Padmi

Security Engineer (Application Security / TPRM)

HyderabadPosted 2 months ago
CybersecurityMid-levelFull Time; Regular
Apply at Implere Technologies Pvt Ltd

Opens the source posting on shine.com

Source description

About the role

View original

Security Engineer (Application Security / TPRM) Location: Bengaluru Mode: Hybrid Experiance : 4+ years Role Overview The role focuses on assessing the security posture of third-party vendors before the organization shares sensitive data with them. The primary objective is to ensure vendors meet the organization's security standards and do not introduce security risks. Key Responsibilities Discussed Review SAST and DAST reports to identify application security vulnerabilities. Analyze Application Penetration Testing reports and ensure critical findings are remediated. Perform Threat Modeling to identify potential attack vectors during the design phase. Assess Cloud Security across AWS, Azure, and GCP, including IAM, encryption, network security, and cloud configurations. Conduct Third-Party Risk Management (TPRM) assessments to determine whether external vendors are secure enough to process or store company data. Review vendor security documentation, compliance certifications (SOC 2, ISO 27001, NIST), and security controls. Collaborate with vendor engineering and security teams to address identified security gaps. Key Skills to Target Application Security (AppSec) SAST / DAST Application Penetration Testing Threat Modeling Cloud Security (AWS / Azure / GCP) API Security TPRM (Third-Party Risk Management) Vendor Security Assessments Security Architecture Reviews BEST FIT Candidates with hands-on experience in Application Security, Cloud Security, thread modeling and Third-Party Risk Management (TPRM). Candidates who have experience evaluating whether third-party applications and cloud environments are secure enough to handle organizational data will be given Priority Security Engineer (Application Security / TPRM) Location: Bengaluru Mode: Hybrid Experiance : 4+ years Role Overview The role focuses on assessing the security posture of third-party vendors before the organization shares sensitive data with them. The primary objective is to ensure vendors meet the organization's security standards and do not introduce security risks. Key Responsibilities Discussed Review SAST and DAST reports to identify application security vulnerabilities. Analyze Application Penetration Testing reports and ensure critical findings are remediated. Perform Threat Modeling to identify potential attack vectors during the design phase. Assess Cloud Security across AWS, Azure, and GCP, including IAM, encryption, network security, and cloud configurations. Conduct Third-Party Risk Management (TPRM) assessments to determine whether external vendors are secure enough to process or store company data. Review vendor security documentation, compliance certifications (SOC 2, ISO 27001, NIST), and security controls. Collaborate with vendor engineering and security teams to address identified security gaps. Key Skills to Target Application Security (AppSec) SAST / DAST Application Penetration Testing Threat Modeling Cloud Security (AWS / Azure / GCP) API Security TPRM (Third-Party Risk Management) Vendor Security Assessments Security Architecture Reviews BEST FIT Candidates with hands-on experience in Application Security, Cloud Security, thread modeling and Third-Party Risk Management (TPRM). Candidates who have experience evaluating whether third-party applications and cloud environments are secure enough to handle organizational data will be given Priority

One address, no account. We’ll tell you when matching roles go live.

More at Implere Technologies Pvt Ltd

Related open roles

View all roles