Lead Information Security Engineer

24 Minutes ago • 10 Years +
Cyber Security

Job Description

The Lead Information Security Engineer designs, develops, and implements IT security solutions for new and existing applications, systems, and networks, both on-premise and cloud-based. This role involves reviewing system requirements, coding, testing, and debugging software solutions. Key responsibilities include performing penetration testing, Red Teaming, and risk assessments, serving as the primary security contact for Google cloud projects, and evaluating software fixes for sophisticated system vulnerabilities. The engineer will also conduct security assessments using ethical hacking tools and support regulatory compliance initiatives.
Must Have:
  • Design, develop, modify, adapt, and implement IT security solutions.
  • Review system requirements and business processes.
  • Code, test, debug, and architect on-premise and cloud-based software solutions.
  • Perform penetration testing, Red Teaming, and Risk assessments.
  • Serve as Information Security primary point of contact for Google cloud projects.
  • Test and validate solutions to remediate exploitable conditions on applications.
  • Evaluate software fixes for system vulnerabilities (e.g., SQL injection, XSS).
  • Conduct security assessments using penetration tests and ethical hacking tools.
  • Review security designs for complex environments.
  • Support regulatory compliance initiatives.
  • Degree in Computer Science, Information Systems, or equivalent experience.
  • At least 10 years of experience.
  • Certifications: MCSE, GIAC, GSEC, GCFW, GCIA, GCIH, GISO, GSNA, GCFA, GSLC, GPEN, CISA, CISSP, CCSP.
  • Experience with DAST, SAST, Web Application Penetration Testing tools.
Perks:
  • Hybrid work environment (at least 2 days a week in office)
  • Flexibility and accessibility
  • Total rewards program (You&Q)
  • Support for building wealth
  • Career growth opportunities
  • Prioritizing well-being
  • Family care benefits

Add these skills to join the top 1% applicants for this job

risk-management
risk-assessment
game-texts
ethical-hacking
cross-site-scripting
sql

Designs, develops, modifies, adapts and implements short- and long-term solutions to support information technology (IT) needs for new and existing applications, systems architecture, network systems and applications infrastructure. Reviews system requirements and business processes; codes, tests, debugs and architects on premise and cloud-based software solutions. Performs penetration testing, Red Teaming and Risk assessments for cloud-based and on-premise systems.

  • Serves as Information Security primary point of contact for a Google cloud-based technology project
  • Designs, develops, implements, and solves problems with various information systems security software ensuring resolution.
  • Tests, and validates solutions to remediate exploitable conditions on applications.
  • Evaluates software fixes (patches) to address sophisticated system vulnerabilities such as malicious code (e.g., viruses), system exploitation using SQL injection, cross-site scripting, buffer overflows, parameter tampering, hidden field manipulation, cookie poisoning, and Web services manipulation.
  • Conducts security assessments of complex systems, networks and applications using penetration tests and ethical hacking tools and risk assessment/mediation methodologies to evaluate vulnerabilities. Prepares status reports on security matters to develop security risk analysis scenarios and response procedures.
  • Reviews security designs for complex environments.
  • Displays technical knowledge and expertise, in addition to a thorough understanding of the industry, when examining security issues, techniques and implications across multiple computing platforms and of varying complexity.
  • Supports regulatory compliance initiatives related to the industry regulation
  • Works with teams across the organizations involved in the project to deliver information security related tasks

Requirements

  • Education Required: Degree qualified in Computers Science, Information Systems or other related discipline, or equivalent work experience.
  • Experience Required: At least 10 years
  • Special Qualifications: Has completed one or more of the following Certifications and/or Professionalization status: MCSE certification; GIAC, GSEC, GCFW, GCIA, GCIH, GISO, GSNA, GCFA, GSLC; GPEN, CISA, CISSP, CCSP certifications.
  • Experience with application security tools: DAST, SAST, Web Application Penetration Testing.

This position offers the opportunity for a hybrid work environment (at least 2 days a week in office, subject to change), providing flexibility and accessibility for qualified candidates.

Come as You Are

Nasdaq is an equal opportunity employer. We positively encourage applications from suitably qualified and eligible candidates regardless of age, color, disability, national origin, ancestry, race, religion, gender, sexual orientation, gender identity and/or expression, veteran status, genetic information, or any other status protected by applicable law.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.

Set alerts for more jobs like Lead Information Security Engineer
Set alerts for new jobs by Nasdaq
Set alerts for new Cyber Security jobs in Canada
Set alerts for new jobs in Canada
Set alerts for Cyber Security (Remote) jobs

Contact Us
hello@outscal.com
Made in INDIA 💛💙