Lead Cyber Security

SuperOps

Chennai District

On-site

INR 2,800,000 - 4,600,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

SuperOps in Chennai is seeking a Senior Application & Cloud Security Engineer (IC3) to own security for web, mobile, and AWS environments, driving threat modeling, VAPT, and secure CI/CD integration.

You will implement AWS WAF rules, IAM & Secrets Management, and security observability while collaborating with engineers to remediate vulnerabilities and enforce standards across SOC 2, ISO 27001, and CIS benchmarks.

Qualifications

  • 6–9 years in Application Security, Cloud Security, and DevSecOps.
  • In-depth Web & Mobile security testing, API penetration testing, and secure code review.
  • Hands-on AWS Cloud Security experience (IAM, VPC, KMS, GuardDuty, Security Hub, S3, EKS/ECS).
  • Proven WAF & edge defense experience with AWS WAF/CloudFront and custom rules.
  • Observability/SIEM experience (Datadog, Splunk, ELK, CloudWatch).
  • Threat modeling using STRIDE and MITRE ATT&CK.

Responsibilities

  • Take end-to-end ownership of the security posture across Web, Mobile and Cloud environments.
  • Perform VAPT and threat modeling in collaboration with engineers and architects.
  • Embed automated security gates into CI/CD pipelines (SAST/DAST/SCA) with minimal friction.
  • Develop and tune AWS WAF rules, IAM policies, and secure key management.

Skills

Threat modeling
DevSecOps
Cloud security
WAF configuration
SIEM observability

Tools

AWS
GitHub Actions
GitLab CI
OWASP ZAP
Burp Suite

Job description

As a Senior Application & Cloud Security Engineer (IC3), you will take end-to-end technical ownership of our application security posture across Web, Mobile (iOS/Android), and Cloud (AWS) environments. You will be responsible for threat modeling, conducting deep-dive vulnerability assessments (VAPT), embedding automated security gates into CI/CD pipelines, engineering advanced AWS WAF custom rules & perimeter defenses, and leveraging Observability/SIEM platforms for proactive threat detection and incident monitoring.

Key Responsibilities & Core Scope
  • Web & Mobile Application Security (AppSec)
  • Web Application Security: Conduct comprehensive manual and automated vulnerability assessments (VAPT) across web platforms and microservice APIs based on OWASP Top 10 and OWASP API Security Top 10.
  • Mobile Application Security (iOS & Android): Perform static and dynamic security assessments aligned with OWASP Mobile Application Security (MASVS) — auditing secure data storage, certificate pinning, biometric authentication, deep linking, reverse-engineering resistance, and third-party SDK security.
  • Secure SDLC & DevSecOps Automation: Integrate, tune, and scale SAST, DAST, and SCA tools (e.g., Semgrep, Checkmarx, Veracode, Snyk, SonarQube, OWASP ZAP, Burp Suite) inside GitHub Actions / GitLab CI pipelines with minimal developer friction.
  • Threat Modeling: Lead collaborative threat modeling sessions (STRIDE / MITRE ATT&CK) with developers and architects during sprint planning and architectural design phases.
  • Vulnerability Remediation: Work directly with product engineering teams to provide code-level remediation guidance, root-cause analysis, and verification testing.
  • AWS Security Hardening: Architect and maintain hardened AWS multi-account structures (AWS Organizations, Control Tower, SCPs) aligned with CIS AWS Foundations Benchmarks.
  • IAM & Secrets Management: Design least-privilege IAM policies, role-based access controls, automated credential rotation, and secure key management via AWS KMS and Secrets Manager.
  • Container & Kubernetes Security: Enforce runtime protection, image scanning, and network policies for Docker containers and Kubernetes (EKS/ECS) workloads.
  • Infrastructure as Code (IaC) Security: Automate Terraform security auditing using tools such as Checkov, tfsec, and Trivy before deployments hit production.
  • AWS WAF Engineering: Architect, deploy, and fine-tune AWS WAF and Amazon CloudFront security configurations across all edge endpoints.
  • Custom Rule Development: Write custom regex rules, rate-limiting policies, IP set filtering, and bot control rules to mitigate Layer 7 DDoS, credential stuffing, scraping, and zero-day vulnerabilities.
  • Security Observability Platforms: Monitor security telemetry across platforms such as Elastic/OpenSearch, AWS CloudWatch, or Coralogix.
  • Threat Detection & Alerting: Aggregate and correlate security logs (VPC Flow Logs, CloudTrail, ALB logs, WAF logs, GuardDuty findings) to build high-fidelity detection rules and actionable alert dashboards.
  • Incident Response Support: Assist in triaging security events, performing log forensics, and automating alert escalations to reduce Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR).
  • Compliance Alignment: Provide technical evidence and enforce controls for SOC 2 Type II, ISO 27001, and CIS Benchmarks.
  • Tooling & Cost Efficiency: Optimize security tool utilization, eliminate redundancy, and identify cloud architecture cost savings.
Mandatory Qualifications (Must-Haves):
  • Experience: 6–9 years in Application Security, Cloud Security, and DevSecOps.
  • AppSec Mastery: In-depth knowledge of Web & Mobile (Android/iOS) security testing, API penetration testing, and secure code review.
  • AWS Cloud Security: Hands-on experience securing AWS services (IAM, VPC, KMS, GuardDuty, Security Hub, S3, EKS/ECS).
  • WAF & Edge Defense: Proven experience configuring AWS WAF / CloudFront, including authoring custom WAF rules, rate limiting, and bot protection.
  • Observability Experience: Practical experience querying and setting up alerts in modern observability/SIEM tools (e.g., Datadog, Splunk, ELK, CloudWatch, Sumo Logic).
  • Threat Modeling: Solid track record using STRIDE and MITRE ATT&CK frameworks for architecture reviews.
Bonus / Good-to-Have (Optional):
  • Certifications: Relevant offensive/security certifications: OSCP, AWS Certified Security – Specialty, eWPTX, CEH, or CISSP.
  • Emerging Tech: Experience or research in AI/LLM Security (OWASP LLM Top 10, Prompt Injection defense, RAG security).
  • Prior experience managing, administering, or launching a Responsible Disclosure Program (VDP) or Bug Bounty program (e.g., HackerOne, Bugcrowd, or internal security policy) is a strong added advantage.
Get your free, confidential resume review.

or drag and drop your file here.