Cyber Security Automation Engineer

From 5 to 8 year(s) of experience
₹ Not Disclosed by Recruiter
Posted: 23 days agoJob Applicants: 245Job Views: 764

Job Description

  • About this role

Seeking a motivated Security Automation Engineer to join our high-performing engineering team to provide impactful guidance to drive the delivery of secured products and services. In this role, you will help strengthen the security posture and drive the competitive advantage of our comprehensive product portfolio to protect buildings, people, and assets, providing innovative security products that include advanced software and hardware, IP solutions, wireless communications, and electronic locking systems, and mobile applications.

As part of this team, you will work to develop and maintain secure software and controls to support the Software Development Lifecycle (SDLC) for legacy and strategic products. This role is responsible for the implementation of controls to ensure customer software is free from vulnerabilities that can be exploited by an attacker. The ideal candidate would have Security and DevSecOps expertise with the ability to adapt to several different development environments and willingness to be part of a strong team, willing to contribute in a variety of capacities.

Role Responsibilities:

As a Security Automation Engineer, you will focus on the Security by Design of our products and be able to establish, maintain, monitor, and communicate privacy and secure resiliency within our product offerings. Day-to-day responsibilities vary, including but not limited to:

  • Provide security guidance and technical assessments to all stakeholders
  • Provide incident response assistance when there are possible sources of disruption of information and cyber malicious acts and vulnerabilities.
  • Develop and implement DevSecOps and Product Security strategies for SaaS, On-Premises, and Mobile solutions
  • Assurance of secure operations, response, support, and channel engagement for all offerings.
  • Build internal scripts, and automate tools and methodologies to enhance security DevSecOps capabilities.
  • Monitor CI security findings and work with product teams to suggest appropriate corrective actions such as upgrading open-source libraries, tuning configurations, and developing correlation rules.
  • Work with Engineering and security principles to ensure remediation of vulnerabilities.
  • Assemble tools to support the hardening and testing of software and operating systems.
  • Develop automated tooling to aid security engineers, QA & penetration testers in performing security assessments.
  • Perform and participate in web application testing, source code reviews, threat analysis, and security vulnerability mitigation as needed.
  • Product innovation and differentiation leveraging cybersecurity capabilities and expertise
  • Drive secure development principles, practices, and activities within engineering and production to help quantify cybersecurity risk, issues, and defects within our offerings and partner eco-system, such that teams may appropriately characterize, manage, and remediate to standards.
  • Coordinate with delivery teams to help scope projects, define cybersecurity requirements, perform gap analysis, refine functional requirements, and road map residual cyber risk.
  • Perform threat modeling in coordination with delivery teams, security assurance testing, cyber risk assessment, security reviews, and threat vulnerability assessment for all offerings.
  • Provide audit, analysis, and review support for certification, standards, and governance.
  • Provide reporting to program teams regarding production risk, health metrics progress, and set action items.


Minimum Requirements:
  • 5-8 years of experience in the Cybersecurity field, with prior 3-5 yrs of SW development experience
  • Development or scripting experience in either Node.JS, PowerShell, Python
  • Proficient in Windows and Linux operating systems
  • Data encryption crypto communications and encryption key management
  • Familiar with container security practices (Docker, Kubernetes)
  • Experience with SaaS technologies security
  • Knowledge of state of the art in security analysis tools and product security safeguards such as SAST, DAST, Fuzz testing, and OpenSource scanning.
  • Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (OAuth, OpenID, JWT, etc.)
  • Understanding of package managers (Maven, NPM, dpkg, NuGet, etc.)
  • Excellent communication skills
  • Ability to adapt quickly to supported technologies
  • Cross-functional and multi-domain technical aptitude
  • Diverse technical domain experience (ex., Embedded, Enterprise, Mobile, Cloud, etc.)
  • Excellent cybersecurity depth and breadth knowledge and SW engineering skills
  • Strong experience with secure SW development lifecycle, practices, and activities
  • Strong experience with secure by design principles and architecture level security concepts
  • Demonstrated expertise for working w/ cross-functional engineering teams handling complex challenges, delivering results
  • Experience in Cyber Security assessments like threat modeler, Microsoft threat modeling, and mitigating cyber risks.
  • Exposure to basic malware analysis, digital forensics such as participation with incident response red and/or blue teaming, risk vulnerability analysis, and Open Source platforms
  • Knowledge of ISO 27001, CSA, RMF, NIST CSF, or related security standards and frameworks.
  • Integration experience with vulnerability or ticket management systems such as Jira
  • Technical expertise with cloud computing such as Microsoft Azure or Amazon AWS, scripting languages, and integrating 3rd party monitoring tools
  • Experience and understanding of Agile software development practices.
  • Bachelors in computer science field preferably in either computer science, software engineering, Information Assurance, and Cyber Defense or Computing Security. Equivalent experience in lieu of a college degree will be considered with a minimum of one or more certifications demonstrating deep practical knowledge such as CSSLP, CISSP, CISM, GPEN, CCSP, CCSK, AWS Solutions Architect Professional, et. Al.
  • Additional Job Description

Summary
Established Cybersecurity professional. Collects data from a variety of Computer Network Defense (CND) tools, including intrusion detection system alerts, firewall and network traffic logs, and host system logs to analyze events that occur within their environment.

Job Description

  • Supports, designs and develops new systems, applications, and solutions for cybersecurity platforms
  • Supports the integration of new cyber architectural features into existing infrastructures.
  • Provides architectural analysis of cybersecurity solutions and relates existing systems to future needs and trends.
  • Recommends incident response procedures and researches potential network vulnerabilities.
  • Supports identity access management initiatives internally. Participates in internal and external cyber audits.

Minimum Requirements
Requires theoretical to advanced knowledge obtained through a University degree, combined with experience
Practical knowledge of Carrier organization, programs or systems with the ability to make enhancements and leverage in daily work
University Degree or equivalent
A minimum of 3 years prior relevant experience

Role:Cyber Security

Salary: Not Disclosed by Recruiter

Industry:Consumer Electronics & Appliances

Department:IT & Information Security

Role Category:IT Security

Employment Type:Full Time, Permanent

Education

UG:B.Tech/B.E. in Any Specialization,B.Sc in Any Specialization

PG:Any Postgraduate

Company Profile

Carrier

Carrier Global Corporation, global leader in intelligent climate and energy solutions is committed to creating solutions that matter for people and our planet for generations to come. From the beginning, we've led in inventing new technologies and entirely new industries. Today, we continue to lead because we have a world-class, diverse workforce that puts the customer at the center of everything we do.
Company Info
X
View Contact Details+

Contact Company:Carrier

Address:.

Reference Id:30144555

Content provided by Carrier, Info Edge India Limited disclaims all warranties against infringement.
Visit Security Guidelines and Terms and conditions for more comprehensive information in this regard.
Apply