Security & Compliance Engineer

Mphasis

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mphasis is seeking a Security & Compliance Engineer to oversee the complete security and compliance workstream across firmware, applications, and CI/CD interfaces. This role requires expertise in threat modeling, FIPS 140-2 integration, and NIST SP 800-193 firmware integrity to ensure robust security across management interfaces and embedded devices.

You will also prepare security review packages, generate SBOMs, conduct license audits, and provide sign-off on signing pipelines and hardening

Qualifications

  • Knowledge of firmware security architecture and threat modeling.
  • Experience with FIPS 140-2 compliance and cryptographic library integration.
  • Familiarity with NIST SP 800-193 and firmware integrity.
  • Experience preparing security review documentation and CVE posture reports.
  • Experience with open source license audits and SBOM generation.

Responsibilities

  • Conduct threat modeling and attack surface analysis for embedded firmware.
  • Ensure FIPS 140-2 compliance through OpenSSL integration in Yocto.
  • Implement NIST SP 800-193 firmware integrity measures.
  • Prepare security review packages for SSRB, LSRB, and BFSRB.
  • Generate SBOMs and conduct license audits for Yocto/OpenBMC dependencies.
  • Provide security review and sign-off on CI/CD signing pipelines and interface hardening.

Skills

Firmware security architecture
Security
FIPS 140-2 compliance
Cryptographic library integration
NIST SP 800-193
Security review documentation
SBOM generation and license audits

Education

Bachelor's degree in Computer Science, Cybersecurity, or Electrical Engineering

Tools

OpenSSL integration

Job description

Job Title: Security & Compliance Engineer

Job Summary:

The Security & Compliance Engineer will be responsible for overseeing the complete security and compliance workstream within our organization. This includes threat modeling, FIPS 140-2 integration, NIST SP 800-193 firmware integrity, and the preparation of all security review packages. The role requires a specialist with a deep understanding of security protocols and compliance requirements, ensuring that all systems are secure and compliant with industry standards.

Responsibilities:
  • Conduct threat modeling and attack surface analysis for BMC firmware, including Redfish, IPMI, KVM, boot chain, and signing processes.
  • Ensure FIPS 140-2 compliance through the integration of FIPS-validated OpenSSL in Yocto, including the selection of cryptographic modules and TLS configuration for management interfaces.
  • Implement NIST SP 800-193 firmware integrity measures, focusing on detection, protection, and recovery mechanisms.
  • Prepare security review packages for SSRB, LSRB, and BFSRB, including code review artifacts, architecture documentation, CVE posture reports detailing vulnerabilities and their mitigations, and managing remediation responses.
  • Generate Software Bill of Materials (SBOM) and conduct license audits for all Yocto/OpenBMC dependencies, preparing OSC submissions as required.
  • Provide security review and sign-off on CI/CD signing pipelines and management interface hardening, ensuring robust security measures are in place.
Mandatory Skills:
  • Proficient in firmware security architecture, including threat modeling and mitigation design.
  • Security
  • Strong understanding of FIPS 140-2 compliance and experience with cryptographic library integration.
  • Knowledge of NIST SP 800-193 and its application in firmware integrity.
  • Experience in preparing security review documentation, including CVE posture reports and remediation response management.
  • Familiarity with open source license compliance, including SBOM generation and license audits.
Preferred Skills:
  • Knowledge of the EU Cybersecurity Resilience Act (CRA) and its implications for product compliance.
  • Experience with EAR/ECCN export control assessments for cryptographic components.
  • Ability to coordinate or execute security penetration testing.
  • Experience with HSM integration and signing infrastructure.
  • Familiarity with CVE triage and patch backport workflow management.
Qualifications:

Bachelor's degree in Computer Science, Cybersecurity, or Electrical Engineering. Relevant certifications such as CISSP, CEH, or CompTIA Security+ are valued but not mandatory.

Prior Work Experience Examples That Would Be Helpful:
  • Developed a formal threat model for an embedded firmware product or IoT device, addressing all network-facing attack surfaces with documented mitigations.
  • Integrated a FIPS 140-2 validated cryptographic library into a Yocto-based embedded Linux build and validated compliance.
  • Prepared and submitted a formal security review package for a firmware product, including managing remediation response cycles.
  • Conducted or coordinated an open source license audit and produced a Software Bill of Materials (SBOM) for a complex firmware project.
About Mphasis:

Mphasis applies next-generation technology to help enterprises transform businesses globally. Customer centricity is foundational to Mphasis and is reflected in the Mphasis’ Front2Back™ Transformation approach. Front2Back™ uses the exponential power of cloud and cognitive to provide hyper-personalized (C=X2C2TM=1) digital experience to clients and their end customers. Mphasis’ Service Transformation approach helps ‘shrink the core’ through the application of digital technologies across legacy environments within an enterprise, enabling businesses to stay ahead in a changing world. Mphasis’ core reference architectures and tools, speed and innovation with domain expertise and specialization are key to building strong relationships with marquee clients.

Equal Opportunity Employer:

Mphasis is an equal opportunity/affirmative action employer. We provide equal employment opportunities to applicants and existing associates and evaluate qualified candidates without regard to race, gender, national origin, ancestry, age, color, religious creed, marital status, genetic information, sexual orientation, gender identity, gender expression, sex (including pregnancy, breast feeding and related medical conditions), mental or physical disability, medical conditions military and veteran status or any other status or condition protected by applicable federal, state, or local laws, governmental regulations and executive orders. View the EEO in the law poster here, view the EEO in the law supplement here. To view the pay transparency nondiscrimination provision please click here and to view the E-Verify posting click here.
Mphasis is committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of disability to search and apply for a career opportunity, please send an email to accomodationrequest@mphasis.com and let us know your contact information and the nature of your request.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Software Engg - Systems
Senior Software Engg - Systems

Mphasis • Bengaluru

On-site
INR 1,200,000 - 1,800,000
OpenBMC Engineer
OpenBMC Engineer

Mphasis • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Contractor-04
Contractor-04

Mphasis • Bengaluru

On-site
INR 700,000 - 1,100,000
BMC Engineer
BMC Engineer

Axiado Corporation • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
BMC Engineer
BMC Engineer

Axiado Corporation • Hyderabad

On-site
INR 1,000,000 - 1,500,000
BMC Engineer
BMC Engineer

Axiado Corporation • Chennai District

On-site
INR 1,000,000 - 1,500,000
Firmware Architect
Firmware Architect

SANMINA-SCI TECHNOLOGY INDIA PRIVATE LIMITED • Chennai District

On-site
INR 1,800,000 - 3,200,000
Application Security Engineer
Application Security Engineer

BMC Software • Pune City

On-site
INR 1,800,000 - 2,400,000
Staff Cybersecurity Engineer - Pen Testing
Staff Cybersecurity Engineer - Pen Testing

BMC Software • Pune District

On-site
INR 1,800,000 - 2,435,000
Firmware Developer
Firmware Developer

Hewlett Packard Enterprise Development LP • India

On-site
INR 1,800,000 - 3,000,000
Health & wellbeing benefits
Personal & professional development
Unconditional inclusion