7,540 Cybersecurity Professionals jobs in India
Cybersecurity
Posted 1 day ago
Job Viewed
Job Description
About:
Exide Energy Solutions Limited is a wholly owned Subsidiary of Exide Industries Limited, leading battery manufacturing and distribution company in India with annual revenues of $1.8+ Bn. Exide Energy Solutions Limited is investing $500+ Mn dollars to setup India’s first Giga plant to manufacture Lithium-Ion Cells at Devanahalli Industrial Area in Bengaluru. Exide Energy designs, develops, and manufactures Lithium Ion Cells and Battery Pack solutions for various energy storage. Exide Energy is a leading player in the market with OEM customers across key market applications – 2W, 3W, 4W, CV and industrial applications. Exide is also deeply invested in further developing li-ion technology with significant R&D investments including setup of in-house team as well as necessary lab infrastructure to support development activities.
Job Summary:
Experienced Cybersecurity Deputy Manager to join our Cybersecurity team. The role involves support in designing, implementing, and maintaining the organization’s security posture. The candidate will lead operational security activities, ensure governance, compliance with regulatory requirements, and handle critical systems and data from emerging threats.
Key Responsibilities:
Vendor & Technology Management:
Evaluate and manage relationships with third-party security solution providers. Oversee the implementation of advanced security technologies and tools, such as EDR, DLP, SIEM,IAM and PAM solutions. Continuously evaluate the effectiveness of security controls and recommend enhancements.
Security Operations: Assist in implementing the organization’s cybersecurity projects and roadmap. Oversee day-to-day security operations, including incident management, threat monitoring, and vulnerability assessments. Manage cybersecurity projects to ensure timely delivery and alignment with organizational goals. Oversee security tools, monitor KPIs, and communicate risks to stakeholders,
Threat Management & Incident Response: Lead and coordinate response to security incidents, including root cause analysis, mitigation, and reporting. Monitor and analyze security alerts, ensuring appropriate actions are taken to mitigate risks. Stay up-to-date with emerging threats and recommend proactive measures to counteract risks.
Compliance & Risk Management: Ensure compliance with regulatory frameworks (e.g., GDPR, DPDP Act, TISAX, ISO 27001, etc.). Conduct periodic risk assessments and recommend mitigation strategies. Assist in the preparation and execution of internal and external audits. Develop, implement, and maintain security policies, procedures, and standards.
Security Training & Awareness : Conduct employee awareness programs on cybersecurity best practices. Support cross-functional teams to embed security into organizational processes. Train, and upskill internal IT team members and focused training for functions while fostering a security-first culture.
Qualification:
- Strong understanding of cybersecurity frameworks (NIST, CIS Controls, ISO 27001).
- Hands-on experience with:
Security tools like SIEM, EDR, DLP,MDM, IAM, PAM, Proxy solutions.
IT/OT Security Architecture design and review.
OT (Operational Technology) Cybersecurity tools.
Firewalls, vulnerability scanners, and endpoint protection solutions.
Proficiency in incident response, threat hunting, and risk management processes.
Knowledge of regulatory standards such as GDPR, ISO 27001:2022, DPDP Act.
Third party security vendor management.
Application security.
- Strong analytical, problem-solving, and communication skills.
- Relevant certifications (CISSP, CISM, CEH, CISA or equivalent).
Preferred Qualifications :
- Strong analytical and problem-solving skills
- Attention to detail and ability to prioritize tasks effectively
- Knowledge of Industry Control Systems Cybersecurity will be advantageous.
- Knowledge of other regulatory standards & frameworks like TISAX, SOC etc.
