Security and GRC Specialist - 5-10Yrs - Hyderabad
Summary
Leads Pragma Edge's end-to-end security function from Hyderabad, owning governance/risk/compliance (ISO 27001, SOC 2, NIST, Vanta), application security (secure code review, SAST/DAST/SCA via Mend, OWASP ZAP, Burp Suite), penetration testing, cloud & infrastructure security (Nessus, AWS), threat monitoring (Trend Micro, Sophos), and external attack surface management.
Job Description: Lead — Security, GRC
& Application Security
Role Summary
This role leads Pragma Edge's end-to-end security function — spanning
governance/compliance, application security, cloud & infrastructure
security, threat monitoring, and external attack surface management. The Lead
owns the security posture across internal systems, client-facing products, and
cloud/on-prem infrastructure, and is the primary point of accountability for
audit readiness, client TPRM responses, and remediation across every layer of
the stack.
Core Responsibilities
1. Governance, Risk & Compliance (GRC)
- Own and
maintain security policies (Access Control, Incident Response, Data
Protection, SDLC) — review and update on a recurring cycle.
- Conduct risk
assessments and client Third-Party Risk Management (TPRM) reviews;
maintain and update the Vanta risk register and track remediation to
closure.
- Map controls to
ISO 27001, SOC 2, NIST, and OWASP standards.
- Own audit
evidence collection — logs, screenshots, approvals — for both internal and
external audits.
- Lead quarterly
internal audits (client-specific) and HR audits; own annual external audit
and ongoing Vanta compliance management.
2. Application Security & Secure Development
- Perform secure
code reviews on critical APIs and backend services.
- Own OWASP Top
10 remediation (BOLA, BFLA, Injection, Security Misconfigurations).
- Run Software
Composition Analysis (SCA) — dependency vulnerability management, SBOM
generation, license review, remediation validation.
- Own SAST
scanning across JAR, Python, and Maven artifacts using Mend/WhiteSource;
own DAST scanning (web app + API) using OWASP ZAP and Burp Suite.
- Run
container/image vulnerability scanning (Mend CLI).
- Coordinate
SAST/DAST/SCA findings with development teams, validate fixes, and perform
rescans.
3. Penetration Testing
- Build and
execute pentesting plans for web applications, APIs, and products.
- Own client
communication throughout pentest engagements, produce findings reports,
and drive remediation to closure.
4. Cloud & Infrastructure Security
- Review cloud
IAM, network rules, and storage exposure; own security hardening (insecure
configs, headers, TLS, secrets).
- Run
infrastructure vulnerability assessments (Active Directory, switches,
routers, internal servers) via Nessus.
- Run cloud
compliance scans and client-specific AWS security/compliance assessments
via Nessus.
- Own network
security review, configuration validation, and hardening recommendations.
- Manage on-prem
security: installation requests, firewall changes, domain whitelisting,
and inbound/outbound IP access control.
- Validate
backup, restore, and DR readiness; improve audit logging and SIEM
integration.
5. Threat Monitoring & Security Operations
- Monitor
security logs (Trend Micro) and firewall logs (Sophos) — event review,
traffic analysis, and investigation.
- Coordinate
remediation with Infrastructure, Cloud, Networking, and Development teams;
produce vulnerability reporting across infrastructure, cloud, application,
and product layers.
6. External Attack Surface Management
- Run weekly
public IP discovery and maintain external asset inventory.
- Perform
external reconnaissance, port scanning, and service enumeration.
- Own subdomain
enumeration, takeover validation, and DNS verification.
- Run external
vulnerability scanning and validation; monitor for exposed
company-sensitive information on the internet.
7. Training, Awareness & Documentation
- Run security
awareness training and phishing simulations; run developer secure-coding
sessions (OWASP/API security).
- Prepare
security assessments, training plans, test evaluations, and score
analysis.
- Own compliance
documentation: Access Change Requests, Device Disposal records, Incident
Response documentation, Tabletop Exercise (TTE) documentation.
- Own security
documentation: policies, assessment reports, remediation reports.
- Provide audit
support: quarterly evidence, compliance reporting, vulnerability tracking,
and exit-access revocation verification.
Requirements
Tools & Stack
Vanta (GRC/compliance), Mend/WhiteSource (SAST, SCA, container scanning),
OWASP ZAP & Burp Suite (DAST), Nessus (infra/cloud vulnerability
assessment), Trend Micro (log monitoring), Sophos (firewall monitoring).