject matter expert, this role owns end-to-end design, deployment, and troubleshooting of enterprise data and cloud security architectures — spanning DLP, SWG, CASB, and SSE/ZTNA. The role sits at the intersection of solution architecture and hands-on L3 execution: defining security policies, configuring network proxies, and resolving complex support escalations in a client-facing, consultative capacity.
Core Products
- Forcepoint DLP (Endpoint, Network, Web, Email)
- Forcepoint Web Security
- Forcepoint Email Security
- Forcepoint CASB
- Forcepoint Suite / Forcepoint One
- Forcepoint Cloud Security / SSE (incl. ZTNA)
- Forcepoint DSPM
Key Responsibilities
1. Solution Design & Architecture
- Design enterprise architectures: DLP (Endpoint + Network + Discovery), Web Security (Proxy/Hybrid/Cloud), CASB & SaaS protection, Forcepoint Suite/One
- Install & configure Management Server, Policy Engine, Detection Servers, Protectors (Email/Web/Network), Endpoint agents (Windows/Mac)
- Implement EDM/IDM/OCR and data classification policies
2. Web Security (SWG)
- Deploy on-prem (V-series appliances) and cloud SWG/hybrid mode
- Configure transparent/explicit proxy, SSL inspection, URL filtering
3. Email Security
- Configure SMTP routing, DLP email policies, encryption & compliance rules
4. Advanced Policy Configuration
- Design/tune DLP policies (structured + unstructured data), web filtering (user/group/app-based), cloud app governance rules
5. L3 Troubleshooting & RCA (Critical)
- Handle: DLP not detecting over HTTPS, endpoint agent communication failures, web proxy latency/SSL failures, policy not applying to users, email DLP bypass
- Approach: log analysis (Policy Engine, endpoint, web), packet capture/traffic analysis, root cause identification & permanent fix
Qualifications & Certifications (Preferred)
- Bachelor's degree (IT/CS or related)
- Forcepoint Certified Administrator (FCA)
- Forcepoint DLP Specialist
- CCNA / Security+ (nice-to-have)
Technical Consultant – Cisco SSE
Company: Inflow Technologies
Website: https://inflowtechnologies.com/
Company Details:
Founded in 2005, Inflow Technologies is a niche player in the IT Infrastructure Distribution Services industry, providing Value Added Distribution in Networking, Cyber Security, Unified Communications and Collaboration, AIDC, Surveillance, Server, Storage & Software related Products & Services in India/South Asia. Inflow is headquartered in Bangalore with a presence across 20+ locations, enabling resellers to design, deploy, and adopt IT Infrastructure solutions to facilitate their customers' needs. This initiative, supported by a strong technical team of 120+ certified resources, assists channel partners throughout their sales cycle. Inflow has an annual run-rate revenue of USD 700+ million.
Location: Bangalore
Mode of Working: Work From Office
Days of Working: 5 Days a week
Responsibilities:
Position Overview:
We are seeking a highly skilled and customer-centric Technical Consultant – Cisco SSE (Security Service Edge) to join our team in Bangalore. In this role, you will act as a trusted advisor and hands-on expert, leading the end-to-end design, deployment, and optimization of Cisco's cutting-edge SSE solutions for enterprise clients.
Key Responsibilities:
- Design and implement Cisco SSE solutions for secure user access to cloud and on-prem resources.
- Perform ongoing policy and access control reviews, aligning with Zero Trust principles.
- Troubleshoot SSE-related issues, including secure connectivity, access policies, and traffic routing.
- Lead end-to-end implementation of Cisco SSE solutions for enterprise clients.
- Configure and deploy Cisco (ZTNA, SWG, CASB) in customer environments.
- Work closely with network teams to integrate Cisco SD-WAN and optimize SSE delivery.
- Troubleshoot technical issues during and after implementation, ensuring minimal downtime.
- Conduct knowledge transfer and handover sessions for client IT teams.
- Collaborate with Cisco TAC, account managers, and the partner ecosystem for escalations.
- Document configurations, solution architectures, and SOPs.
- Provide post-deployment tuning, updates, and optimization services.
- Collaborate with IT, Security, and Compliance teams to ensure architecture meets business and regulatory requirements.