Cybersecurity
Posted today
Job Viewed
Job Description
Exide Energy Solutions Limited is a wholly owned Subsidiary of Exide Industries Limited, leading battery manufacturing and distribution company in India with annual revenues of $1.8+ Bn. Exide Energy Solutions Limited is investing $500+ Mn dollars to setup India’s first Giga plant to manufacture Lithium-Ion Cells at Devanahalli Industrial Area in Bengaluru. Exide Energy designs, develops, and manufactures Lithium Ion Cells and Battery Pack solutions for various energy storage. Exide Energy is a leading player in the market with OEM customers across key market applications – 2W, 3W, 4W, CV and industrial applications. Exide is also deeply invested in further developing li-ion technology with significant R&D investments including setup of in-house team as well as necessary lab infrastructure to support development activities.
Job Summary:
Experienced Cybersecurity Deputy Manager to join our Cybersecurity team. The role involves support in designing, implementing, and maintaining the organization’s security posture. The candidate will lead operational security activities, ensure governance, compliance with regulatory requirements, and handle critical systems and data from emerging threats.
Key Responsibilities:
Vendor & Technology Management:
Evaluate and manage relationships with third-party security solution providers. Oversee the implementation of advanced security technologies and tools, such as EDR, DLP, SIEM,IAM and PAM solutions. Continuously evaluate the effectiveness of security controls and recommend enhancements.
Security Operations: Assist in implementing the organization’s cybersecurity projects and roadmap. Oversee day-to-day security operations, including incident management, threat monitoring, and vulnerability assessments. Manage cybersecurity projects to ensure timely delivery and alignment with organizational goals. Oversee security tools, monitor KPIs, and communicate risks to stakeholders,
Threat Management & Incident Response: Lead and coordinate response to security incidents, including root cause analysis, mitigation, and reporting. Monitor and analyze security alerts, ensuring appropriate actions are taken to mitigate risks. Stay up-to-date with emerging threats and recommend proactive measures to counteract risks.
Compliance & Risk Management: Ensure compliance with regulatory frameworks (e.g., GDPR, DPDP Act, TISAX, ISO 27001, etc.). Conduct periodic risk assessments and recommend mitigation strategies. Assist in the preparation and execution of internal and external audits. Develop, implement, and maintain security policies, procedures, and standards.
Security Training & Awareness: Conduct employee awareness programs on cybersecurity best practices. Support cross-functional teams to embed security into organizational processes. Train, and upskill internal IT team members and focused training for functions while fostering a security-first culture.
Qualification:
- Strong understanding of cybersecurity frameworks (NIST, CIS Controls, ISO 27001).
- Hands-on experience with:
Security tools like SIEM, EDR, DLP,MDM, IAM, PAM, Proxy solutions.
IT/OT Security Architecture design and review.
OT (Operational Technology) Cybersecurity tools.
Firewalls, vulnerability scanners, and endpoint protection solutions.
Proficiency in incident response, threat hunting, and risk management processes.
Knowledge of regulatory standards such as GDPR, ISO 27001:2022, DPDP Act.
Third party security vendor management.
Application security.
- Strong analytical, problem-solving, and communication skills.
- Relevant certifications (CISSP, CISM, CEH, CISA or equivalent).
Preferred Qualifications:
- Strong analytical and problem-solving skills
- Attention to detail and ability to prioritize tasks effectively
- Knowledge of Industry Control Systems Cybersecurity will be advantageous.
- Knowledge of other regulatory standards & frameworks like TISAX, SOC etc.
Cybersecurity
Posted today
Job Viewed
Job Description
About:
Exide Energy Solutions Limited is a wholly owned Subsidiary of Exide Industries Limited, leading battery manufacturing and distribution company in India with annual revenues of $1.8+ Bn. Exide Energy Solutions Limited is investing $500+ Mn dollars to setup India’s first Giga plant to manufacture Lithium-Ion Cells at Devanahalli Industrial Area in Bengaluru. Exide Energy designs, develops, and manufactures Lithium Ion Cells and Battery Pack solutions for various energy storage. Exide Energy is a leading player in the market with OEM customers across key market applications – 2W, 3W, 4W, CV and industrial applications. Exide is also deeply invested in further developing li-ion technology with significant R&D investments including setup of in-house team as well as necessary lab infrastructure to support development activities.
