Senior Security Engineer
Location: Bengaluru, India
Job Type: Full‑Time
Overview
We are looking for a skilled senior Security Engineer who will design and implement security solutions, conduct security assessments, and develop security architecture frameworks for 42Gears products and infrastructure. The role focuses on creating secure cloud architectures across AWS and GCP, requires a strategic and analytical professional with strong communication and problem‑solving skills, and involves collaboration with cross‑functional teams in a dynamic environment.
Responsibilities
- Design and implement security architecture solutions aligned with business requirements and industry best practices.
- Conduct security assessments and vulnerability analysis to identify and remediate gaps in existing infrastructure.
- Develop comprehensive documentation, including threat models and architecture diagrams, to standardize security across the organization.
- Collaborate with cross‑functional teams to integrate security controls directly into the software development lifecycle (SDLC).
- Evaluate and pilot emerging security technologies to maintain a proactive defense posture against evolving threats.
- Mentor junior team members and lead security awareness initiatives to foster a culture of collective responsibility.
- Architect secure cloud solutions that ensure continuous compliance with organizational policies and cloud‑native best practices.
- Perform cloud hardening by evaluating infrastructure configurations and implementing rigorous security benchmarks.
- Oversee IAM strategies across multi‑cloud environments (AWS/GCP) to enforce strict least‑privilege access and identity governance.
- Automate security guardrails through Infrastructure as Code (IaC) to ensure consistent security deployment across all environments.
- Design centralized logging and monitoring frameworks to provide the visibility required for effective threat detection and response.
- Integrate SAST, DAST, and SCA tools into CI/CD pipelines to automate the detection of vulnerabilities in custom code and third‑party libraries.
- Develop security blueprints for containerised environments (Kubernetes/Docker) covering image signing, pod security, and runtime protection.
- Define Data Loss Prevention (DLP) architectures to monitor and control the movement of sensitive data across cloud and hybrid environments.
- Map technical security controls to regulatory frameworks (SOC2, ISO 27001, GDPR) to ensure the architecture meets audit requirements.
Critical Skills / Competencies
- Security Frameworks: Proficient in NIST CSF, ISO 27001, and SOC2 control mapping.
- Cloud Architecture: Security design knowledge for AWS (EC2, S3, VPC, Lambda, IAM), Azure (VMs, KMS, Storage, App Services), and GCP (Compute Engine, Cloud Storage, Identity Management).
- Threat Modeling: Expert in STRIDE/PASTA methodologies and infrastructure risk assessment.
- Identity & Access: Advanced IAM governance, Zero Trust architecture, and JIT access.
- Container Security: Hardening and orchestration security for Docker and Kubernetes.
- DevSecOps: Integrating SAST/DAST/SCA gating into automated CI/CD pipelines.
- Network Security: Implementing micro‑segmentation, WAF, and API Security Gateways.
- Data Protection: Centralised secrets management (Vault) and PKI/Encryption standards.
- Security Observability: Architecting SIEM/SOAR telemetry for high‑fidelity detection.
- Application Security: Deep knowledge of OWASP Top 10 and secure coding practices.
- Compliance: Technical auditing against FedRAMP, HIPAA, PCI‑DSS standards using security assessment methodologies.
- Enterprise security frameworks and governance standards (NIST, ISO 27001, SOC 2).
Required Skills
- Cloud Security and Compliance
- Compliance
- Code Quality and Architecture
- Cyber Threat Awareness
- Collaboration & Communication
Preferred Certifications
- CISSP or equivalent advanced security certification.
- CISM or GIAC Security Essentials (GSEC).
- Cloud architect certifications such as AWS Solutions Architect Professional, Azure Solutions Architect Expert, or Google Cloud Professional Cloud Architect.
- Kubernetes security certifications (CKA, CKAD) or cloud‑native security certifications.
- Experience with enterprise security frameworks and governance standards (NIST, ISO 27001, SOC 2).
Application
Ready to apply? Keep this role in view and open the application form when you’re ready.