- Monitor and optimize network security performance across branch offices, mobile users, and remote workforces.
- Provide technical documentation and training to internal teams.
Skills Needed:
Core Requirements — Education & Experience: Min 6 Years
- Bachelor's degree in Computer Science, Information Technology, or a related field
- 6 to 12 years of experience in network and security engineering
Interview Process: 2 Rounds Virtual and Final Face-to-Face
Technical Consultant – Palo Alto Networks
Company: Inflow Technologies
Website: https://inflowtechnologies.com
About: Founded in 2005, Inflow Technologies is a niche IT Infrastructure Distribution Services player offering Value Added Distribution in Networking, Cybersecurity, UCC, AIDC, Surveillance, Server, Storage & Software across India/South Asia. HQ in Bangalore, 20+ locations, 120+ certified technical resources, USD 700M+ annual run-rate revenue.
Location: Bangalore
Work Mode: Work From Office
Work Days: 5 days/week
Position Overview
Senior-level, high-impact technical role driving architecture, implementation, and optimization of Palo Alto Networks' enterprise security solutions. Acts as SME bridging security engineering and client-facing technical consultation.
Key Responsibilities
- Design, deploy, and optimize Palo Alto NGFW solutions in complex enterprise environments
- Provide L3/L4 escalation support for Palo Alto firewall, Prisma, and Cortex-related issues (PAN-OS)
- Architect and implement: Prisma Access (SASE/ZTNA), Prisma Cloud (CSPM, CWPP, CNAPP), Cortex XDR/XSOAR
- Advanced troubleshooting: traffic flow issues, security policy mismatches, VPN (IPSec/GlobalProtect), threat prevention, URL filtering, SSL decryption
- Lead end-to-end implementation projects (design, deployment, migration, optimization)
- Integrate Palo Alto solutions with SIEM/SOC platforms, IAM (SAML, Azure AD, Okta), and public cloud (AWS, Azure, GCP)
- Manage HA, clustering, and firewall upgrades
- Liaise with Palo Alto TAC for critical issue resolution
- Conduct security assessments, best practice reviews, and performance tuning
- Maintain technical documentation (HLDs/LLDs, SOPs, runbooks)
- Mentor L1/L2 engineers
- Participate in change management, maintenance windows, and incident response
Requirements
- Experience: 6–12 years in network and security engineering (min 6 years)
- Education: Bachelor's degree in Computer Science, Engineering, or related field
Process
- Interview Rounds: 2 Virtual + Final Face-to-Face
Role Overview
We are looking for an experienced Network Security Engineer to design, implement, maintain, and secure enterprise network infrastructure. The role requires a strong understanding of network security principles, hands-on experience with security technologies, and the ability to troubleshoot complex network and security issues.
The ideal candidate will work closely with network, infrastructure, cloud, application, and security teams to ensure secure, resilient, and highly available network environments. The candidate should be comfortable handling security incidents, performing root-cause analysis, implementing security controls, and contributing to continuous improvement of the organization's network security posture.
Key Responsibilities
- Design, implement, configure, and maintain enterprise network security infrastructure.
- Manage and support network security technologies including firewalls, VPNs, IDS/IPS, secure gateways, and network access controls.
- Configure and maintain security policies, access rules, NAT, VPN tunnels, and related network security controls.
- Monitor network traffic and security events to identify potential threats, anomalies, and unauthorized access.
- Troubleshoot complex network connectivity and security-related issues and perform root-cause analysis.
- Investigate and respond to network security incidents in coordination with security and infrastructure teams.
- Review firewall and network security rules regularly and ensure they follow established security standards and business requirements.
- Support secure connectivity across data centers, corporate networks, remote locations, cloud environments, and third-party networks.
- Participate in network security assessments, vulnerability remediation, and security hardening activities.
- Implement and maintain network segmentation and access-control mechanisms.
- Work with internal teams to assess security requirements for new applications, infrastructure, and network changes.
- Participate in change management, implementation, and post-change validation activities.
- Maintain network security documentation, architecture diagrams, configurations, and operational procedures.
- Contribute to security improvement initiatives, automation, standardization, and operational efficiency.
