Esyasoft Technologies Private Limited | Full time
Senior Lead Engineer - Security Consultant
- Relevant Experience (Years) 10 to 12 years
- Required Skills
- service component archite...
- systems development
- +22
- Country India
- City Joka
Job Description
The Security Consultant is responsible for assessing, designing,implementing, and maintaining information security controls to protectorganizational systems, networks, and data. The role ensures compliance withsecurity standards, manages cyber risks, and supports secure digitaltransformation initiatives.
Key Responsibility:
1. Security Assessment & Risk Management
- Architectenterprise-wide Application Security (AppSec) programs across complex,distributed enterprise environments—embedding SAST, DAST, and SCA intoCI/CD pipelines to enable secure-by-design architecture and reducevulnerabilities.
- Definesecure architecture patterns and guardrails, integrating AppSec controlsinto DevSecOps pipelines to standardize risk management acrossdistributed engineering teams.
- Collaboratedwith Customer Security teams to embed security architecture principlesto produce secure project environment.
- Experience in Application Security governance frameworks,aligning with NIST, ISO 27001, and PCI DSS to achieve compliance postureand audit readiness
- Conductsecurity risk assessments, vulnerability assessments, and threatmodeling across applications, infrastructure, and networks.
- Identifysecurity gaps and provide risk-based mitigation recommendations.
- Performperiodic security posture reviews and maturity assessments.
2. Security Architecture & Solution Design
- Designand review secure architecture for applications, cloud, and on-premisesystems.
- Ensuresecurity-by-design principles are embedded in system development andintegration.
- Reviewtechnical designs to ensure alignment with security standards and bestpractices.
3. Application & Infrastructure Security
- Supportand define application security testing (SAST, DAST, API securitytesting).
- Supportsecure coding practices and review source code for vulnerabilities.
- Assessinfrastructure security including servers, databases, networks, andendpoints.
- Implementand review cloud security controls for AWS, Azure, or GCP environments.
- Integratesecurity tools into CI/CD pipelines (DevSecOps).
- Lead full-lifecycleSIEM deployments, from HLD/LLD design through to steady-stateoperations.
- Produce detailedsolution proposals, policies, and procedures to support secure, reliableSIEM services
- Ensure secure configuration,identity access management, and logging in cloud platforms.
5. Security Operations & Incident Management
- Supportsecurity incident detection, response, and investigation activities.
- Performroot cause analysis and recommend corrective and preventive actions.
- Coordinatewith SOC, IT, and business teams during security incidents.
6. Compliance & Governance
- Ensurecompliance with security frameworks and regulations (ISO 27001, NIST,GDPR, etc.).
- Supportinternal and external security audits and risk assessments.
- Developand maintain security policies, standards, and procedures.
7. Awareness & Stakeholder Engagement
- Providesecurity guidance to development, infrastructure, and business teams.
- Conductsecurity awareness sessions and training programs.
- Actas a trusted advisor on security best practices and emerging threats.
- Stayupdated with latest cyber security threats, vulnerabilities, and trends.
- Preparesecurity assessment reports, dashboards, and risk summaries formanagement.
- Recommendcontinuous improvements to enhance organizational security posture.
Requirements
Qualification: Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field.
Professional Certificate Preferred:
- CISSP (Certified Information SystemsSecurity Professional).
- CISM (Certified Information SecurityManager).
- CEH (Certified Ethical Hacker).
- ISO/IEC 27001 Lead Implementer or LeadAuditor.
- AWS / Azure / GCP Security Certification.
- CompTIA Security+ (added advantage).
Years of Exp: 8-13 years of experience in information security, cyber securityconsulting, or related roles
Job Specific Skill:
- Strong knowledge of cyber securityprinciples, tools, and frameworks.
- Hands-on experience with vulnerabilityassessment and penetration testing tools.
- Experience in application, infrastructure,and cloud security.
- Knowledge of security compliance andregulatory standards.
- Understanding of networking, operatingsystems, and databases.
- Strong documentation, reporting, andstakeholder communication skills.