System Security

Bigship

Dadri

On-site

INR 8,000,000 - 12,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A prominent IT company in India is seeking a skilled System Security professional. The role involves safeguarding software applications and servers against threats. Candidates must have at least 5 years of IT security experience, particularly in application and server security, along with a Bachelor’s degree in Computer Science or related field. Proficiency in security tools and strong communication skills are essential. This position offers the chance to work in a dynamic environment focused on continuous improvement of security measures.

Qualifications

  • 5 years of experience in IT security focusing on application security and server security.
  • Strong knowledge of security frameworks (e.g., OWASP, NIST).
  • Experience with cloud security (AWS, Azure) is a plus.

Responsibilities

  • Conduct security assessments and vulnerability analysis on applications.
  • Implement secure coding practices and review application code.
  • Develop and maintain security controls within applications.

Skills

Application Level Security
Server Level Security
Risk Management
Incident Response
Secure Coding Practices

Education

Bachelor’s degree in Computer Science or Information Security

Tools

Nmap
Burp Suite
SQLmap
Kali-Linux

Job description

Join to apply for the System Security role at Bigship

We are seeking a skilled and experienced IT Security Professional with a primary focus on Application Level Security and a solid understanding of Server Level Security. The ideal candidate will be responsible for ensuring the security of our software applications and underlying servers, safeguarding against threats, vulnerabilities, and unauthorized access. This role requires a deep knowledge of security practices, the ability to assess and mitigate risks, and collaboration with development and operations teams to integrate security into the software development lifecycle (SDLC).

Responsibilities
  • Conduct security assessments and vulnerability analysis of web and mobile applications.
  • Implement secure coding practices and review application code for security flaws.
  • Perform penetration testing on applications to identify and rectify security vulnerabilities.
  • Develop and maintain security controls within applications to prevent unauthorized access, data breaches, and other cyber threats.
  • Collaborate with development teams to ensure security is integrated into the software development lifecycle (SDLC).
  • Implement and manage application firewalls, security gateways, and encryption technologies.
  • Strong understanding of network security, web application security, API security across public and private networks.
  • Experience in Black Box and Gray Box testing with the capability of finding business logic vulnerabilities.
  • Knowledge in performing VAPT as per OWASP Top 10 and SANS Top 25 including Broken Access Controls, SQL Injection, Security Misconfiguration, Cross-Site Scripting, CSRF, and authentication/authorization issues. Proficient in both manual and automated tool-based testing for these vulnerabilities.
Tools & Technologies
  • Nmap, Nessus, SSL Scan, Burp Suite, SQLmap, OWASP ZAP, Metasploit, Wireshark, Kali-Linux, Nikto, Nipper, Postman, DirBuster
Server Level Security
  • Assess and improve the security posture of servers hosting critical applications.
  • Implement and manage server security measures, including firewalls, intrusion detection systems (IDS), and security patches.
  • Conduct regular security audits and vulnerability assessments on server infrastructure.
  • Monitor server logs and alerts to detect and respond to potential security incidents.
  • Collaborate with system administrators to ensure servers are configured securely and comply with industry standards.
  • Understanding of OSI Model, TCP/IP, IPv4 & IPv6 and various Network Protocols. Good knowledge of firewalls, IDS/IPS, and network segmentation.
Risk Management & Compliance
  • Identify and evaluate security risks related to applications and servers, and implement mitigation strategies.
  • Ensure compliance with relevant security standards, regulations, and best practices (e.g., OWASP, ISO 27001, PCI-DSS).
  • Maintain and update security policies, procedures, and documentation related to application and server security.
  • Participate in incident response activities, including investigating security breaches and implementing corrective actions.
Security Awareness & Training
  • Conduct security awareness training for development, operations, and other relevant teams.
  • Stay up-to-date with the latest security trends, vulnerabilities, and technologies.
  • Provide guidance and support to other IT teams on security best practices.
Continuous Improvement
  • Continuously monitor and improve application and server security measures.
  • Evaluate and implement new security tools, technologies, and methodologies to enhance security.
  • Participate in security research and development initiatives to advance the organization’s security capabilities.
Qualifications
  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • Minimum of 5 years of experience in IT security, with a focus on application security and server security.
  • Strong knowledge of security frameworks and standards (e.g., OWASP, NIST, CIS).
  • Hands-on experience with security tools such as web application firewalls, IDS/IPS, vulnerability scanners, and encryption technologies.
  • Proficiency in secure coding practices and experience with programming languages such as Java, Python, or C#.
  • Experience with cloud security and securing applications in cloud environments (AWS, Azure, Google Cloud) is a plus.
  • Certifications such as CISSP, CEH, OSCP, Certified Ethical Hacker or similar are highly desirable.
  • Excellent problem-solving skills, with the ability to identify and mitigate security risks.
  • Strong communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Security
System Security

BigShip Technologies Pvt. Ltd • Dadri

On-site
INR 1,000,000 - 1,500,000
Application Security
Application Security

Airtel • India

On-site
INR 1,200,000 - 2,400,000
Security-focused culture
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000
Application Security Engineer
Application Security Engineer

Cynosure Corporate Solutions • Chennai District

On-site
INR 1,500,000 - 2,500,000
Senior Application Security Engineer
Senior Application Security Engineer

FloQast, Inc. • Pune District

On-site
INR 1,500,000 - 2,500,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Application Security Lead | Offshore
Application Security Lead | Offshore

Photon • Hyderabad

On-site
INR 850,000 - 1,800,000
Application Security Specialist
Application Security Specialist

Pearson India Education Services Pvt Ltd • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000