- Work with vendors and technology partners for issue resolution, upgrades, and technical escalations.
- Ensure network security operations align with organizational policies, industry standards, and compliance requirements.
Required Skills
- Strong experience in network security engineering and enterprise networking.
- Good understanding of TCP/IP, DNS, DHCP, HTTP/HTTPS, routing, switching, VLANs, and network protocols.
- Hands-on experience with enterprise firewalls and security gateways.
- Strong understanding of VPN technologies, IPsec, SSL/TLS, NAT, and access-control policies.
- Experience with IDS/IPS, network monitoring, traffic analysis, and security event investigation.
- Experience troubleshooting network and security issues across complex environments.
- Good understanding of network security architecture, segmentation, and secure connectivity.
- Experience with incident management, change management, and root-cause analysis.
- Familiarity with security best practices, vulnerability management, and network hardening.
- Strong analytical, troubleshooting, and problem-solving skills.
- Good written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
Preferred Skills
- Experience with security technologies from vendors such as Palo Alto, Fortinet, Cisco, Check Point, or similar.
- Exposure to cloud networking and cloud security across AWS, Azure, or GCP.
- Knowledge of Zero Trust, SASE, SD-WAN, or network access control concepts.
- Experience with security monitoring/SIEM platforms.
- Exposure to scripting or automation using Python, PowerShell, or similar technologies.
- Relevant certifications such as CCNA/CCNP Security, PCNSE, Fortinet certifications, or equivalent are an advantage.
Key Competencies
- Network Security Engineering
- Enterprise Network Troubleshooting
- Firewall & VPN Management
- Security Incident Handling
- Network Monitoring & Analysis
- Security Hardening
- Root-Cause Analysis
- Risk & Vulnerability Awareness
- Change & Configuration Management
- Stakeholder Communication
- Problem Solving
- Documentation & Process Discipline
IT Systems Engineer
Location: Bengaluru, India · On-site | Experience: 5+ years in IT systems / infrastructure
Department: IT & Information Security | Employment Type: Full-time | Reports To: Engineering Leadership
Focus: Own the identity, endpoints, network, and compliance backbone that powers immersive technology at
scale.
The Mission
About Metadome.ai
Metadome.ai is an immersive 3D & XR technology company that enables cloud-based, photorealistic, and captivating customer experiences for brands. Our technology offers a complete stack for creating immersive 3D & XR applications with omni-channe deployment across both in-store and digital touchpoints, and over a multitude of devices. These experiences span a spectrum of use cases across the automotive, home décor, fashion, and cosmetics & accessories sectors. Our flagship automotive platform — Autodome — enables unprecedented photorealistic, cloud-based immersive 3D & XR applications that cover the entire pre-retail funnel, empowering brands to launch products virtually and drive awareness, engagement, and bookings among modern automotive consumers. Today, we are trusted partners to leading brands across the globe — including Unilever, MG Motor, Lexus, Asian Paints, Tata Motors, and Royal Enfield, among others. We have also partnered with the likes of TCS, SAP , and PwC, and are an active voice in the XR community, including the
Metaverse Standards Forum and the VR/AR Association.
About the Role
We are looking for a hands-on IT Systems Engineer to own and run the technology backbone that keeps our teams productive and our data secure. You will be the single point of accountability for IT operations and information security across a multi-location business where 24x7 systems availability is core to how we operate — managing identity, endpoints, network, and our cloud workspace, while operating and continuously hardening our GDPR, SOC 2, and ISO 27001 compliance posture.
This is a builder-operator role, not a supervisory one. We run a tight ship on security and compliance, and we expect you to have personally implemented and operated the systems and controls described below — you should know them inside out, down to the configuration, the evidence, and the edge cases.
Core Responsibilities
● Identity & Access Management — JumpCloud:
○ Own the JumpCloud directory end-to-end: user lifecycle (joiner / mover / leaver), groups, and organizational structure.
○ Administer SSO, enforce MFA, and configure conditional and device-based access policies across all SaaS applications.
○ Manage cross-platform device policies (macOS, Windows, Linux) via JumpCloud device management, including disk encryption and compliance baselines.
