1. Security Assessment & Risk Management
- Architect
enterprise-wide Application Security (AppSec) programs across complex,
distributed enterprise environments—embedding SAST, DAST, and SCA into
CI/CD pipelines to enable secure-by-design architecture and reduce
vulnerabilities.
- Define
secure architecture patterns and guardrails, integrating AppSec controls
into DevSecOps pipelines to standardize risk management across
distributed engineering teams.
- Collaborated
with Customer Security teams to embed security architecture principles
to produce secure project environment.
- Experience in Application Security governance frameworks,
aligning with NIST, ISO 27001, and PCI DSS to achieve compliance posture
and audit readiness
- Conduct
security risk assessments, vulnerability assessments, and threat
modeling across applications, infrastructure, and networks.
- Identify
security gaps and provide risk-based mitigation recommendations.
- Perform
periodic security posture reviews and maturity assessments.
2. Security Architecture & Solution Design
- Design
and review secure architecture for applications, cloud, and on-premise
systems.
- Ensure
security-by-design principles are embedded in system development and
integration.
- Review
technical designs to ensure alignment with security standards and best
practices.
3. Application & Infrastructure Security
- Support
and define application security testing (SAST, DAST, API security
testing).
- Support
secure coding practices and review source code for vulnerabilities.
- Assess
infrastructure security including servers, databases, networks, and
endpoints.
4. Cloud & DevSecOps Security
- Implement
and review cloud security controls for AWS, Azure, or GCP environments.
- Integrate
security tools into CI/CD pipelines (DevSecOps).
- Lead full-lifecycle
SIEM deployments, from HLD/LLD design through to steady-state
operations.
- Produce detailed
solution proposals, policies, and procedures to support secure, reliable
SIEM services
- Ensure secure configuration,
identity access management, and logging in cloud platforms.
5. Security Operations & Incident Management
- Support
security incident detection, response, and investigation activities.
- Perform
root cause analysis and recommend corrective and preventive actions.
- Coordinate
with SOC, IT, and business teams during security incidents.
6. Compliance & Governance
- Ensure
compliance with security frameworks and regulations (ISO 27001, NIST,
GDPR, etc.).
- Support
internal and external security audits and risk assessments.
- Develop
and maintain security policies, standards, and procedures.
7. Awareness & Stakeholder Engagement
- Provide
security guidance to development, infrastructure, and business teams.
- Conduct
security awareness sessions and training programs.
- Act
as a trusted advisor on security best practices and emerging threats.
8. Continuous Improvement & Reporting
- Stay
updated with latest cyber security threats, vulnerabilities, and trends.
- Prepare
security assessment reports, dashboards, and risk summaries for
management.
- Recommend
continuous improvements to enhance organizational security posture.
|