Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cybersecurity Engineer based in India.
This is a hands-on cybersecurity role focused on strengthening product and enterprise security across a modern technology environment.
You will combine penetration testing, threat modeling, secure architecture reviews, and security automation to identify and reduce risk.
The role partners closely with Engineering, Product, Architecture, DevOps, and Operations teams throughout the SDLC.
You will help embed security-by-design principles and DevSecOps practices into development and deployment workflows.
Your work will span web applications, APIs, cloud environments, infrastructure, containers, and modern distributed architectures.
The position offers significant opportunity to influence security strategy while remaining deeply involved in technical execution.
This is an ideal opportunity for a security-minded engineer who enjoys thinking like an attacker while enabling teams to build resilient products.
Accountabilities:
- Conduct manual and automated penetration testing across web applications, APIs, cloud environments, and supporting infrastructure, validating security controls and identifying vulnerabilities.
- Lead threat modeling exercises for new and existing products, identifying attack paths, risks, and appropriate mitigations using methodologies such as STRIDE, PASTA, or equivalent frameworks.
- Perform secure design and architecture reviews and promote security-by-design principles throughout the Software Development Lifecycle.
- Evaluate application, cloud, and infrastructure security controls and translate findings into practical, actionable remediation recommendations.
- Partner with Engineering, Product, Architecture, and DevOps teams to prioritize, track, and remediate security findings while promoting secure coding practices.
- Integrate security testing and validation into CI/CD pipelines, enabling automated security checks and continuous risk identification.
- Develop and maintain security tooling, scripts, and automation to improve the efficiency, scalability, and coverage of security assessments.
- Support vulnerability management activities, including risk assessment, validation, remediation guidance, and verification of fixes.
- Contribute to security standards, secure development guidelines, governance processes, and product security initiatives.
- Provide technical guidance and mentorship to engineering teams on secure design, threat mitigation, and security best practices.
- Support security audits, compliance initiatives, and evidence collection related to product and application security controls.
- Monitor emerging threats, vulnerabilities, attack techniques, and security technologies and apply relevant developments to improve security capabilities.
- Drive continuous improvement across Product Security and DevSecOps practices through automation, innovation, and adoption of industry-leading approaches.
- Be available to work a European shift from 1:00 PM to 10:00 PM
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related technical discipline, or equivalent practical experience.
- 5+ years of experience in cybersecurity, application security, product security, security engineering, or a related field.
- Demonstrated experience with manual and automated penetration testing of web applications, APIs, cloud environments, and infrastructure.
- Strong experience in threat modeling and security architecture reviews using STRIDE, PASTA, ATT&CK, or equivalent methodologies.
- Strong knowledge of secure software development, common attack techniques, OWASP Top 10, and API Security Top 10.
- Experience identifying, validating, prioritizing, and communicating security risks to both technical and non-technical stakeholders.
- Proficiency in at least one programming or scripting language such as Python, Java, JavaScript, C#, PowerShell, or Go.
- Experience working in Agile development environments and embedding security practices into the SDLC.
- Strong understanding of DevSecOps and experience integrating security tooling into CI/CD pipelines.
- Experience assessing and securing cloud environments such as AWS, Azure, or Google Cloud Platform.
- Knowledge of modern architectures including microservices, APIs, containers, Kubernetes, and serverless technologies.
- Familiarity with SAST, DAST, SCA, container security, and Infrastructure-as-Code security tools.
- Experience developing security automation, custom tooling, or pipeline integrations.
- Knowledge of secure architecture patterns, identity and access management, cryptography, and zero-trust concepts.
- Experience supporting regulatory, compliance, or audit requirements, particularly in highly regulated industries such as healthcare, life sciences, or financial services.
- Strong analytical, problem-solving, communication, collaboration, and stakeholder-management skills.
- Ability to independently lead security initiatives while working effectively across Engineering, Product, Architecture, and Operations.
- A security-first mindset with the ability to think like an attacker while partnering constructively with development teams.
- Curiosity, self-motivation, and a commitment to continuous learning in emerging security technologies and attack techniques.
- Experience building or operating Product Security programs, leading enterprise-wide threat modeling initiatives, conducting adversarial assessments, or creating secure coding standards and developer enablement programs is highly valued.
- Familiarity with AI-assisted security analysis, remediation workflows, or security engineering automation is an advantage.
- Relevant certifications such as OSCP, OSWE, GWAPT, GWEB, CISSP, CCSP, or AWS/Azure/GCP security certifications are valued.
Benefits
- Competitive compensation.
- Provident fund.
- Medical insurance.
- Flexible remote work environment.
- Engaging employee programs and local events.
- Opportunity to work on modern cybersecurity, cloud, application security, and DevSecOps initiatives.
- Exposure to complex security challenges across applications, APIs, infrastructure, and enterprise environments.
- Opportunities to collaborate with cross-functional engineering, product, architecture, and operations teams.
- Professional growth through hands-on security engineering, automation, threat modeling, and security program development.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1