À propos de ce poste Security Engineer chez Anchanto
AWS & Application Security Engineer
Experience: 5+ Years
Location: Pune,India
Job Role Pointers:
- Conduct security assessments, VAPT, and penetration testing of web applications, mobile applications, AWS infrastructure, and networks.
- Perform security reviews of AWS accounts, VPCs, EC2 instances, EKS clusters, RDS databases, S3 buckets, Load Balancers, and serverless services.
- Implement and manage AWS security services such as GuardDuty, Security Hub, AWS Config, Inspector, CloudTrail, WAF, Shield, and IAM.
- Conduct regular cloud security posture assessments and identify misconfigurations against AWS security best practices and CIS benchmarks.
- Identify security vulnerabilities, misconfigurations, and compliance gaps, and drive remediation efforts.
- Hands-on experience with Ansible Automation for server provisioning, configuration management, security hardening, patch management, and compliance enforcement.
- Develop and maintain Ansible playbooks for automating security controls, vulnerability remediation, user access management, and AWS infrastructure deployments.
- Perform and support internal/external security audits and compliance assessments.
- Prepare security test cases, audit checklists, VAPT reports, and risk assessment reports.
- Coordinate with engineering and infrastructure teams to remediate findings within defined timelines.
- Implement OWASP security best practices and support secure SDLC initiatives.
- Perform Linux server hardening and infrastructure security reviews.
- Support firewall, network security, cloud security monitoring, and incident response activities.
Required Skills
- Strong hands-on experience in AWS Security, Application Security, and VAPT.
- Hands-on experience with AWS Security Hub, GuardDuty, Inspector, CloudTrail, Config, WAF, Shield, Secrets Manager, and KMS.
- Experience securing containerized environments such as Docker and Kubernetes
- Expertise with tools such as Burp Suite Pro, Nessus, Qualys, Acunetix, Netsparker, Metasploit, WebInspect, and Nmap.
- Experience with OWASP Top 10, secure coding practices, and cloud security controls.
- Good understanding of Linux administration, server hardening, and network security.
- Experience participating in at least two security audits, with one conducted in the last 12 months.
- Excellent analytical, documentation, and communication skills.
Preferred
- Experience in SaaS, e-commerce, or product-based organizations.
- Certifications such as AWS Security Specialty, CISM, or ISO 27001 Lead Auditor.