Responsibilities
- Conduct vulnerability assessments and penetration tests on systems, networks, and applications.
- Investigate, analyze, and respond to security incidents and threats in a timely manner.
- Keep abreast of the latest security trends, threat intelligence, and best practices.
- Provide guidance and support to other teams and stakeholders on security-related matters.
- Regularly review and update security measures, tools, and processes to stay ahead of evolving threats.
- Lead or support security-related projects, such as implementing new security tools or technologies.
- Analyze security metrics and trends to identify areas for improvement and adjust strategies accordingly.
- Review product designs and system architectures to identify security risks early and define appropriate security requirements using threat modeling techniques.
- Perform source code reviews to detect security flaws and potential vulnerabilities before deployment.
- Design and implement security controls and technical solutions to reduce identified risks across applications and infrastructure.
- Integrate automated security checks and testing into CI/CD pipelines to ensure consistent and scalable security practices.
- Monitor systems, logs, and alerts to identify, investigate, and respond to suspected security incidents in accordance with incident response procedures.
- Maintain and evolve security standards for web and mobile technologies to keep pace with emerging threats.
- Educate and support engineering teams through guidance, workshops, and secure coding best practices.
- Collaborate with information security personnel, auditors, and other stakeholders on technical security matters and risk assessments.
Requirements
- At least 3-5 years of experience in information security, network security, or similar role
- Hands on experience with threat and vulnerability management
- Strong knowledge of security concepts, principles, and best practices.
- Proficiency in network and system security, including firewalls, IDS/IPS, and VPNs.
- Experience with vulnerability assessments, penetration testing, and security auditing tools.
- Familiarity with security frameworks and regulations (e.g., NIST, ISO 27001, GDPR)
Nice to haves
While not specifically required, tell us if you have any of the following.
- Knowledge of cloud security concepts and experience working with cloud platforms (e.g., AWS, GCP).
- Familiarity with secure coding practices and experience with application security testing tools and methodologies.
- Proficiency in one or more programming or scripting languages (e.g., Python, JavaScript, Golang) for automation and custom tool development.
- Experience leading, executing or coordinating security-related projects.
- Relevant professional certifications such as CISSP, CEH, CompTIA Security+, or GIAC.