Point your AI agent at freehire and let it find you a job.

Get the CLI →

Pragma Edge

Security and GRC Specialist - 5-10Yrs - Hyderabad

Posted 4 views
Discussion

Summary

Leads Pragma Edge's end-to-end security function from Hyderabad, owning governance/risk/compliance (ISO 27001, SOC 2, NIST, Vanta), application security (secure code review, SAST/DAST/SCA via Mend, OWASP ZAP, Burp Suite), penetration testing, cloud & infrastructure security (Nessus, AWS), threat monitoring (Trend Micro, Sophos), and external attack surface management.

Job Description: Lead — Security, GRC & Application Security

Role Summary

This role leads Pragma Edge's end-to-end security function — spanning governance/compliance, application security, cloud & infrastructure security, threat monitoring, and external attack surface management. The Lead owns the security posture across internal systems, client-facing products, and cloud/on-prem infrastructure, and is the primary point of accountability for audit readiness, client TPRM responses, and remediation across every layer of the stack.

Core Responsibilities

1. Governance, Risk & Compliance (GRC)

  • Own and maintain security policies (Access Control, Incident Response, Data Protection, SDLC) — review and update on a recurring cycle.
  • Conduct risk assessments and client Third-Party Risk Management (TPRM) reviews; maintain and update the Vanta risk register and track remediation to closure.
  • Map controls to ISO 27001, SOC 2, NIST, and OWASP standards.
  • Own audit evidence collection — logs, screenshots, approvals — for both internal and external audits.
  • Lead quarterly internal audits (client-specific) and HR audits; own annual external audit and ongoing Vanta compliance management.

2. Application Security & Secure Development

  • Perform secure code reviews on critical APIs and backend services.
  • Own OWASP Top 10 remediation (BOLA, BFLA, Injection, Security Misconfigurations).
  • Run Software Composition Analysis (SCA) — dependency vulnerability management, SBOM generation, license review, remediation validation.
  • Own SAST scanning across JAR, Python, and Maven artifacts using Mend/WhiteSource; own DAST scanning (web app + API) using OWASP ZAP and Burp Suite.
  • Run container/image vulnerability scanning (Mend CLI).
  • Coordinate SAST/DAST/SCA findings with development teams, validate fixes, and perform rescans.

3. Penetration Testing

  • Build and execute pentesting plans for web applications, APIs, and products.
  • Own client communication throughout pentest engagements, produce findings reports, and drive remediation to closure.

4. Cloud & Infrastructure Security

  • Review cloud IAM, network rules, and storage exposure; own security hardening (insecure configs, headers, TLS, secrets).
  • Run infrastructure vulnerability assessments (Active Directory, switches, routers, internal servers) via Nessus.
  • Run cloud compliance scans and client-specific AWS security/compliance assessments via Nessus.
  • Own network security review, configuration validation, and hardening recommendations.
  • Manage on-prem security: installation requests, firewall changes, domain whitelisting, and inbound/outbound IP access control.
  • Validate backup, restore, and DR readiness; improve audit logging and SIEM integration.

5. Threat Monitoring & Security Operations

  • Monitor security logs (Trend Micro) and firewall logs (Sophos) — event review, traffic analysis, and investigation.
  • Coordinate remediation with Infrastructure, Cloud, Networking, and Development teams; produce vulnerability reporting across infrastructure, cloud, application, and product layers.

6. External Attack Surface Management

  • Run weekly public IP discovery and maintain external asset inventory.
  • Perform external reconnaissance, port scanning, and service enumeration.
  • Own subdomain enumeration, takeover validation, and DNS verification.
  • Run external vulnerability scanning and validation; monitor for exposed company-sensitive information on the internet.

7. Training, Awareness & Documentation

  • Run security awareness training and phishing simulations; run developer secure-coding sessions (OWASP/API security).
  • Prepare security assessments, training plans, test evaluations, and score analysis.
  • Own compliance documentation: Access Change Requests, Device Disposal records, Incident Response documentation, Tabletop Exercise (TTE) documentation.
  • Own security documentation: policies, assessment reports, remediation reports.
  • Provide audit support: quarterly evidence, compliance reporting, vulnerability tracking, and exit-access revocation verification.


Requirements

Tools & Stack

Vanta (GRC/compliance), Mend/WhiteSource (SAST, SCA, container scanning), OWASP ZAP & Burp Suite (DAST), Nessus (infra/cloud vulnerability assessment), Trend Micro (log monitoring), Sophos (firewall monitoring).



Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available