
Sr Security Engineer
Kobie Marketing3 months ago
Bengaluru, IndiaSenior
Responsibilities
- Design, implement, and maintain security controls across cloud infrastructure, applications, and network environments.
- Conduct vulnerability assessments, penetration testing, and threat modeling, and remediate identified risks.
- Monitor security events and alerts, investigate incidents, and lead or contribute to incident response and post-incident reviews.
- Embed security best practices into CI/CD pipelines and infrastructure-as-code workflows with Cloud Engineering, DevOps, and application teams.
- Develop and enforce security policies, standards, and compliance frameworks.
- Implement IAM, least-privilege, privileged access management, conditional access, DLP, information protection, and endpoint security controls.
- Evaluate third-party security tools, conduct vendor risk assessments, and review end-user applications and software for compliance.
- Automate security operations including testing, compliance checks, threat detection, triage, and response workflows.
- Maintain runbooks, threat models, risk registers, and other security documentation.
- Advise engineering and product teams on secure design and coding practices.
- Track emerging threats and vulnerabilities, and train or mentor team members on security and compliance practices.
Requirements
- At least 5 years of experience in information security, cybersecurity engineering, or a related technical discipline.
- At least 3 years of hands-on experience securing cloud environments, preferably AWS, including IAM, VPC security, security groups, and cloud-native security services.
- Experience with SIEM platforms, security event monitoring, alerting, and incident response workflows.
- Experience with vulnerability management and conducting or coordinating penetration testing.
- Strong understanding of firewalls, WAFs, IDS/IPS, DNS security, and zero-trust principles.
- Experience with SSO, MFA, OAuth, and privileged access management solutions.
- Hands-on experience integrating security into CI/CD pipelines, including static and dynamic analysis tools and secrets management.
- Familiarity with SOC 2, ISO 27001, NIST CSF v2.0, PCI-DSS, GDPR, and CCPA; knowledge of NIST AI RMF and ISO 42001 is a plus.
- Experience implementing conditional access, DLP, information protection classifications, and endpoint security controls.
- Scripting or automation experience with Python, Bash, or similar technologies, including use of AI-assisted security tools.
- Strong Linux administration skills, preferably with RHEL-based systems.
- Strong analytical, problem-solving, written communication, verbal communication, and stakeholder presentation skills.
- Experience mentoring or developing junior security team members or contributing through training, knowledge transfer, or documentation.
- Relevant certifications such as CISSP, CISM, OSCP, or AWS Security Specialty are a plus.
Benefits
- Competitive benefits, comprehensive health coverage, and well-being perks for teammates and dependents.
- Public holidays, flexible time off, and an emphasis on work-life balance.
- Global collaboration with U.S. teams and exposure to international projects and industry leaders.
- The India Tech Hub will establish a physical office in Bengaluru, India, as the team grows.
- Charitable partnerships, annual fundraising, and volunteer opportunities.
- A collaborative, growth-focused, and diversity-oriented workplace culture.