AI Jobs Map

UST · Kochi, Kerala, India

Offensive Security Engineer

mid_levelfull timePosted today
Apply on LinkedInLinkedInOpens the original posting. AI Jobs Map never asks for your details.

Stack mentioned

ci/cdcybersecuritydevsecopspythonpowershellapplication-securitypenetration-testingpci-dssiso-27001vulnerability-management

Role Description

Job Description We have an exciting opportunity for an Offensive Security Engineer to join our Technology team. This role plays an important part in protecting the confidentiality, integrity, availability and resilience of technology and data by identifying exploitable weaknesses before they cause harm, validating the effectiveness of security controls, and supporting safer delivery across our technology environment. Reporting to the Senior Manager, Security Compliance & Governance, you’ll work closely with engineering, cloud, platform, infrastructure, architecture and security teams to embed security early in the software development lifecycle, reduce vulnerabilities reaching production, and provide evidence-based assurance across applications, APIs, cloud environments and security controls. This is a hands-on role for someone who enjoys practical security testing, automation, threat emulation, vulnerability lifecycle management and working with technical teams to improve security outcomes in a complex enterprise environment. What You’ll Do

- Plan and perform authorised, risk-based security testing across web applications, APIs, infrastructure, networks, identity services and cloud-hosted workloads.

- Operate, administer and optimise security testing platforms, including SAST, DAST, CSPM and attack simulation tooling.

- Embed security testing early in the software development lifecycle and support secure development practices across engineering teams.

- Integrate application security, dependency, open-source risk, DAST and API security testing controls into code repositories, IDEs and CI/CD pipelines.

- Conduct authorised penetration testing, technical security assessments, security design reviews and threat modelling for material changes.

- Validate, triage and document security findings, including severity, business impact, accountable owners, target remediation dates and closure evidence.

- Track remediation progress, retest resolved vulnerabilities and escalate overdue or material findings where required.

- Use cloud security posture management tooling to assess cloud vulnerabilities, misconfigurations, attack paths and compliance posture.

- Conduct MITRE ATT&CK-aligned control validation, adversary emulation and purple team activities across key security controls.

- Provide practical remediation advice to engineering and technology teams, including guidance aligned to OWASP Top 10, PCI DSS secure coding requirements and secure AI development practices.

- Automate repeatable discovery, testing, ticketing, evidence collection, reporting, remediation tracking and validation activities where practical.

- Produce evidence-based reports, service metrics and control-effectiveness insights to support operational, executive, audit and governance reporting. What You’ll Bring

- Experience in cybersecurity, application security, penetration testing, security engineering or DevSecOps.

- Strong knowledge of web application, API and cloud security.

- Hands-on experience with security testing tools such as SAST, DAST and CSPM platforms.

- Understanding of secure software development and CI/CD environments.

- Experience identifying, validating and remediating security vulnerabilities.

- Knowledge of security frameworks including OWASP Top 10, MITRE ATT&CK, ISO 27001, NIST and PCI DSS.

- Ability to automate tasks using scripting languages such as Python or PowerShell.

- Strong analytical and problem-solving capabilities.

- Excellent stakeholder engagement and communication skills.

- Ability to provide practical, risk-based security advice to technical and business teams.

- Relevant cybersecurity qualifications, certifications or equivalent industry experience.

- A passion for emerging security technologies, automation and continuous improvement.

Skills

Vulnerability Management, Vulnerability Assessment and Penetration Testing, Threat Modeling, Vulnerability Assessment, Application Security, CI/CD, CSPM, Security Engineering, Cloud Security, Python, ISO 27001

More jobs at UST