○ Integrate RADIUS / LDAP for Wi-Fi and application authentication.
○ Automate onboarding and offboarding to guarantee least-privilege access and clean, auditable deprovisioning.
● Google Workspace Administration — GWS:
○ Administer the Google Workspace tenant: users, groups, organizational units, and email routing.
○ Configure and enforce security controls — 2-Step Verification, context-aware access, DLP rules,
and sharing / visibility policies.○
○ Manage retention, eDiscovery, and legal holds through Google Vault. Optimize licensing and SaaS spend across Workspace and other portals.
Endpoint & Threat Protection — Sophos:
○ Deploy, configure, and manage Sophos Central (Intercept X / XDR) across all endpoints and
servers.
○ Monitor alerts, triage threats, and lead incident detection, response, and remediation.
○ Maintain endpoint encryption, web / application control, and device-hardening standards.
○ Where Sophos Firewall is in use, manage firewall policies, IPS, and secure remote access.
Network, Firewall & Wi-Fi:
○ Design, configure, and maintain firewalls, VLAN segmentation, VPN, and secure remote access.
○ Administer enterprise Wi-Fi and wired networks (switches, access points), including
RADIUS-backed authentication.
○ Manage LAN / WAN connectivity, ISP relationships, and network performance and uptime.
○ Implement network monitoring, intrusion detection, and centralized logging.
Hardware, Software & Asset Management:
○ Own the full hardware lifecycle — procurement, provisioning / imaging, maintenance, repair, and
decommissioning.
○ Support a mixed fleet of macOS, Windows, and Android devices, including high-performance workstations and XR / VR hardware used by our creative and engineering teams.
○ Maintain an accurate hardware and software inventory and asset register.
○ Manage software deployment, patch management, and license compliance.
Security, Risk & Compliance — GDPR · SOC 2 · ISO 27001:
○ Operate and continuously improve the company's Information Security Management System
(ISMS).
○ Own day-to-day compliance for GDPR, SOC 2 (Type II), and ISO/IEC 27001 — including control
implementation, evidence collection, and continuous monitoring.
○ Conduct risk assessments, internal audits, periodic access reviews, and vendor security / DPA
assessments.
○ Serve as a primary point of contact during external audits and customer security reviews.
○ Maintain security policies, records of processing (RoPA), DPIAs, and incident / breach-response
runbooks.
○ Drive security-awareness and phishing-simulation programs across the organization.
IT Operations & Support:
○ Ensure 24x7 high availability of core systems and meet defined uptime and SLA metrics.
○ Provide escalation-level troubleshooting and support across macOS, Windows, and Android.
○ Manage backups, disaster recovery, and business-continuity testing.
○ Coordinate internal teams and third-party vendors to deliver IT projects on time and within
budget.
○ Maintain documentation, runbooks, and standard operating procedures.
○ Own and report on the IT budget and asset allocation.
Required Skills & Experience
● 5+ years in IT systems / infrastructure engineering — with direct, hands-on ownership of the systems
below rather than purely supervisory exposure.
● JumpCloud — demonstrated hands-on expertise across identity, SSO, MFA, and device management.
● Google Workspace (GWS) — deep admin-console experience including security, DLP , and Vault.
● Sophos — hands-on endpoint / XDR administration and threat response.
● Networking — firewall configuration, Wi-Fi, VLANs, VPN, LAN / WAN, and RADIUS / LDAP fundamentals.
● GDPR, SOC 2 & ISO 27001 — hands-on — you have personally taken an organization through at least one
full audit / certification cycle and know the controls, evidence, and auditor expectations inside out.
Cross-platform support — proven troubleshooting across macOS, Windows, and Android in a 24x7, multi-location environment.
System security — solid grasp of IDS / IPS, endpoint hardening, encryption, and backup / recovery.
Education — B.Sc. / B.Tech in Information Technology, Computer Science, or a related discipline.
Mindset — strong documentation discipline, ownership, resourcefulness, and a structured, problem-solving approach.
Preferred Qualifications
●Relevant certifications — e.g., ISO 27001 Lead Implementer / Auditor, CompTIA Security+ / Network+, or vendor certifications from JumpCloud and Sophos.