Job Summary:
Experienced Cybersecurity Deputy Manager to join our Cybersecurity team. The role involves support in designing, implementing, and maintaining the organization’s security posture. The candidate will lead operational security activities, ensure governance, compliance with regulatory requirements, and handle critical systems and data from emerging threats.
Key Responsibilities:
Vendor & Technology Management:
Evaluate and manage relationships with third-party security solution providers. Oversee the implementation of advanced security technologies and tools, such as EDR, DLP, SIEM,IAM and PAM solutions. Continuously evaluate the effectiveness of security controls and recommend enhancements.
Security Operations: Assist in implementing the organization’s cybersecurity projects and roadmap. Oversee day-to-day security operations, including incident management, threat monitoring, and vulnerability assessments. Manage cybersecurity projects to ensure timely delivery and alignment with organizational goals. Oversee security tools, monitor KPIs, and communicate risks to stakeholders,
Threat Management & Incident Response: Lead and coordinate response to security incidents, including root cause analysis, mitigation, and reporting. Monitor and analyze security alerts, ensuring appropriate actions are taken to mitigate risks. Stay up-to-date with emerging threats and recommend proactive measures to counteract risks.
Compliance & Risk Management: Ensure compliance with regulatory frameworks (e.g., GDPR, DPDP Act, TISAX, ISO 27001, etc.). Conduct periodic risk assessments and recommend mitigation strategies. Assist in the preparation and execution of internal and external audits. Develop, implement, and maintain security policies, procedures, and standards.
Security Training & Awareness : Conduct employee awareness programs on cybersecurity best practices. Support cross-functional teams to embed security into organizational processes. Train, and upskill internal IT team members and focused training for functions while fostering a security-first culture.
Qualification:
- Strong understanding of cybersecurity frameworks (NIST, CIS Controls, ISO 27001).
- Hands-on experience with:
Security tools like SIEM, EDR, DLP,MDM, IAM, PAM, Proxy solutions.
IT/OT Security Architecture design and review.
OT (Operational Technology) Cybersecurity tools.
Firewalls, vulnerability scanners, and endpoint protection solutions.
Proficiency in incident response, threat hunting, and risk management processes.
Knowledge of regulatory standards such as GDPR, ISO 27001:2022, DPDP Act.
Third party security vendor management.
Application security.
- Strong analytical, problem-solving, and communication skills.
- Relevant certifications (CISSP, CISM, CEH, CISA or equivalent).
Preferred Qualifications :
- Strong analytical and problem-solving skills
- Attention to detail and ability to prioritize tasks effectively
- Knowledge of Industry Control Systems Cybersecurity will be advantageous.
- Knowledge of other regulatory standards & frameworks like TISAX, SOC etc.
Cybersecurity
Posted 3 days ago
Job Viewed
Job Description
About:
Exide Energy Solutions Limited is a wholly owned Subsidiary of Exide Industries Limited, leading battery manufacturing and distribution company in India with annual revenues of $1.8+ Bn. Exide Energy Solutions Limited is investing $500+ Mn dollars to setup India’s first Giga plant to manufacture Lithium-Ion Cells at Devanahalli Industrial Area in Bengaluru. Exide Energy designs, develops, and manufactures Lithium Ion Cells and Battery Pack solutions for various energy storage. Exide Energy is a leading player in the market with OEM customers across key market applications – 2W, 3W, 4W, CV and industrial applications. Exide is also deeply invested in further developing li-ion technology with significant R&D investments including setup of in-house team as well as necessary lab infrastructure to support development activities.
Job Summary:
Experienced Cybersecurity Deputy Manager to join our Cybersecurity team. The role involves support in designing, implementing, and maintaining the organization’s security posture. The candidate will lead operational security activities, ensure governance, compliance with regulatory requirements, and handle critical systems and data from emerging threats.
