Information Security Specialist

  • Gurugram
  • Policybazaar.com
Job title: - Information Security Associate Job brief : The candidate will be responsible for conducting technical security assessments of organization's assets to identify vulnerabilities and evaluate the effectiveness of existing security controls. The candidate will play a critical role in ensuring the confidentiality, integrity and availability of sensitive information and systems. Job responsibilities : ● Conducting vulnerability scans and penetration testing to identify security weaknesses across infrastructure and application(web and mobile application) landscape; ● Documenting and reporting findings, including recommendations for remediation and liaising with internal stakeholders for closure; ● Staying current with new attack vectors and tools, and incorporating them into testing procedures; and ● Collaborating with other teams to prioritize remediation efforts. ● Performing Red Team in different locations of Policybazaar’s office and CTI(Cyber threat intelligence) for all Policybazaar network and application. Requirements and skills : ● Proven work experience of 2-3 years as an Information Security Associate/Engineer or a similar role ● Proficient with Linux and Windows; ● Excellent written and verbal communication skills; ● Knowledge of OWASP Top 10, NIST CSF, MITRE ATT&CK is preferable; ● Proficiency in conducting thorough source code reviews and implementing automation processes; ● Technical security certifications like OSCP, PNPT, CRTP, or similar are good to have; ● Experienced in DAST, SAST and infrastructure penetration testing; ● Ability to identify security vulnerabilities and suggest appropriate mitigation steps. Desired qualifications : ● BTech or equivalent degree in Computer Science, Information Security or related field; ● 2-3 years of experience in technical security assessment; and ● Ability to contribute individually, and as a part of team