Source description
About the role
Sibros Technologies is accelerating the future of SDV excellence with its Deep Connected Platform that orchestrates full vehicle software update management, vehicle analytics, and remote commands in one integrated system. Adaptable to any vehicle architecture, Sibros' platform meets stringent safety, security, and compliance standards, propelling OEMs to innovate new connected vehicle use cases across fleet management, predictive maintenance, data monetization, and beyond. As a Security Engineer II at Sibros, your role will be crucial in driving end-to-end security across web applications, APIs, cloud systems, and emerging firmware layers. You will proactively identify vulnerabilities, integrate security into the SDLC, and build scalable, automated security solutions using modern tools, including AI-driven technologies. Working closely with engineering teams, you will ensure secure design, development, and deployment, while also exploring and strengthening firmware-level security as part of a holistic product security approach. Key Responsibilities: - Perform web & API security testing aligned with OWASP Top 10, including API security - Continuously review code changes/releases and validate vulnerability fixes - Implement and manage SAST, DAST, and automated security scans in pipelines - Discover, track, and maintain API inventory with risk classification - Perform advanced API testing, including API fuzzing and abuse-case testing - Secure cloud environments using various frameworks and remediate misconfigurations and identity risks - Conduct threat modeling based on STRIDE and recommend secure architecture improvements - Build automated security pipelines, enforce security gates, and enhance detection using AI - Provide technical evidence and documentation for internal and external security audits to ensure continuous regulatory compliance Qualifications Required: - 3-5 years of professional work experience in cybersecurity and application security - Hands-on experience in application pentesting on Web and Mobile applications - Proficient in SAST, DAST, and API security testing with tools like Semgrep and Burp Suite - Strong willingness to learn firmware or embedded security - Solid understanding of AWS and GCP environments, including various frameworks - Ability to identify cloud risks and ensure continuous compliance monitoring - Strong grasp of web and API security concepts, focusing on authentication, data exposure, and business logic testing Sibros offers a competitive and generous total compensation package including equity options, flexible vacation and paid time off, team events, budget for online courses, books, and conferences, as well as employee wellness programs to support self-care and overall wellness. Sibros is committed to a policy of equal employment opportunity, recruiting, employing, training, compensating, and promoting without regard to various factors. They value privacy and safeguarding personal information, utilizing third-party service providers for data management solely for recruitment purposes. For more information about Sibros Technologies, visit sibros.tech. Sibros Technologies is accelerating the future of SDV excellence with its Deep Connected Platform that orchestrates full vehicle software update management, vehicle analytics, and remote commands in one integrated system. Adaptable to any vehicle architecture, Sibros' platform meets stringent safety, security, and compliance standards, propelling OEMs to innovate new connected vehicle use cases across fleet management, predictive maintenance, data monetization, and beyond. As a Security Engineer II at Sibros, your role will be crucial in driving end-to-end security across web applications, APIs, cloud systems, and emerging firmware layers. You will proactively identify vulnerabilities, integrate security into the SDLC, and build scalable, automated security solutions using modern tools, including AI-driven technologies. Working closely with engineering teams, you will ensure secure design, development, and deployment, while also exploring and strengthening firmware-level security as part of a holistic product security approach. Key Responsibilities: - Perform web & API security testing aligned with OWASP Top 10, including API security - Continuously review code changes/releases and validate vulnerability fixes - Implement and manage SAST, DAST, and automated security scans in pipelines - Discover, track, and maintain API inventory with risk classification - Perform advanced API testing, including API fuzzing and abuse-case testing - Secure cloud environments using various frameworks and remediate misconfigurations and identity risks - Conduct threat modeling based on STRIDE and recommend secure architecture improvements - Build automated security pipelines, enforce security gates, and enhance detection using AI - Provide technical evidence and documentation for internal and external security audits t
More at SIBROS TECHNOLOGIES INC
Related open roles
Senior Build & Release Engineer
Bangalore · Mumbai
Systems & Operations Analyst (General IT + Automation)
Mumbai
Product Manager (Core Platform and Infrastructure)
Mumbai
Engineering Manager (Backend Engineering)
Bangalore · Mumbai
Engineering Manager, Backend Engineering
Mumbai
Product Manager (Core Platform and Infrastructure)
Mumbai