Senior Security Engineer

Chronos Systems Inc.

India

Hybrid

INR 2,500,000 - 5,000,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Chronos Systems Inc. seeks a Senior Security Engineer to strengthen defensive security, build detection and incident response capabilities, and secure the platform across domains.

You will design, deploy and automate security controls, respond to incidents, and work with cross-functional teams using AWS tools and scripting. Requires 5+ years in security and strong knowledge of threats and OWASP.

Qualifications

  • Five+ years in enterprise SaaS security.
  • Strong logging, monitoring, vulnerability analysis and mitigation.
  • Experience implementing threat intel and automating threat hunting.
  • Hands-on with AWS security services (Inspector, GuardDuty, Detective, Security Hub, Shield).
  • Designing and deploying security controls across domains (access, data, vulnerability, incident, app, network).
  • Programming/scripting in Python/Go/Ruby for security tasks.
  • Understanding TLS, RSA, AES, PKI and web protocols (HTTP/SOAP/REST).
  • Experience with incident response and threat investigation.
  • Knowledge of OWASP Top 10, SANS 25, CWE; CS degree; certs a plus.
  • Able to work autonomously in a fast-paced, cross-functional environment.

Responsibilities

  • Bolster and develop defensive security capabilities and countermeasures.
  • Respond to incidents and investigations via logs and AWS sources.
  • Engineer and automate detection and response capabilities.
  • Keep current with TTPs and implement mitigations to reduce risk.
  • Be part of a product security team building security frameworks across SDLC.
  • Conduct vulnerability assessments and security audits.
  • Improve incident detection processes and countermeasures execution.
  • Create and maintain run books for security incidents.
  • Configure threat management platforms including SOAR and SIEM.
  • Contribute to security architecture for detection and response.
  • Support security audits with the compliance team.
  • Collaborate with Product/Development to enhance the security program.
  • Participate in on-call rotation and lead incident response efforts.

Skills

Defensive security
Offensive security
Security logging
Vulnerability assessment
Threat intelligence
Threat hunting
AWS security
Incident response
Penetration testing
OWASP Top 10
Python scripting

Education

Bachelor’s or Master’s degree in computer science

Tools

AWS Inspector
AWS GuardDuty
AWS Detective
AWS Security Hub
AWS Shield

Job description

Our client is a world-renowned US startup in the field of automation. This California unicorn is still a private enterprise experiencing hypergrowth. They are looking for an exceptional Senior Security Engineer to join their team as they build their defensive security capabilities. This is a full-time, permanent role. Hybrid or Remote.

Requirements
  • At least 5 years of multifaceted defensive and offensive security experience in an enterprise Saas-based company.
  • Strong technical knowledge and deep experience in security logging and monitoring, vulnerability assessment, risk-based analysis, and vulnerability mitigation.
  • A skilled security expert who can implement tools and processes to incorporate threat intelligence from the ground up and automate threat-hunting.
  • Operational experience with AWS security solutions (e.g. Inspector, Guarduty, Detective, Security Hub, Advanced Shield).
  • Hands-on experience designing and deploying security controls across all security domains, such as access management, data protection, vulnerability management, incident response and management, application security, network security, preventive, detective, and offensive security solutions.
  • Capable of leveraging programming and/or scripting languages to solve practical day-to-day security challenges (Python, Go, Ruby).
  • Strong understanding of encryption technologies (e.g., TLS, HMAC, RSA, AES, PKI).
  • Strong understanding of Web-related technologies (e.g., HTTP, SOAP, REST, TCP / IP).
  • Experience conducting or managing incident response for organizations, and investigating targeted threats.
  • Experience and knowledge of common penetration testing techniques, application security vulnerabilities, OWASP Top 10, SANS 25, CWE, etc.
  • Bachelor’s or Master’s degree in computer science or equivalent experience.
  • Information security professional certifications are a plus (CLSSP, CISSP, CISA, GSSP, GSEC, etc.).
  • Ability to work autonomously in a fast-paced, cross-functional environment and comfortable with ambiguity.
RESPONSIBILITIES
  • Bolster and develop our defensive security capabilities, identifying advanced threats to the platform, developing and implementing countermeasures.
  • Responding to incidents and conducting investigations as events happen through analyzing logs and various other sources (ex: AWS Guardduty, SecurityHub, Detective, etc.).
  • Engineer and automate custom detection and response capabilities to combat malicious and/or unwanted behaviors within the environment.
  • Stay up to date with Tactics, Techniques, and Procedures (TTPs) that may apply and define and implement mitigation techniques to improve our overall risk posture.
  • You will be part of a new product security team responsible for building, supporting, enhancing, and improving our security frameworks, tools, processes, and methodologies used across our SDLC and Runtime environments.
  • Conduct in-depth vulnerability assessments and security auditing of assets.
  • Develop and improve processes for incident detection and the execution of countermeasures.
  • Contribute to the creation and upkeep of run books to handle security incidents.
  • Administer security configuration for threat management platforms for large-scale environments, including security orchestration, automation, and response (SOAR) and security information and event management (SIEM) tools.
  • Provide guidance on security architecture for threat detection and response systems used as a part of the overall security operations.
  • Consult with our security compliance team during security audits to demonstrate our technical security capabilities.
  • Collaborate with Product Management and Development team members to enhance our Security program.
  • Take part in the Security Operations on-call rotation, including leading all incident response efforts and documentation during your rotation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr Cyber Security Engineer
Sr Cyber Security Engineer

TechBrein Solutions Private Limited • Kozhikode district

On-site
INR 1,200,000 - 2,400,000
Senior Information Security Engineer (DevSecOps)
Senior Information Security Engineer (DevSecOps)

WLEN WorldJobs LLP • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Security Engineer
Security Engineer

Aynsoft • Delhi

On-site
INR 1,000,000 - 1,500,000
Principal Software Engineer / Engineering Manager – Security
Principal Software Engineer / Engineering Manager – Security

ULTISOURCE • Bengaluru

Hybrid
INR 3,800,000 - 6,800,000
Lead Security Engineer
Lead Security Engineer

mpc • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Senior Security Analyst
Senior Security Analyst

UltraViolet Cyber • Hyderabad

On-site
INR 800,000 - 1,200,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Nextwebi • Bengaluru

On-site
INR 1,500,000 - 3,000,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Cyber Security Engineer
Cyber Security Engineer

Playsimple Games Private Limited • Bengaluru

On-site
INR 1,500,000 - 2,000,000