This page was automatically translated and may contain errors. View in English.
기음

Senior Information Security Engineer

Cimpress

Mumbai, Maharashtra, India · 정규직

가장 먼저 지원하세요

경험
4년 이상
샐러리
채용 공고
1
게시됨
10시간 전
작업 모드
사무실에서
교육
졸업생 누구나
적임
Any graduate from a recognized university can apply for this position.
재개하다
신청 시 필수 사항

당신이 일하게 될 곳

직무 설명

About the Role

We are seeking a proactive and hands-on Senior Information Security Engineer who thrives on independent ownership and delivering impactful outcomes. This role requires leading security efforts across cloud platforms, managing incident responses from detection to resolution, handling vulnerability lifecycles, and providing actionable security architecture advice that can be readily applied by teams. You will engage across various InfoSec areas, coordinate with cross-functional teams, and serve as the primary security expert within the organization. The security team is lean and collaborative, requiring versatility, quick adjustment to contexts, and contribution across multiple domains.

Key Responsibilities

  • Conduct practical security architecture assessments for workloads on AWS, OCI, Azure, and GCP based on standards like CIS Benchmarks, CSA CCM, and NIST CSF.
  • Evaluate and offer security improvements for cloud environments including IaaS, PaaS, and SaaS, focusing on network segmentation, IAM, encryption, logging, and data protection.
  • Review configurations of cloud and application resources, infrastructure-as-code templates, deployment pipelines, and perform threat modeling to identify security vulnerabilities before production deployment.
  • Collaborate with engineering and DevOps teams to integrate security controls into software development lifecycles and cloud deployment utilizing frameworks like AWS Well-Architected Security Pillar and Azure Security Benchmark.
  • Manage the full vulnerability management process, including discovery, evaluation, prioritization, tracking, remediation coordination, and reporting to stakeholders.
  • Operate security tools such as Orca Security, Microsoft Defender Security Posture Management, and Azure Security Posture Management for continuous cloud security monitoring.
  • Lead remediation efforts for external penetration test findings, coordinating with application and infrastructure teams and validating fixes independently.
  • Generate vulnerability trend analyses and communicate remediation progress and residual risks to both technical and non-technical audiences.
  • Apply CVSS, EPSS, and risk-based frameworks such as NIST SP 800-40 and OWASP Risk Rating to prioritize security remediation.
  • Perform SOC activities including alert triage, threat hunting, and incident investigation.
  • Lead comprehensive incident response following NIST SP 800-61 and SANS methodologies, including digital forensics tasks such as evidence collection, timeline analysis, and root cause identification.
  • Manage CrowdStrike EDR for endpoint detection, automation, use case implementation, and threat hunting.
  • Utilize Hunters.io, Splunk, and QRadar SIEM to facilitate log correlation, alert management, and enhancement of detection capabilities.
  • Create detailed incident reports, conduct post-incident reviews, and drive remediation to prevent recurrence, mapping adversary tactics to MITRE ATT&CK Framework.
  • Employ Dark & Deep Web monitoring tools such as Google Threat Intelligence, Cyble, Flare.io, and CloudSek to detect and analyze emerging threats.
  • Monitor and assess threat intelligence from diverse sources to inform defence strategies using frameworks like MITRE ATT&CK, Cyber Kill Chain, and Diamond Model of Intrusion Analysis.
  • Support secure coding practices using SAST and SCA tools including Snyk and SonarQube to detect and remediate vulnerabilities during software development.
  • Act as a key contact for security guidance, translating technical findings into accessible language for diverse stakeholders.
  • Coordinate with engineering, IT operations, and compliance teams to ensure informed decision-making and security-awareness throughout the organisation.
  • Promote security best practices and knowledge sharing through documentation and advisory efforts.

Mandatory Skills and Experience

  • Deep hands-on experience in cloud security architecture reviews aligned with industry benchmarks and frameworks.
  • Proficiency in managing vulnerability assessment tools and lifecycle, including external penetration test remediation.
  • Expertise in SOC operations, incident response, and digital forensics using relevant tools and methodologies.
  • Capability to apply threat intelligence and align security tactics with recognized frameworks.
  • Experience in secure coding practices and supply chain security management utilizing SAST and SCA tools.
  • Minimum 4 years of hands-on cybersecurity experience across various domains such as cloud security, endpoint security, SOC operations, or threat intelligence.

Preferred Certifications

  • CompTIA Security+, CEH, CCNA Security
  • Cloud security certifications like AWS Certified Security Specialty, AZ-500, Google Professional Cloud Security Engineer, or CCSP

Desirable Qualifications

  • CISM, CISSP, CISA certifications are advantageous.

Eligibility

Applicants should have graduated from any recognized university.

Why Join Us

Joining Cimpress means engaging in a career journey that goes beyond a traditional workplace. Our environment encourages continuous learning, growth, and innovation. As a global leader in mass customization, we provide exposure to cutting-edge technology and the opportunity to work with diverse teams worldwide, fostering both professional and personal development.

답변을 원하시면 남겨주세요. 다른 용도로는 사용하지 않습니다.

클릭하여 살펴보세요드래그 앤 드롭 또는 반죽 스크린샷

PNG, JPG, GIF, MP4, WebM, MOV · 파일당 최대 20MB · 최대 5개 파일

🤖
온라인 · 즉각적인 AI 도움말