Key Responsibilities:
Vendor & Technology Management:
Evaluate and manage relationships with third-party security solution providers. Oversee the implementation of advanced security technologies and tools, such as EDR, DLP, SIEM,IAM and PAM solutions. Continuously evaluate the effectiveness of security controls and recommend enhancements.
Security Operations: Assist in implementing the organization’s cybersecurity projects and roadmap. Oversee day-to-day security operations, including incident management, threat monitoring, and vulnerability assessments. Manage cybersecurity projects to ensure timely delivery and alignment with organizational goals. Oversee security tools, monitor KPIs, and communicate risks to stakeholders,
Threat Management & Incident Response: Lead and coordinate response to security incidents, including root cause analysis, mitigation, and reporting. Monitor and analyze security alerts, ensuring appropriate actions are taken to mitigate risks. Stay up-to-date with emerging threats and recommend proactive measures to counteract risks.
Compliance & Risk Management: Ensure compliance with regulatory frameworks (e.g., GDPR, DPDP Act, TISAX, ISO 27001, etc.). Conduct periodic risk assessments and recommend mitigation strategies. Assist in the preparation and execution of internal and external audits. Develop, implement, and maintain security policies, procedures, and standards.
Security Training & Awareness : Conduct employee awareness programs on cybersecurity best practices. Support cross-functional teams to embed security into organizational processes. Train, and upskill internal IT team members and focused training for functions while fostering a security-first culture.
Qualification:
- Strong understanding of cybersecurity frameworks (NIST, CIS Controls, ISO 27001).
- Hands-on experience with:
Security tools like SIEM, EDR, DLP,MDM, IAM, PAM, Proxy solutions.
IT/OT Security Architecture design and review.
OT (Operational Technology) Cybersecurity tools.
Firewalls, vulnerability scanners, and endpoint protection solutions.
Proficiency in incident response, threat hunting, and risk management processes.
Knowledge of regulatory standards such as GDPR, ISO 27001:2022, DPDP Act.
Third party security vendor management.
Application security.
- Strong analytical, problem-solving, and communication skills.
- Relevant certifications (CISSP, CISM, CEH, CISA or equivalent).
Preferred Qualifications :
- Strong analytical and problem-solving skills
- Attention to detail and ability to prioritize tasks effectively
- Knowledge of Industry Control Systems Cybersecurity will be advantageous.
- Knowledge of other regulatory standards & frameworks like TISAX, SOC etc.
Cybersecurity
Posted today
Job Viewed
Job Description
About:
Exide Energy Solutions Limited is a wholly owned Subsidiary of Exide Industries Limited, leading battery manufacturing and distribution company in India with annual revenues of $1.8+ Bn. Exide Energy Solutions Limited is investing $500+ Mn dollars to setup India’s first Giga plant to manufacture Lithium-Ion Cells at Devanahalli Industrial Area in Bengaluru. Exide Energy designs, develops, and manufactures Lithium Ion Cells and Battery Pack solutions for various energy storage. Exide Energy is a leading player in the market with OEM customers across key market applications – 2W, 3W, 4W, CV and industrial applications. Exide is also deeply invested in further developing li-ion technology with significant R&D investments including setup of in-house team as well as necessary lab infrastructure to support development activities.
Job Summary:
Experienced Cybersecurity Deputy Manager to join our Cybersecurity team. The role involves support in designing, implementing, and maintaining the organization’s security posture. The candidate will lead operational security activities, ensure governance, compliance with regulatory requirements, and handle critical systems and data from emerging threats.
Key Responsibilities:
Vendor & Technology Management:
Evaluate and manage relationships with third-party security solution providers. Oversee the implementation of advanced security technologies and tools, such as EDR, DLP, SIEM,IAM and PAM solutions. Continuously evaluate the effectiveness of security controls and recommend enhancements.
