Lead design and implementation of enterprise application, cloud, and infrastructure security. Embed AppSec and DevSecOps controls (SAST/DAST/SCA) into CI/CD, perform risk and vulnerability assessments, design secure architectures, lead SIEM deployments, support incident response and compliance (NIST, ISO 27001, PCI DSS, GDPR), and provide security guidance and training to stakeholders.
The Security Consultant is responsible for assessing, designing,
implementing, and maintaining information security controls to protect
organizational systems, networks, and data. The role ensures compliance with
security standards, manages cyber risks, and supports secure digital
transformation initiatives.
Key Responsibility:
1. Security Assessment & Risk Management
- Architect
enterprise-wide Application Security (AppSec) programs across complex,
distributed enterprise environments—embedding SAST, DAST, and SCA into
CI/CD pipelines to enable secure-by-design architecture and reduce
vulnerabilities.
- Define
secure architecture patterns and guardrails, integrating AppSec controls
into DevSecOps pipelines to standardize risk management across
distributed engineering teams.
- Collaborated
with Customer Security teams to embed security architecture principles
to produce secure project environment.
- Experience in Application Security governance frameworks,
aligning with NIST, ISO 27001, and PCI DSS to achieve compliance posture
and audit readiness
- Conduct
security risk assessments, vulnerability assessments, and threat
modeling across applications, infrastructure, and networks.
- Identify
security gaps and provide risk-based mitigation recommendations.
- Perform
periodic security posture reviews and maturity assessments.
2. Security Architecture & Solution Design
- Design
and review secure architecture for applications, cloud, and on-premise
systems.
- Ensure
security-by-design principles are embedded in system development and
integration.
- Review
technical designs to ensure alignment with security standards and best
practices.
3. Application & Infrastructure Security
- Support
and define application security testing (SAST, DAST, API security
testing).
- Support
secure coding practices and review source code for vulnerabilities.
- Assess
infrastructure security including servers, databases, networks, and
endpoints.
4. Cloud & DevSecOps Security
- Implement
and review cloud security controls for AWS, Azure, or GCP environments.
- Integrate
security tools into CI/CD pipelines (DevSecOps).
- Lead full-lifecycle
SIEM deployments, from HLD/LLD design through to steady-state
operations.
- Produce detailed
solution proposals, policies, and procedures to support secure, reliable
SIEM services
- Ensure secure configuration,
identity access management, and logging in cloud platforms.
5. Security Operations & Incident Management
- Support
security incident detection, response, and investigation activities.
- Perform
root cause analysis and recommend corrective and preventive actions.
- Coordinate
with SOC, IT, and business teams during security incidents.
6. Compliance & Governance
- Ensure
compliance with security frameworks and regulations (ISO 27001, NIST,
GDPR, etc.).
- Support
internal and external security audits and risk assessments.
- Develop
and maintain security policies, standards, and procedures.
7. Awareness & Stakeholder Engagement
- Provide
security guidance to development, infrastructure, and business teams.
- Conduct
security awareness sessions and training programs.
- Act
as a trusted advisor on security best practices and emerging threats.
8. Continuous Improvement & Reporting
- Stay
updated with latest cyber security threats, vulnerabilities, and trends.
- Prepare
security assessment reports, dashboards, and risk summaries for
management.
- Recommend
continuous improvements to enhance organizational security posture.
Requirements
Qualification: Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field.
Professional Certificate Preferred:
- CISSP (Certified Information Systems
Security Professional).
- CISM (Certified Information Security
Manager).
- CEH (Certified Ethical Hacker).
- ISO/IEC 27001 Lead Implementer or Lead
Auditor.
- AWS / Azure / GCP Security Certification.
- CompTIA Security+ (added advantage).
Years of Exp: 8-13 years of experience in information security, cyber security
consulting, or related roles
Job Specific Skill:
- Strong knowledge of cyber security
principles, tools, and frameworks.
- Hands-on experience with vulnerability
assessment and penetration testing tools.
- Experience in application, infrastructure,
and cloud security.
- Knowledge of security compliance and
regulatory standards.
- Understanding of networking, operating
systems, and databases.
- Strong documentation, reporting, and
stakeholder communication skills.
Similar Jobs
Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Provides systems safety engineering for aircraft turbine engines and power systems. Conducts hazard, reliability, and root cause analyses; develops safety requirements, plans, procedures, and reports; reviews designs for regulatory compliance; manages requirements using DOORS; supports certification and qualification; collaborates cross-functionally on risk mitigation, reliability metrics, process automation, and AI-enabled safety improvements.
Top Skills:
Aircraft Turbine EnginesArp 4754Arp 4761Artificial IntelligenceAuxiliary Power UnitsDoorsDoors NgEasaFaaFailure Modes And Effects Analysis (Fmea)Fault Tree Analysis (Fta)Functional Hazard Analysis (Fha)Model Based Safety AnalysisModel Based Systems EngineeringSystems Safety Analysis (Ssa)
Aerospace • Artificial Intelligence • Cloud • Machine Learning • Software • Cybersecurity • Defense
Technically lead the Avionics Testing End State team by defining test requirements and scenarios, designing test hardware and software, reviewing layouts, diagnosing production issues, and supporting troubleshooting. The role owns the PBA test functional area, designs ATEs and interface test adapters, provides technical recommendations, mentors engineers, supports strategic initiatives, and communicates with customers and cross-functional teams.
Top Skills:
Automated Test Equipment (Ate)Avionics TestingCable Harness DesignHardware LayoutInterface Test AdaptersTest Hardware DesignTest Software
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Analyze, develop, and execute integration test cases for network systems. Prepare and validate scripts and configurations, troubleshoot issues, perform integration and migration tasks, and maintain accurate operating system, hardware, software, licensing, and configuration data. The role also involves project scoping, cost and time estimation, process adherence, service delivery, stakeholder management, data security, privacy, and compliance with environmental, occupational health, safety, legal, and financial requirements.
Top Skills:
Artificial IntelligenceAutomationData AnalyticsHardwareOperating SystemsSoftware Configuration
What you need to know about the Kolkata Tech Scene
When considering the industries shaping India's tech scene, gaming might not immediately come to mind. However, in the last decade, increased internet usage and greater access to mobile devices have catapulted the industry to new heights, with Kolkata-based companies like Virtualinfocom, Red Apple Technologies and Digitoonz, at the forefront, driving the design and animation of new gaming titles for players.