●Experience with compliance-automation platforms such as Sprinto, Vanta, or Drata.
●Scripting and automation for IT operations (Bash, PowerShell, or Python).
●Experience in a fast-paced SaaS or technology company serving enterprise and global clients.
●Familiarity with supporting creative, 3D, or XR workflows and high-performance computing environments.
Why Join Us
You will own the systems and security posture of a company building category-defining immersive technology for some of the world's most recognizable brands. It is a high-trust, high-ownership role with the autonomy to design things properly — and the visibility that comes with keeping a security- and compliance-first business running
flawlessly.
Cyber Security Expert
We are seeking a highly skilled Cyber Security Expert with strong expertise in AI-driven
security tools and ethical hacking techniques. The ideal candidate will safeguard our digital
infrastructure, proactively identify vulnerabilities, and design intelligent defense mechanisms
against evolving cyber threats.
Key Responsibilities
• Threat Analysis: Identify, assess, and mitigate potential risks across systems and
networks.
• AI Security Tools: Deploy and manage AI-based solutions for intrusion detection,
anomaly monitoring, and predictive threat modelling.
• Ethical Hacking: Conduct penetration testing, simulate cyber-attacks, and recommend
remediation strategies.
• Incident Response: Lead investigations, contain breaches, and implement recovery
measures.
• Compliance & Governance: Ensure adherence to data protection laws, industry
standards, and organizational policies.
• Training & Awareness: Educate employees on best practices and emerging threats.
Required Skills & Qualifications
• Proven hands-on experience with AI-powered security platforms (e.g., SIEM, SOAR,
ML-based anomaly detection).
• Strong knowledge of ethical hacking tools (Metasploit, Burp Suite, Kali Linux, etc.).
• Expertise in network security, firewalls, IDS/IPS, and endpoint protection.
• Familiarity with cloud security (AWS, cloud platform).
• Proficiency in scripting languages (Python, Bash, PowerShell) for automation.
• Solid understanding of cryptography, authentication protocols, and secure coding
practices.
We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.
Responsibilities
- Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
- Monitor and respond to security events using SIEM tools as part of SOC operations
- Test application security using Burp Suite and similar tools
- Support ISO 27001 compliance, audits and security policies
- Harden network infrastructure, firewalls and access controls
- Document findings and track fixes with engineering teams
Requirements
- 1+ years of experience in VAPT, SOC or security engineering
- Hands-on experience with Burp Suite and SIEM tools
- Knowledge of the OWASP Top 10 and network security fundamentals
- Exposure to ISO 27001 or similar frameworks
- Certifications such as CEH, OSCP or CompTIA Security+ are a plus
Senior Network Security Engineer – ZTNA (Zscaler, Axis/HPE SSE Focus)
• ZTNA and Zero Trust Implementation: The role involves architecting and deploying ZTNA solutions using platforms like Zscaler and Axis Security, replacing traditional VPNs with identity-aware access, enforcing least-privilege models based on user identity, device posture, and application context, and integrating with identity providers and security tools to secure remote workforces and third parties. Migration from VPN to ZTNA is a key responsibility.
• Network Security Architecture and Operations: The engineer participates in architecture reviews, designs secure environments across data centers, cloud, and edge, provides risk and telemetry analysis, supports audits and compliance, manages SIEM systems, and collaborates with global cybersecurity and infrastructure teams to maintain security posture.
• Technical Expertise and Qualifications: Required qualifications include over 10 years of experience in network security engineering, hands-on expertise with Zscaler (ZIA, ZPA), Axis Security/Aruba SSE, deep knowledge of Zero Trust, SASE frameworks, firewall and proxy technologies, identity integration, cloud security across AWS, Azure, and GCP, and certifications such as CCNP, CCIE, Zscaler certifications, and CISSP or CISM.
• Role Focus and Strategic Importance: The position emphasizes transitioning from traditional network security to identity-driven access security, positioning ZTNA as a core transformation pillar replacing VPNs, aligning with enterprise Zero Trust initiatives, enabling secure hybrid workforces, and balancing expertise in both modern cloud security platforms and traditional network controls.
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com







