Information Technology Security Engineer
Job Description
Requirements:
- Bachelor's Degree in Software Engineering / Computer Science / Information Technology / equivalent or relevant work experience.
- Good at managing sensitive and confidential data, workstation devices, patching and upgrading systems, applications, services, and other infrastructure foundational components.
- Familiar with ISO27001
- Familiar with Linux and Windows OS
- Familiar with cloud security services such as AWS, Azure, and GCP
- Able to create some script, i.e., bash, python
- Having certification in cloud security area is a plus
Job Descriptions:
- Penetration Testing & Red Teaming: Conducted attack simulations and red teaming activities on internal applications to identify critical security vulnerabilities (e.g., SQLi, XSS, brute force, authorization flaws) and developed PoCs detailing technical and business impacts.
- Dependency Analysis & Validation: Identified and analyzed over 100 packages/dependencies per application using CVE databases, GHSA, and CVSS score metrics to map third-party component risks.
- False Positive Elimination: Performed manual source code reviews and manual exploit replications based on CVEs to ensure vulnerabilities were true positives, optimizing mitigation priorities.
- Secure SDLC Implementation: Executed security reviews and rigorous testing for every feature addition or application change prior to production deployment.
- Reporting & Cross-Divisional Collaboration: Authored detailed penetration testing reports (findings, risk levels, mitigations) and presented them to both technical teams and non-technical management in clear, accessible language.
- Security Standards Consultation: Provided architecture and security governance compliance recommendations based on CIS Controls, ISO 27001, OWASP, PTES, and NIST SP 800-115 frameworks.