Security Operations: Assist in implementing the organization’s cybersecurity projects and roadmap. Oversee day-to-day security operations, including incident management, threat monitoring, and vulnerability assessments. Manage cybersecurity projects to ensure timely delivery and alignment with organizational goals. Oversee security tools, monitor KPIs, and communicate risks to stakeholders,
Threat Management & Incident Response: Lead and coordinate response to security incidents, including root cause analysis, mitigation, and reporting. Monitor and analyze security alerts, ensuring appropriate actions are taken to mitigate risks. Stay up-to-date with emerging threats and recommend proactive measures to counteract risks.
Compliance & Risk Management: Ensure compliance with regulatory frameworks (e.G., GDPR, DPDP Act, TISAX, ISO 27001, etc.). Conduct periodic risk assessments and recommend mitigation strategies. Assist in the preparation and execution of internal and external audits. Develop, implement, and maintain security policies, procedures, and standards.
Security Training & Awareness : Conduct employee awareness programs on cybersecurity best practices. Support cross-functional teams to embed security into organizational processes. Train, and upskill internal IT team members and focused training for functions while fostering a security-first culture.
Qualification:
- Strong understanding of cybersecurity frameworks (NIST, CIS Controls, ISO 27001).
- Hands-on experience with:
Security tools like SIEM, EDR, DLP,MDM, IAM, PAM, Proxy solutions.
IT/OT Security Architecture design and review.
OT (Operational Technology) Cybersecurity tools.
Firewalls, vulnerability scanners, and endpoint protection solutions.
Proficiency in incident response, threat hunting, and risk management processes.
Knowledge of regulatory standards such as GDPR, ISO 27001:2022, DPDP Act.
Third party security vendor management.
Application security.
- Strong analytical, problem-solving, and communication skills.
- Relevant certifications (CISSP, CISM, CEH, CISA or equivalent).
Preferred Qualifications :
- Strong analytical and problem-solving skills
- Attention to detail and ability to prioritize tasks effectively
- Knowledge of Industry Control Systems Cybersecurity will be advantageous.
- Knowledge of other regulatory standards & frameworks like TISAX, SOC etc.
Information Security Analyst (Cybersecurity)
Posted 3 days ago
Job Viewed
Job Description
Responsibilities:
- Monitor security infrastructure for threats and intrusions, analyzing security logs and alerts.
- Investigate security incidents, performing root cause analysis and implementing remediation plans.
- Develop, implement, and maintain security policies, standards, and procedures.
- Conduct regular vulnerability assessments and penetration testing to identify weaknesses in systems and applications.
- Recommend and implement security enhancements and controls to mitigate risks.
- Manage and configure security tools, including firewalls, IDS/IPS, SIEM, and endpoint protection solutions.
- Stay current with the latest cybersecurity threats, trends, and technologies, and adapt defenses accordingly.
- Educate employees on security best practices and awareness training.
- Participate in security audits and ensure compliance with relevant regulations (e.g., ISO 27001, GDPR).
- Collaborate with IT and development teams to ensure security is integrated into the system development lifecycle.
- Develop and maintain incident response plans and conduct regular drills.
- Prepare reports on security status, incidents, and recommendations for management.
- Evaluate and recommend new security technologies and solutions.
- Maintain up-to-date documentation of security systems and processes.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 3 years of hands-on experience in information security, cybersecurity operations, or a related role.
- Strong understanding of network security principles, protocols, and technologies.
- Experience with security tools such as SIEM, firewalls, intrusion detection/prevention systems, and vulnerability scanners.
- Proficiency in scripting languages (e.g., Python, Bash) for automation is a plus.
- Knowledge of common security frameworks and compliance standards.
- Excellent analytical and problem-solving skills with meticulous attention to detail.
- Ability to work independently, manage time effectively, and thrive in a remote, fast-paced environment.
