Consultant - Info Security Engineer

Principal Financial Group

Hyderabad

On-site

INR 2,200,000 - 4,200,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Principal Financial Group in Hyderabad, India seeks an experienced Consultant - Info Security Engineer to safeguard applications on‑premises and in the cloud. You will perform security testing, identify vulnerabilities, and provide remediation guidance while mentoring peers.

This role requires deep knowledge of web APIs, thick clients, and AWS services, with hands‑on use of industry tools to deliver actionable security assessments and detailed reporting.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Technology, Engineering, Mathematics, or related fields, or equivalent professional experience.
  • 8-10 years of practical experience in security assessment of web apps, APIs, thick client apps, mobile apps, and AWS services.
  • Proficiency with web/API testing tools such as Burp Suite, Postman, and OWASP ZAP.
  • Experience with Kali and advanced security assessments of applications.
  • Knowledge of common web vulnerabilities (OWASP Top Ten, SANS Top 25) and remediation techniques.
  • AWS Cloud Practitioner certification or other cloud certifications; C|EH, CPent, etc., are a plus.

Responsibilities

  • Perform manual security penetration assessments of web applications and APIs hosted within on‑premises infrastructure.
  • Conduct security assessments on web apps and APIs in cloud environments using AWS services (S3, EC2, Lambda, API Gateway, SNS).
  • Apply re-engineering techniques using tools for thick client/desktop apps.
  • Manage Vulnerability Disclosure Program (VDP) and Bug Bounty reports with detailed validation and risk assessment.
  • Use CVSS to assess risk levels of identified vulnerabilities.
  • Identify techniques to exploit vulnerabilities, generate POCs, and mentor dev teams on remediations.
  • Write comprehensive reports and update documentation.
  • Work independently and mentor peers, sharing attack techniques during security testing.

Skills

Penetration testing
Web API security
Security reporting
Mentoring
Cloud security (AWS)

Education

Bachelor's or Master’s in CS/Engineering/Math

Tools

Burp Suite
Postman
OWASP ZAP
Kali Linux
Wireshark
IDA Pro
ghidra
Echo Mirage
CFF Explorer

Job description

Additional Information

Why Principal?

At Principal, we believe in fostering a cooperative and welcoming environment where everyone's input is appreciated. We are committed to your professional development and assist our team members in reaching their personal and career ambitions. Join us and become part of a world-class team that is making an impact!

Responsibilities

Unique Opportunity

At Principal, we believe in encouraging innovation and excellence. As a Consultant - Info Security Engineer, you will have the outstanding opportunity to collaborate with world-class professionals in Hyderabad, Telangana, India. You'll play a crucial role in ensuring the security and integrity of our applications, both on-premises and in the cloud, by performing security penetration testing. This position is for those who are ambitious and determined to make a significant impact in the field of information security.

Key Responsibilities

  • Perform manual security penetration assessments of web applications and APIs hosted within on-premises infrastructure.
  • Conduct security assessments on web applications and APIs deployed in cloud environments using AWS services such as S3 buckets, EC2 instances, Lambda functions, API Gateway, and SNS.
  • Apply re-engineering techniques using tools like Echo Mirage, IDAPro, CFF Explorer, Dnspy, MS sys-internals, Wireshark, dotpeek, and ghidra for thick client/desktop applications.
  • Manage Vulnerability Disclosure Program (VDP) and Bug Bounty reports with detailed technical validation, consistent assessment of impact and severity, and fair evaluation aligned with policies.
  • Use CVSS scoring mechanisms to assess risk levels of identified vulnerabilities.
  • Innovatively identify techniques to exploit vulnerabilities in applications, generate impactful proof-of-concepts (POCs), provide walkthroughs to app-dev teams, and offer remediation mentorship.
  • Write comprehensive reports and update existing documentation.
  • Work independently and multi-functionally, mentoring peers and junior team members, helping them learn and apply new attack techniques during security testing.
Qualifications

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Technology, Engineering, Mathematics, or related fields, or equivalent professional experience (B.E. / B.Tech / M.S. / M.Tech / MCA).
  • 8-10 years of practical experience in security assessment of web applications, web APIs, thick client apps, mobile apps, and AWS services, preferably within the finance domain.
  • Proficiency in using web/API testing tools such as Burp Suite, Postman, and OWASP ZAP.
  • Practical experience with Kali and performing advanced security assessments of applications.
  • Detailed knowledge of common web application security vulnerabilities (OWASP Top Ten, SANS Top 25, etc.), programming patterns leading to them, and remediation techniques.
  • AWS Cloud Practitioner Certification or other cloud certifications are helpful. Additional security certifications like C|EH, CPent, etc., are a plus.

Plus/Good to Have

  • Experience in conducting security assessments of AI applications.
  • Understanding of server-less architectures and micro-services on AWS.

Be part of Principal's world-class team making a difference. We honor each person's input and strive to maintain a supportive and inclusive culture. We prioritize your professional growth and assist our team in achieving their personal and career objectives. Bring your skills to life and expand your potential with us!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Principal Security Consultant
Principal Security Consultant

Claranet India • India

On-site
INR 3,000,000 - 6,000,000
Principal Consultant, Offensive Security
Principal Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

The Herjavec Group US • Bengaluru

Hybrid
INR 1,800,000 - 3,200,000
Hybrid Work Model
Medical Insurance - Employee + depend.
Life Insurance
+3
Consultant, Offensive Security
Consultant, Offensive Security

Kroll • Bengaluru

On-site
INR 1,200,000 - 2,400,000
Application Security Engineer
Application Security Engineer

Byline Learning Solutions • Pune District

On-site
INR 1,200,000 - 1,800,000
Security Engineer (Onsite - Hyderabad)
Security Engineer (Onsite - Hyderabad)

Uplers • Hyderabad

On-site
INR 900,000 - 2,000,000
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cyderes • India

On-site
INR 1,200,000 - 2,400,000
TECHNICAL LEAD - Application Security
TECHNICAL LEAD - Application Security

Happiest Minds Technologies • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Senior Security Consultant
Senior Security Consultant

Payatu Technologies Pvt Ltd • Pune District

On-site
INR 1,800,000 - 3,200,000