Senior Cybersecurity Engineer

Cornerstone

Mumbai, Pune District

On-site

INR 2,000,000 - 4,000,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cornerstone in India is seeking a Senior Cybersecurity Engineer to defend and secure our SDLC across applications and platforms. You will evaluate security controls, perform white box testing, and collaborate with security and engineering teams.

The role focuses on AI/LLM based applications, threat modelling, incident response, and staying current with vulnerabilities and best practices. Candidates should have 6+ years of experience in application security and a strong background in cloud

Qualifications

  • Bachelor’s degree in IT/CS or related field.
  • 6+ years of experience in application security.
  • Experience with AI/LLM-based applications is a plus.

Responsibilities

  • Maintain security tools and processes for cloud environments (AWS, GovCloud, GCP).
  • Conduct white box security testing to assess application security.
  • Perform security assessments and code reviews of applications in development stages.
  • Define and enforce security measures for AI and LLM-based applications.
  • Lead incident response for AI/LLM security breaches.
  • Research latest vulnerabilities and best practices.
  • Coordinate penetration testing activities and report findings.

Skills

Application security
White box testing
Threat modelling
CI/CD security
AWS security
C# / Python
Node.js
Go
BSIMM / SAMM
Security tooling
Vulnerability management

Education

Bachelor's degree in IT/CS

Tools

Git
Jenkins
CloudFormation
SAST/DAST

Job description

Senior CybersecurityEngineer (India)

The Senior CybersecurityEngineer position is a hands-on role that involves evaluating and enforcing application security in all phases of the Software Development Life Cycle(SDLC). This position will work closely with our security and engineering team on conducting white box security testing, threat modelling, security assessments and support the identification, interpretation, and remediation of vulnerabilities across a variety of applications, programming languages, and platforms. The candidate should have a strong background in application security, coupled with deep knowledge of AI technologies and LLMs, to protect our applications from potential security threats.

In this role you will
  • Maintain security tools/processes to effectively secure our cloud-based environments and applications (AWS, GovCloud, GCP)
  • Conduct white box security testing to assess and validate application security.
  • Conduct security assessments and code reviews of applications in various stages of development.
  • Define, maintain, and enforce application security measures for AI and LLM based applications and evaluate application security tools to improve our detection and prevention capabilities
  • Monitor and track progress of found vulnerabilities and maintain the history
  • Explain and demonstrate vulnerabilities to application/system owners, and provide recommendations for mitigation
    Issue reports on assigned application and system scans
  • Continuously monitor and evaluate the security posture of AI/LLM applications and lead incident response efforts for security breaches related to AI and LLM applications
  • Perform threat modeling exercises and risk analysis for new and existing applications.
  • Research and stay up to date with the latest security vulnerabilities and best practices.
Youve got what it takesif you have
  • Bachelors degree in an Information Technology related field of study or equivalent post high school education and/or work-related experience
  • 6+ years of experience in application security
  • Knowledge of application security focused on AI and LLM-based applications
  • Knowledge of OWASP Top 10 for LLM applications
  • Knowledge of information security principles, web applications, and a level of familiarity with malicious code and common techniques used by hackers
  • Experience with common SDLC tools: static and dynamic code analysis, open-source management, container security, threat modeling, etc.
  • Experience with HTML and JavaScript along with a solid understanding of HTTP protocol
  • Experience coordinating penetration testing activities and performing penetration testing
  • Experience with CI/CD practices and tools (Git, Jenkins) and integrating security solutions into CI/CD pipelines is a plus
  • Experience creating solutions in C#, Python, Node.JS, or Go, and Infrastructure as Code (CloudFormation) is a plus
  • Knowledge of microservices architectures is a plus
  • Experience working on security responsibilities for a SaaS or PaaS solutions, preferably in AWS is a plus
  • Basic knowledge of SQL and prior experience with programming in one or more server-side technologies such as ASP.NET Core is a plus.
  • Thorough understanding of SDLC and software security maturity models such as Building Security In Maturity Model (BSIMM) or OWASP Software Assurance Maturity Model (SAMM) is a plus
  • Experience conducting secure code development training is a plus
  • Knowledge of cryptographic tools and/or security APIs is a plus
  • Experience interacting with security vendors and customers is a plus
  • Excellent problem solving and analytical skills; outstanding oral and written communication skills
  • Self-motivation and the ability to work under minimal supervision are a must
  • Excellent at multitasking, and open to constant learning
  • Energetic and positive attitude
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer - India
Senior Cybersecurity Engineer - India

Cornerstone OnDemand • Maharashtra

Hybrid
INR 2,400,000 - 4,200,000
AI Security Engineer
AI Security Engineer

QualiZeal • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Application Security Engineer
Application Security Engineer

Millennium • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Application Security Head
Application Security Head

Adani Group • Mumbai

On-site
INR 3,500,000 - 6,000,000
Application Security Lead-CXA
Application Security Lead-CXA

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,800,000 - 2,500,000
Cyber Penetration Tester
Cyber Penetration Tester

Alignity Solutions • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Lead - AI and Application Security
Lead - AI and Application Security

LeadSquared • Bengaluru

On-site
INR 1,400,000 - 2,200,000
Security Engineer
Security Engineer

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Senior Security Engineer
Senior Security Engineer

Smartstream Limited • Bengaluru

On-site
INR 3,500,000 - 6,000,000