Overview
AWS & Application Security Engineer focused on security assessments, VAPT/penetration testing, and AWS/application security reviews.
What you'll do
- Conduct security assessments and VAPT/penetration testing for web apps, mobile apps, AWS infrastructure, and networks.
- Perform security reviews of AWS accounts, VPCs, EC2 instances, EKS clusters, RDS, S3, load balancers, and serverless services.
- Implement and manage AWS security services including GuardDuty, Security Hub, AWS Config, Inspector, CloudTrail, WAF, Shield, and IAM.
- Run cloud security posture assessments, identify misconfigurations vs best practices/CIS benchmarks, and drive remediation.
- Use Ansible for server provisioning, configuration management, security hardening, patch management, and compliance enforcement.
- Support internal/external security audits and prepare test cases, checklists, VAPT reports, and risk assessment reports.
- Implement OWASP security best practices, support secure SDLC, and perform Linux hardening and infrastructure security reviews.
What you'll need
- 5+ years of experience.
- Hands-on AWS security, application security, and VAPT experience.
- Experience with AWS Security Hub, GuardDuty, Inspector, CloudTrail, Config, WAF, Shield, Secrets Manager, and KMS.
- Experience securing containerized environments such as Docker and Kubernetes.
- Expertise with tools like Burp Suite Pro, Nessus, Qualys, Acunetix, Netsparker, Metasploit, WebInspect, and Nmap.
- Good understanding of Linux administration, server hardening, and network security.
- Participated in at least two security audits, with one in the last 12 months.
Nice to have
- Preferred experience in SaaS, e-commerce, or product-based organizations.
- Certifications such as AWS Security Specialty, CISM, or ISO 27001 Lead Auditor.
Details
Read the full description and apply on the company’s own careers page.