Job Summary
We are seeking a highly skilled Senior Security Engineer with strong expertise in penetration testing, vulnerability management, and infrastructure security. The ideal candidate will be responsible for identifying security risks, securing cloud and on-prem environments, and driving remediation efforts across enterprise systems.
This role requires hands-on experience in offensive security (pentesting) along with defensive security practices across cloud, network, and enterprise infrastructure.
Key Responsibilities
1. Penetration Testing & Security Assessments
- Conduct penetration testing across:
- Web applications
- Network infrastructure
- Cloud environments (AWS/Azure)
- Perform vulnerability assessments and risk analysis
- Identify security weaknesses and provide remediation recommendations
2. Vulnerability Management
- Lead end-to-end vulnerability management lifecycle
- Track, prioritize, and validate remediation efforts
- Collaborate with IT and DevOps teams to resolve vulnerabilities
3. Cloud & Infrastructure Security
- Secure cloud platforms:
- AWS
- Azure
- Hybrid environments
- Implement security best practices for:
- Compute, storage, networking
- Identity and access management (IAM)
4. Security Operations & Incident Response
- Support incident detection, analysis, and response
- Work with SOC teams on threat analysis and mitigation
- Investigate security incidents and recommend corrective actions
5. Security Hardening & Compliance
- Implement system and network hardening standards
- Ensure compliance with security frameworks such as:
- NIST
- CIS
- ISO 27001
- SOC 2
- Conduct security audits and reviews
Required Skills & Expertise
Core Skills
- Penetration Testing & Ethical Hacking
- Vulnerability Assessment & Risk Management
- Cloud Security (AWS / Azure)
- Network Security & Firewall Concepts
- Windows/Linux & Active Directory Security
Tools & Technologies
- Vulnerability Scanners (e.g., Nessus, Qualys)
- SIEM Tools (e.g., Splunk, QRadar)
- EDR/XDR Solutions
- Security Testing Tools (Burp Suite, Metasploit, Nmap, etc.)
Frameworks & Standards
- NIST Cybersecurity Framework
- CIS Benchmarks
- ISO 27001
- SOC 2
Preferred Certifications
- OSCP (Offensive Security Certified Professional)
- CEH (Certified Ethical Hacker)
- CISSP
- GPEN
- CompTIA Security+
- AWS Security Specialty
- Azure Security Engineer (AZ-500)
Candidate Requirements
- Total Experience: 5+ years
- Relevant Experience in Security: 3+ years
…