- Strong communication and collaboration skills, able to explain technical security concepts to non-technical audiences.
- Relevant certifications such as CompTIA Security+, CEH, CISSP are highly desirable.
- Experience with cloud security (AWS, Azure, GCP) is an advantage.
Cybersecurity Professional
Posted today
Job Viewed
Job Description
Job Title: Cybersecurity Professional
Description:
We're building a global digital infrastructure layer that prioritizes users, builders, and creators. Our mission is to distribute participatory power to billions in the digital economy by creating efficient, secure, and accessible systems.
You'll work with teams on web 3.0 products, focusing on real-world problem-solving while challenging conventional wisdom about tech and the internet. We prioritize user rights, intellectual property protection, and asset security in an AI-driven world.
Key Responsibilities:
Be The First To Know
About the latest Cybersecurity professionals Jobs in India !
Senior Information Security Analyst (Cybersecurity)
Posted 1 day ago
Job Viewed
Job Description
Responsibilities:
- Monitor security alerts and events from various security tools (SIEM, IDS/IPS, EDR).
- Conduct in-depth analysis of security incidents, including root cause analysis and impact assessment.
- Develop and implement security policies, procedures, and best practices.
- Perform vulnerability assessments and penetration testing to identify and remediate security weaknesses.
- Manage and maintain security infrastructure, including firewalls, intrusion detection systems, and antivirus solutions.
- Stay current with the latest cybersecurity threats, vulnerabilities, and attack vectors.
- Develop and deliver security awareness training to employees.
- Participate in the development and execution of incident response plans.
- Collaborate with IT teams to ensure secure system configurations and deployments.
- Research and recommend new security technologies and solutions.
- Ensure compliance with relevant security standards and regulations.
- Provide expert guidance on information security matters to internal stakeholders.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 5 years of experience in information security, with a focus on threat analysis and incident response.
- Proficiency with SIEM tools, network security monitoring, and vulnerability assessment tools.
- Strong understanding of network protocols, operating systems (Windows, Linux), and cloud security concepts.
- Experience with security frameworks (e.g., NIST, ISO 27001).
- Relevant security certifications such as CISSP, CEH, GIAC, or equivalent.
- Excellent analytical, problem-solving, and critical thinking skills.
- Strong communication and interpersonal skills, with the ability to explain complex technical issues clearly.
- Proven ability to work independently and manage tasks effectively in a remote environment.
Cybersecurity Engineer
Posted 2 days ago
Job Viewed
Job Description
We are seeking a skilled and proactive Cybersecurity Specialist to lead the security strategy and implementation for our enterprise SaaS application. This role will be responsible for safeguarding our platform, users, and data against current and emerging threats. You will work closely with engineering, DevOps, compliance, and product teams to ensure our application is secure by design and compliant with relevant security standards and regulations.
**Your role and responsibilities**
Key Responsibilities:
· Programming & Automation:
· Develop and maintain security automation scripts, tools, and integrations in languages such as Python, Go, JavaScript, or Bash.
· Create CI/CD security gates using tools like GitHub Actions, GitLab CI, Jenkins, or CircleCI.
· Build custom security testing scripts or utilities to supplement commercial tools.
· Automate compliance evidence gathering, scanning, and reporting.
* DevSecOps Integration:
* Champion security automation and CI/CD pipeline integration for static/dynamic scanning, secrets detection, etc.
* Educate developers on secure coding practices and provide guidance during architecture/design discussions.
* Application Security:
* Lead threat modeling, secure code reviews, and security testing throughout the SDLC.
* Implement and maintain security controls across the SaaS stack (frontend, backend, APIs, and data layer).
* Conduct regular vulnerability assessments and coordinate remediation with development teams.
* Cloud & Infrastructure Security:
* Collaborate with DevOps to ensure secure cloud infrastructure (e.g., IBM Cloud, AWS, GCP).
* Define and enforce security policies for IAM, network segmentation, encryption, and logging.
