yoinka

Consultant - Info Security Engineer

Principal Financial Group

Hyderabad, IndiaFull TimeSenior
Sign in to applyVerified 1h ago
Location
Hyderabad, India
Employment
Full Time
Work model
On-Site
Level
Senior
Posted
1h ago

Skills

AWSServerless

About this role

Responsibilities

Unique Opportunity At Principal, we believe in encouraging innovation and excellence. As a Consultant - Info Security Engineer, you will have the outstanding opportunity to collaborate with world-class professionals in Hyderabad, Telangana, India. You'll play a crucial role in ensuring the security and integrity of our applications, both on-premises and in the cloud, by performing security penetration testing. This position is for those who are ambitious and determined to make a significant impact in the field of information security.

Key Responsibilities

Perform manual security penetration assessments of web applications and APIs hosted within on-premises infrastructure. Conduct security assessments on web applications and APIs deployed in cloud environments using AWS services such as S3 buckets, EC2 instances, Lambda functions, API Gateway, and SNS. Apply re-engineering techniques using tools like Echo Mirage, IDAPro, CFF Explorer, Dnspy, MS sys-internals, Wireshark, dotpeek, and ghidra for thick client/desktop applications. Manage Vulnerability Disclosure Program (VDP) and Bug Bounty reports with detailed technical validation, consistent assessment of impact and severity, and fair evaluation aligned with policies. Use CVSS scoring mechanisms to assess risk levels of identified vulnerabilities. Innovatively identify techniques to exploit vulnerabilities in applications, generate impactful proof-of-concepts (POCs), provide walkthroughs to app-dev teams, and offer remediation mentorship. Write comprehensive reports and update existing documentation. Work independently and multi-functionally, mentoring peers and junior team members, helping them learn and apply new attack techniques during security testing.

Qualifications

Qualifications Bachelor’s or Master’s degree in Computer Science, Technology, Engineering, Mathematics, or related fields, or equivalent professional experience (B.E. / B.Tech / M.S. / M.Tech / MCA). 8-10 years of practical experience in security assessment of web applications, web APIs, thick client apps, mobile apps, and AWS services, preferably within the finance domain. Proficiency in using web/API testing tools such as Burp Suite, Postman, and OWASP ZAP. Practical experience with Kali and performing advanced security assessments of applications. Detailed knowledge of common web application security vulnerabilities (OWASP Top Ten, SANS Top 25, etc.), programming patterns leading to them, and remediation techniques. AWS Cloud Practitioner Certification or other cloud certifications are helpful. Additional security certifications like C|EH, CPent, etc., are a plus. Plus/Good to Have Experience in conducting security assessments of AI applications. Understanding of server-less architectures and micro-services on AWS. Be part of Principal's world-class team making a difference. We honor each person's input and strive to maintain a supportive and inclusive culture. We prioritize your professional growth and assist our team in achieving their personal and career objectives. Bring your skills to life and expand your potential with us!

Additional Information

Why Principal? At Principal, we believe in fostering a cooperative and welcoming environment where everyone's input is appreciated. We are committed to your professional development and assist our team members in reaching their personal and career ambitions. Join us and become part of a world-class team that is making an impact!

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Consultant - Info Security Engineer at Principal Financial Group, Hyderabad, India | Yoinka