
Lead Security Engineer
Huron Consulting Group6 months ago
Bengaluru, IndiaStaff+
Responsibilities
- Perform application security assessments across web, API, and internal applications using OWASP methodologies and industry frameworks.
- Conduct DAST, SAST, and manual secure code reviews to identify vulnerabilities and insecure coding practices.
- Provide remediation guidance to development and application teams and retest fixes.
- Conduct vulnerability scanning, monitoring, reporting, validation, prioritization, and remediation tracking using Tenable and related tools.
- Design, develop, and execute penetration testing plans across applications, networks, cloud, and infrastructure environments.
- Develop and maintain custom scripts and security tools for penetration testing, automation, and validation.
- Support security reviews, threat analysis, malware analysis, security research, and continuous security improvement initiatives.
- Document findings and communicate security risks and remediation recommendations to technical and non-technical stakeholders.
Requirements
- Bachelor's or master's degree in computer science or a related field, or related field experience.
- Experience with Burp Suite, OWASP ZAP, and other application security assessment tools.
- Experience performing secure code reviews and static analysis using tools or manual methods.
- Strong hands-on experience with vulnerability assessment and penetration testing.
- Experience with Tenable, including Nessus, Tenable.sc, or Tenable.io, and tools such as Nmap and Metasploit.
- Understanding of network, application, endpoint, and infrastructure security.
- Proficiency in scripting or programming, such as Python, Bash, or PowerShell, for custom security tools and automation.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, authentication mechanisms, and common attack techniques.
- Ability to document findings and communicate risks clearly to technical and non-technical stakeholders.
- Knowledge or experience in threat intelligence, malware analysis, or reverse engineering is preferred.