Crisil
Crisil3h ago
Foundit

Security Engineer

Mumbai
Mid Level

Auto Apply to 50+ AI Matched Security Engineer Jobs

Use Auto Apply Agents to Bulk Apply jobs with ATS Optimised Resumes, find verified Insider Connections for jobs at Crisil

Full Job Description

Security Engineer - Information Security

Company: Crisil

Location: Mumbai

Job Overview

Crisil is seeking a skilled Security Engineer with a focus on Information Security to join our team in Mumbai. This role is critical for maintaining the security posture of our servers and ensuring compliance with industry standards.

Key Responsibilities

Vulnerability Assessment & Management

Conduct comprehensive server vulnerability assessments (VA) and meticulously track remediation efforts. Perform thorough configuration reviews to ensure strict adherence to security baselines. Leverage tools like Qualys VMDR or equivalent platforms for scanning, analysis, and reporting of vulnerabilities. Collaborate closely with system administrators to validate and promptly patch identified vulnerabilities.

Server Hardening & Configuration Review

Execute detailed server configuration reviews based on established CIS benchmarks and industry best practices. Propose and implement robust server hardening measures to enhance security. Guarantee compliance with relevant industry security standards and internal organizational policies.

VAPT & Security Testing

Perform Vulnerability Assessment and Penetration Testing (VAPT) across servers and network infrastructure. Engage effectively with third-party security testing vendors to review their findings and ensure timely and effective fixes. Manage and track security incidents directly related to server vulnerabilities.

Compliance & Risk Management

Ensure adherence to critical security standards including OWASP, ISO 27001, PCI DSS, NIST, and other relevant security frameworks. Collaborate with internal teams to effectively close security gaps identified during audits and risk assessments. Maintain comprehensive documentation of security controls, remediation plans, and compliance reports.

Vendor Management

Evaluate security vendors, critically review their security reports, and diligently track their remediation efforts. Coordinate with third-party vendors for security audits and essential compliance checks. Ensure that vendor-provided solutions consistently meet and comply with established security policies.

Required Skills & Qualifications

  • Bachelor's degree in Computer Science, Information Security, or Engineering (BE/B.Tech).
  • 3-5 years of proven experience in server security, vulnerability assessment, and compliance management.
  • Hands-on experience with vulnerability scanning tools such as Qualys VMDR, Nessus, or equivalent.
  • Strong knowledge of CIS benchmarks, server hardening techniques, and overarching security best practices.
  • Demonstrated experience in VAPT and various security testing methodologies.
  • Solid understanding of security compliance frameworks including ISO 27001, PCI DSS, NIST, or others.
  • Excellent analytical and communication skills, enabling effective collaboration with internal teams and external vendors.

Preferred Certifications

  • Certified Ethical Hacker (CEH)
  • ECSA
  • CompTIA Security+
  • GIAC Security Essentials (GSEC)
  • Qualys Certified Specialist (QCS) (Preferred)

Join Crisil in Mumbai to contribute to our robust information security infrastructure.

Company

Crisil

Crisil

Mumbai
Posted on Foundit