Sr. security engineer

Posted: April 3, 2024, 5:47 a.m. - Full Time - Noida

Job Title: Senior Security Engineer

Working Days: 5 days Experience : 6+ years Location: Noida Sector-62 ( Work from Office only )

Job Description:

We are seeking a dynamic Security Engineer with proven leadership skills to join our team at ThinkSys Inc, a service-based company managing multiple projects. This role involves overseeing the implementation and maintenance of robust security measures across various projects to safeguard our clients' sensitive information and infrastructure. The ideal candidate will combine technical expertise in cybersecurity with effective leadership abilities to drive security initiatives, mentor team members, and collaborate with project teams to ensure the highest standards of security across all engagements.

Responsibilities:

Lead the design, implementation, and optimization of Security Orchestration, Automation, and Response (SOAR) solutions to automate repetitive security tasks, improve incident response times, and enhance overall security operations efficiency.

Collaborate with project teams to assess existing security processes and workflows, identify opportunities for automation and orchestration, and develop tailored SOAR workflows to address specific project requirements.

Comprehensive understanding of cybersecurity principles, attack vectors, and incident response methodologies, with experience responding to a wide range of security incidents. Act as a subject matter expert on security matters during client engagements, participating in client meetings, security audits, and compliance assessments ensuring adherence to regulatory requirements and industry standards such as GDPR, HIPAA, PCI DSS, and ISO/IEC 27001 as needed.

Develop and implement security policies, procedures, and best practices to ensure compliance with regulatory requirements and industry standards.

Conduct regular security assessments, penetration tests, and vulnerability scans across various projects to identify and mitigate security risks.

Provide technical leadership and guidance to project teams on security-related matters, including secure coding practices, vulnerability management, and incident response procedures.

Excellent leadership and communication skills, with the ability to effectively collaborate with cross-functional teams, articulate complex technical concepts to non-technical stakeholders, and lead by example.

Lead security awareness training programs for employees of parent organization as well as client projects to promote a culture of security awareness and compliance.

Mentor junior security engineers and foster a culture of continuous learning and development within the security team.

Participate in the incident response process, including investigation, analysis, and remediation of security incidents and breaches.

Ability to work independently, manage multiple projects, and thrive in a fast-paced, dynamic environment.

Minimum Qualifications:

Bachelor's degree in Computer Science, Information Technology, or a related field. Master's degree preferred. 5+ years of experience in cybersecurity roles, with a focus on security engineering. Experience working in a service-based company or consulting firm with a diverse portfolio of projects. Knowledge of cloud security principles and experience securing cloud-based environments (e.g., AWS, Azure, GCP). Demonstrated leadership experience, including team management, project management, and strategic planning. Strong technical knowledge of networking protocols, operating systems and security technologies. Experience with security tools such as SIEM, IDS/IPS, DLP, endpoint protection, and vulnerability management systems. Familiarity with industry standards and frameworks such as ISO 27001, HIPAA, SOC 2, NIST Cybersecurity Framework, and PCI DSS. Proficiency in programming/scripting languages (e.g., Python, PowerShell) for automating security tasks and analyzing data. Excellent communication skills, with the ability to articulate complex security concepts to technical and non-technical audiences.

Educational Qualifications:

Bachelor's degree in Computer Science, Information Technology, or a related field. Master's degree preferred. Professional cybersecurity certifications such as Comptia Security+, CISSP, CISM, CEH, or equivalent are highly desirable.