Padmi

Security Platform Engineer Tool Configuration & Data Unification

IndiaPosted 1 month ago
CybersecuritySeniorFull Time; Regular
Apply at Sparix Global

Opens the source posting on shine.com

Source description

About the role

View original

Position: Security Platform Engineer - Tool Configuration & Data Unification Job Type :- Remote IST Experience :- 6 - 8 years Position Overview We are seeking a Security Platform Engineer specializing in Tool Configuration and Data Unification to bring deep security domain expertise to the hands-on configuration of our scanning and aggregation stack. This role is responsible for unifying the output of multiple security scanners into a single, coherent vulnerability language. You will tune what each tool detects, define how findings are normalized and deduplicated, and design the data model that transforms raw scanner output into defensible, evaluated vulnerability records. Working alongside DevSecOps engineers and GRC engineers, you will own the intelligence and structure of the security data pipeline-determining what flows through it and how it is shaped-to support FedRAMP compliance, audit evidence requirements, and actionable vulnerability management at scale. Key Responsibilities Own scanner configuration and tuning across the detection fleet: Scan policies Coverage scope Severity mappings Signal quality for: Trivy Semgrep Qualys Tenable AWS Inspector CrowdStrike Dependabot Design the deduplication and correlation strategy in DefectDojo, including: Keying logic that recognizes the same vulnerability across: Image scans Runtime scans Host scans Dependency scans Grouping rules that collapse duplicate findings into single actionable issues Target: ~70% ticket reduction Define the unified findings data model, including: Field schema Asset identity Component mapping Support the FedRAMP reporting requirements: 11-field vulnerability detail schema 8-field accepted-vulnerability reporting schema Build the reachability signal layer using: AWS Reachability Analyzer Service mesh eBPF-based signals Feed internet-reachability determinations (IRV/NIRV) per finding. Configure runtime visibility using CrowdStrike Falcon Cloud Security. Reconcile runtime observations against image scan results to eliminate the rebuilt-but-not-redeployed gap. Partner with GRC engineers to ensure the data model captures all information required by the: LEV IRV PAIN evaluation engine Audit evidence requirements Validate detection coverage across: Containers Hosts Serverless environments Dependencies External attack surface Identify security blind spots. Required Skills 6+ years of Security Engineering experience with hands-on vulnerability management. Strong understanding of: CVEs CPE/PURL identity Scanner false positives Scanner disagreement analysis Experience configuring and tuning multiple commercial and open-source security scanners in production. Strong data modeling skills for: Normalization Deduplication Enrichment Asset correlation AWS cloud security expertise, including: Container security Image scanning Registry policy Runtime security EKS ECS Working knowledge of: CISA KEV EPSS VEX Vulnerability prioritization Hands-on experience with: Trivy Semgrep Qualys Tenable AWS Inspector CrowdStrike Dependabot Experience with DefectDojo for vulnerability aggregation and deduplication. Preferred (Bonus) Skills Deep DefectDojo experience, including: Deduplication engine Parsers API Experience with network reachability analysis: AWS Reachability Analyzer Service mesh telemetry eBPF tooling Familiarity with FedRAMP concepts: VDR/VER LEV (Likely Exploitable) IRV/NIRV (Internet-Reachable / Non-Internet-Reachable) PAIN ratings Timeframe classes Experience writing custom scanner parsers or findings transformation code in Python. .

One address, no account. We’ll tell you when matching roles go live.

More at Sparix Global

Related open roles

View all roles