* Security Monitoring & Incident Response:
* Investigate and respond to security incidents, breaches, and anomalies in real-time.
* Compliance & Governance:
* Ensure the application meets relevant security and privacy standards (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
* Support audits and customer security reviews with documentation and evidence collection.
**Required technical and professional expertise**
* Total 10+ years' experience including 3-5+ years of experience in cybersecurity, with a focus on application and cloud security.
* Strong understanding of web application security principles (e.g., OWASP Top 10, API security).
* Experience securing modern cloud-native SaaS architectures.
* Hands-on experience with tools like SAST/DAST scanners, WAFs, SIEMs, vulnerability management platforms.
* Familiarity with secure development practices and CI/CD security (DevSecOps).
* Knowledge of regulatory and compliance frameworks (SOC 2, ISO 27001, GDPR, etc.).
* Strong scripting or automation skills (e.g., Python, Bash, Terraform, etc.)
**Preferred technical and professional experience**
* Security certifications such as CISSP, CEH, OSCP, CSSLP, or CCSP.
* Experience working in Agile/Scrum environments.
* Background in penetration testing or red/blue team activities.
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Cybersecurity Engineer
Posted 2 days ago
Job Viewed
Job Description
We are seeking a skilled and proactive Cybersecurity Specialist to lead the security strategy and implementation for our enterprise SaaS application. This role will be responsible for safeguarding our platform, users, and data against current and emerging threats. You will work closely with engineering, DevOps, compliance, and product teams to ensure our application is secure by design and compliant with relevant security standards and regulations.
**Your role and responsibilities**
Key Responsibilities:
· Programming & Automation:
· Develop and maintain security automation scripts, tools, and integrations in languages such as Python, Go, JavaScript, or Bash.
· Create CI/CD security gates using tools like GitHub Actions, GitLab CI, Jenkins, or CircleCI.
· Build custom security testing scripts or utilities to supplement commercial tools.
· Automate compliance evidence gathering, scanning, and reporting.
* DevSecOps Integration:
* Champion security automation and CI/CD pipeline integration for static/dynamic scanning, secrets detection, etc.
* Educate developers on secure coding practices and provide guidance during architecture/design discussions.
* Application Security:
* Lead threat modeling, secure code reviews, and security testing throughout the SDLC.
* Implement and maintain security controls across the SaaS stack (frontend, backend, APIs, and data layer).
* Conduct regular vulnerability assessments and coordinate remediation with development teams.
* Cloud & Infrastructure Security:
* Collaborate with DevOps to ensure secure cloud infrastructure (e.g., IBM Cloud, AWS, GCP).
* Define and enforce security policies for IAM, network segmentation, encryption, and logging.
* Security Monitoring & Incident Response:
* Investigate and respond to security incidents, breaches, and anomalies in real-time.
* Compliance & Governance:
* Ensure the application meets relevant security and privacy standards (e.g., SOC 2, ISO 27001, GDPR, HIPAA).
* Support audits and customer security reviews with documentation and evidence collection.
**Required technical and professional expertise**
* 3-5+ years of experience in cybersecurity, with a focus on application and cloud security.
* Strong understanding of web application security principles (e.g., OWASP Top 10, API security).
* Experience securing modern cloud-native SaaS architectures.
* Hands-on experience with tools like SAST/DAST scanners, WAFs, SIEMs, vulnerability management platforms.
* Familiarity with secure development practices and CI/CD security (DevSecOps).
* Knowledge of regulatory and compliance frameworks (SOC 2, ISO 27001, GDPR, etc.).
* Strong scripting or automation skills (e.g., Python, Bash, Terraform, etc.)
**Preferred technical and professional experience**
* Security certifications such as CISSP, CEH, OSCP, CSSLP, or CCSP.
* Experience working in Agile/Scrum environments.
* Background in penetration testing or red/blue team activities.
IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.