4486-Security Engineer II
Innovaccer Analytics Noida, Uttar Pradesh, India
Hospitals and Health Care · 1,001-5,000 employees
About the role
The Security Engineer II will perform end-to-end security assessments, including penetration testing and threat modeling, across web, mobile, and cloud-native applications. They will collaborate with cross-functional teams to remediate vulnerabilities and implement secure-by-design principles throughout the software development lifecycle.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 3-5 years of experience in product or application security. Proficiency in penetration testing tools, cloud security, and scripting languages is required, along with familiarity with modern security standards.
Benefits
Full description
Engineering at Innovaccer
With every line of code, we accelerate our customers' success, turning complex challenges into innovative solutions. Collaboratively, we transform each data point we gather into valuable insights for our customers. Join us and be part of a team that's turning dreams of better healthcare into reality, one line of code at a time. Together, we’re shaping the future and making a meaningful impact on the world.
About the Role
We at Innovaccer are looking for a Security Engineer-II for Product Security who will be responsible for End to End Security of the entire solution. This role will encompass the use of a broad range of security domains (Application Security – Web, Mobile & Desktop, Data Security, Cloud Security, Automation, VAPT).This role would be a great opportunity to learn and grow as you would be exposed to multiple security domains at single time.
A Day in the Life
● Perform Black Box, White Box, Grey Box, Web, API, and AI/LLM application penetration testing to identify security vulnerabilities across products and services.
● Conduct AI/LLM security assessments and red teaming exercises in alignment with OWASP LLM Top 10 and emerging AI security best practices.
● Perform security architecture reviews, threat modeling, and secure design assessments for new products, features, APIs, and cloud-native applications.
● Assess applications against OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and industry security standards.
● Work closely with Product, Engineering, DevOps, Infrastructure, Platform Engineering, and SRE teams to remediate security vulnerabilities and implement secure-by-design principles.
● Provide security guidance throughout the Secure Software Development Lifecycle (SSDLC), including design reviews, code reviews, and release security assessments.
● Conduct secure code reviews and assist engineering teams in implementing secure coding practices.
● Perform cloud security assessments across AWS, Azure, and GCP environments, including cloud-native services, IAM, networking, containers, and Kubernetes.
● Collaborate with Infrastructure, Data Security, SRE, and DevOps teams to implement, validate, and periodically test Business Continuity (BCP) and Disaster Recovery (DR) solutions
● Develop security use cases, dashboards, reports, and metrics to improve visibility into product security posture.
● Develop scripts and automation to improve penetration testing, vulnerability validation, and security assessment efficiency.
● Support vulnerability management by validating remediation, performing retesting, and working with engineering teams to drive timely closure of security findings.
● Participate in incident response activities involving application and product security when required.
● This role requires being available on call during weekends and off hours.
What You Need
● Bachelor's degree (engineering) in Computer Science, Information Technology, Cyber Security, or a related field.
● Minimum 3-5 years of experience in Product Security, Application Security, or Penetration Testing.
● Experience conducting AI/LLM security testing and familiarity with OWASP LLM Top 10 is highly desirable.
● Hands-on experience with penetration testing tools such as Burp Suite Professional, OWASP ZAP,Nmap, Nessus, OpenVAS, SQLMap, Metasploit, and similar tools.
● Familiarity with SAST, DAST, SCA, Container Security, Infrastructure as Code (IaC), and Secrets Scanning tools.
● Experience with AWS, Azure, and GCP cloud security, including IAM, networking, storage, compute, Kubernetes, and container security. ● Good understanding of Secure SDLC, DevSecOps, CI/CD pipelines, and modern application architectures.
● Strong knowledge of networking fundamentals, TCP/IP, HTTP/HTTPS, TLS, authentication,authorization, OAuth2, JWT, and API security.
● Good scripting and automation skills using Python, Bash, PowerShell, or similar languages.
● Strong analytical, problem-solving, reporting, and communication skills.
● Ability to work independently, prioritize multiple assignments, and manage competing deadlines.
● OSCP, OSWE, CEH, AWS Security Specialty, or equivalent security certifications are preferred.
● Proficient in open-source security tools and technologies.
● Willingness to work in a 24x7 support environment and take on additional responsibilities
We offer competitive benefits to set you up for success in and outside of work.
Here’s What We Offer
- Generous Leaves: Enjoy generous leave benefits of up to 40 days.
- Parental Leave: Leverage one of industry's best parental leave policies to spend time with your new addition.
- Sabbatical: Want to focus on skill development, pursue an academic career, or just take a break? We've got you covered.
- Health Insurance: We offer comprehensive health insurance to support you and your family, covering medical expenses related to illness, disease, or injury. Extending support to the family members who matter most.
- Care Program: Whether it’s a celebration or a time of need, we’ve got you covered with care vouchers to mark major life events. Through our Care Vouchers program, employees receive thoughtful gestures for significant personal milestones and moments of need.
- Financial Assistance: Life happens, and when it does, we’re here to help. Our financial assistance policy offers support through salary advances and personal loans for genuine personal needs, ensuring help is there when you need it most.
Innovaccer is an equal-opportunity employer. We celebrate diversity, and we are committed to fostering an inclusive and diverse workplace where all employees, regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, marital status, or veteran status, feel valued and empowered.
Disclaimer:
Innovaccer does not charge fees or require payment from individuals or agencies for securing employment with us. We do not guarantee job spots or engage in any financial transactions related to employment. If you encounter any posts or requests asking for payment or personal information, we strongly advise you to report them immediately to our HR department at px@innovaccer.com. Additionally, please exercise caution and verify the authenticity of any requests before disclosing personal and confidential information, including bank account details.
Similar roles
-
Security Engineer I
URM Stores Inc Spokane, Washington, United States · $79K–$96K/yr
-
Cybersecurity Program Manager
Gunnison Consulting Group Alexandria, Virginia, United States · $180K–$210K/yr
-
Cybersecurity Operations Lead
Gunnison Consulting Group Alexandria, Virginia, United States · $160K–$170K/yr
-
Cloud Security Engineer
Workstreet Philippines
-
Security Engineer
Sundt Tempe, Arizona, United States
-
Director, Cybersecurity Practice
Collective Insights Careers Atlanta, Georgia, United States