Search by job, company or skills

Senior Lead Engineer, Information Security

Senior Lead Engineer, Information Security

Majesco
Fresher
Not Disclosed
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

Key Responsibilities

JOB DESCRIPTION

Security Engineering & Architecture

  • Design, implement, and maintain enterprise security controls across cloud, infrastructure, and application environments.
  • Evaluate emerging threats and technologies and recommend improvements to the organization's security architecture.
  • Develop security standards, engineering patterns, and technical guidance to improve the overall security posture.

Security Automation & DevSecOps

  • Design and develop security automation solutions that improve operational efficiency and reduce manual effort.
  • Integrate security controls and validation activities into CI/CD pipelines and software delivery workflows.
  • Build and maintain GitHub Actions and related automation to support secure development practices.
  • Automate vulnerability management, policy enforcement, reporting, and remediation tracking activities.

Application Security

  • Lead security engineering efforts focused on protecting internally developed applications and APIs.
  • Perform and coordinate:
    • Threat modeling
    • Secure design and architecture reviews
    • Secure code reviews
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • Open-source dependency and supply chain security reviews
    • Secret and credential exposure detection
    • API security testing and assessments
    • CI/CD pipeline security reviews
    • Security validation of application deployments
  • Partner with development teams to identify, prioritize, and remediate security risks.

Web Application Firewall (WAF) & Edge Security

  • Design, implement, and maintain Web Application Firewall (WAF) capabilities.
  • Develop and tune security rules, attack detection logic, bot mitigation, rate limiting, and application-layer protections.
  • Continuously monitor and improve protections against OWASP Top 10 and emerging web application threats.

Offensive Security & Penetration Testing

  • Conduct application red team exercises and adversarial security assessments.
  • Perform manual and automated penetration testing of web applications, APIs, and supporting services.
  • Simulate real-world attack techniques to identify weaknesses in application design, authentication, authorization, and deployment architectures.
  • Document findings, provide remediation guidance, and validate corrective actions.

Collaboration & Security Operations Support

  • Partner with engineering, infrastructure, and cloud teams to implement secure solutions.
  • Support incident response investigations involving applications, cloud services, and development platforms.
  • Provide technical leadership and mentorship on security engineering practices and security tool adoption.

Success Measures

  • Increased automation and efficiency of security processes.
  • Successful integration of security controls into engineering and CI/CD workflows.
  • Reduction of application and cloud security risks.
  • Effective implementation and management of WAF protections.
  • Timely identification and remediation of vulnerabilities.
  • Successful execution of penetration testing and red team activities.
  • Improved security posture across applications, APIs, and software delivery platforms.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Secure code reviews

Secure design and architecture reviews

Security automation solutions

GitHub Actions

Enterprise security controls

API security testing

About Company

Similar Jobs

India
Skills:
information security governance , Vulnerability Management, Data Protection, Automation, Regulatory Reporting, Governance Reporting, Digital Risk Protection, Metrics Management Information, Process Improvement, Privacy, Functional Excellence, DPDP Compliance Management, Regulatory Change Management, Risk Compliance
2-4 yrs
Bengaluru, India
Skills:
secure sdlc , Identity and Access Management (IAM), Vulnerability Management, Iso27001, C5, Compliance reports and certifications, Backup Disaster Recovery, SOC2, ENS, Information security assessments
Bengaluru, India
Skills:
tokenization , Identity Access Management, Amazon Web Services, Wan, Cloud Security, Network security, Dns, Encryption, DHCP, Data Protection, Lan, Azure, Nfv, Sdn, SSL certificates, Proxy Servers, CA Directory Services, Network Infrastructure Services, VPN technologies, Network Capacity Planning, BGP Routing, Security Monitoring
Pune, India
Skills:
Penetration Testing, Threat Hunting, Threat Analysis, Threat Intelligence, Security Architecture, security engineering, Access control defenses, Security systems software and applications, Forensics Analysis, Cyber operations intelligence
Hyderabad, India
Skills:
secure sdlc , Incident Response, Application Security, Owasp Top 10, Security Requirements, Threat identification, Engineering, Application Security Risk Assessments, Business continuity, Common application security vulnerabilities and remediation techniques, CWE SANS Top 25, Risk management, Access management