Security engineer - management Job at NITYA Software Solutions, Inc., Mountain View, CA

T1NKa3NKU0l0MWxLZ0ZYOGd3LzJodHNZTEE9PQ==
  • NITYA Software Solutions, Inc.
  • Mountain View, CA

Job Description

Role: Security Engineer - Vulnerability Management

Location: Mountain View CA (100% Onsite)

C2C

Security Engineer - Vulnerability Management Role

Must-Have Skills (Non-Negotiable) - Vulnerability Management.
1. Proficient in Analyzing and prioritizing security vulnerabilities based on risk.
2. Proficient in Developing mitigation strategies and remediation plans.
3. Must be able to use environmental and threat intelligence for vulnerability analysis.
4. Experience in Securing environments in AWS, Google Cloud Platform, Docker, Kubernetes.
5. Proficient in Python, Java, Ruby, Node for security automation.
6. Experience with Tableau, Qlik Sense, SQL for security insights.

Good-to-Have Skills (Preferred but Not Mandatory) - Vulnerability Management.
1. Experience mitigating WAF evasion techniques.
2. Ability to influence engineering teams for secure coding practices.
3. Use AI-driven analytics for vulnerability detection and response.
4. Knowledge of security frameworks and regulatory compliance.

DETAILED JOB DUTIES

Skill Set for Security Engineer - Vulnerability Management Role

Must-Have Skills (Non-Negotiable) Vul. Mgmt

  1. Identify, Analyze, and Prioritize the Impact of Vulnerabilities
    1. Assess and prioritize vulnerabilities based on real-world impact.
    2. Examples: Using risk-based factors beyond CVSS, incorporating threat intelligence and environmental factors.
    3. Tools: OWASP, SANS 25, AWS Security Hub, Tableau, Qlik Sense for risk assessment.
  2. Mitigation if Patch is Not Ready
    1. Implement compensating controls and temporary mitigations for unpatched vulnerabilities.
    2. Examples: Using WAF rules, network segmentation, access controls until a patch is available.
    3. Tools: AWS, Kubernetes, Docker Security Measures, Advanced WAF Configurations.
  3. Automating Future Detection
    1. Develop and implement automated detection mechanisms for vulnerabilities.
    2. Examples: Automating scans, continuous vulnerability assessment, and reporting.
    3. Tools: Python, Java, Ruby, Node, AWS Security Hub, JIRA, ServiceNow.
  4. Detecting Malicious Payloads
    1. Identify and prevent malicious payloads before execution.
    2. Examples: Using threat intelligence and behavioural analytics for payload detection.
    3. Tools: CrowdStrike, AWS GuardDuty, SIEM solutions.
  5. Blocking Advanced WAF Evasion Techniques
    1. Enhance Web Application Firewall (WAF) security to detect and block advanced evasion attempts.
    2. Examples: Implementing custom WAF rules and monitoring attack patterns.
    3. Tools: AWS WAF, Cloudflare, ModSecurity, Imperva.
  6. Automating Threat Responses
    1. Automate incident response workflows for detected vulnerabilities.
    2. Examples: Using security playbooks to trigger automated remediation actions.
    3. Tools: AWS Lambda, Python automation, SIEM integrations.
  7. Risk-Based Factors Beyond CVSS
    1. Consider additional risk factors beyond CVSS scores when prioritizing vulnerabilities.
    2. Examples: Evaluating exploitability, business impact, attack surface exposure.
    3. Tools: Threat intelligence feeds, vulnerability management dashboards.

Good-to-Have Skills (Preferred but Not Mandatory) Vul. Mgmt

  1. Cloud Security & Container Security
    1. Secure AWS, Google Cloud Platform, Kubernetes, Docker environments.
  2. Data Analytics for Security Posture Improvement
    1. Utilize Tableau, Qlik Sense, SQL for security data analysis.
  3. Experience in Influencing Secure Software Development
    1. Work with developers to build security-first applications.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

Report this job
  • Dice Id: RTX1bee1d
  • Position Id: 8568302

Job Tags

Temporary work,

Similar Jobs

Archer Travel

Work-From-Home Travel Agent Job at Archer Travel

 ...travel agents. As a 1099 contractor, you'll have the freedom to work from anywhere, set your own hours, and enjoy unlimited earning potential...  ...! Let's get you started on an exciting journey as a work-from-home travel agent! Employment Type: Contractor Salary: $ 100,000.... 

SportsCare & Armworks Physical and Hand Therapy

Certified Hand Therapist Occupational or Physical Therapist Job at SportsCare & Armworks Physical and Hand Therapy

 ...About SportsCare and Armworks Physical and Hand Therapy: Armworks Hand Therapy was started in 2006 by certified hand therapist, Ryan Glover, with a goal to provide caring and excellent therapy to the elbow, wrist and hand. Our team of therapists focus on being educators... 

Lazy Acre Trucking LLC

Class A OTR Truck Driver Job Job at Lazy Acre Trucking LLC

Class A OTR Truck Driver JobLazy Acre Trucking LLC currently has an open position for an over the road truck driver. Applicant must have a current CDL and must have held it for a minimum of two years. Must be able to pass background and drug/alcohol screening test. Flat... 

The Good Seed CDC

Access Phone Distributor Job at The Good Seed CDC

 ...Job Title: Access/Lifeline Phone Distributor Location: Los Angeles, CA Compensation...  ...potential clients as needed. Work independently to meet and exceed enrollment targets....  ...the potential for high earnings. Opportunity to make a significant impact in your... 

Schmidt's Sausage Haus

Bartender and Server Job at Schmidt's Sausage Haus

 ...Schmidt Sausage is looking for enthusiastic, high energy, bartender and server who enjoys a challenge. Full-time positions with evening and weekend availability. Our family owned and operated business has over 130 years in the food service industry. General responsibilities...