Senior Product Security Analyst

  • Bengaluru
  • Optym

Company Overview


Founded in 2000, Optym is building SaaS solutions for the transportation and logistics industry and making it more efficient. Optym’s software solutions are used by leading railroads, airlines and trucking companies, and have created a cumulative business value of over $1 billion for its clients. With its headquarters based in Dallas, Texas, and centers of excellence located in Europe and India, Optym’s team consists of 250+ professionals. Optym has about 50 highly specialized professionals in US and is expecting a major growth in the next five years. Optym is looking for brilliant, highly qualified and well-educated Operations Research Scientists to assist in building Optimization and AI/ML solutions for the transportation and logistics industry.

Optym offers competitive wages, excellent benefits, a great working environment, and the culture of entrepreneurship and ownership. Optym offers a generous profit and equity sharing plan with the potential to increase your compensation substantially salary based on the success of Optym.



About the job:


This is a technical product security role. It would an individual contributor where

you will be hands-on in driving VAPT testing, working with product engineering

teams to ensure that all the security process are followed and captured

correctly. You will ensure that information security controls, policies and

best practices are followed and organize the documents as per ISMS standards.

The company follows a Hybrid working approach.

Responsibilities:


  • Implementation of security in SDLC, infrastructure and DevOps, including security focused design, architecture and security testing.
  • Support the compliance and certification requirements of the organization.
  • Establish and conduct VAPT tests across all the products & solutions.
  • Organize all ISMS documentation required for ISO 27001, CSA Star and SOC2 certifications from product engineering and support teams
  • Highlight cyber security risks and monitor them.
  • Coordinate and support cybersecurity audits.
  • Post audit / assessments and implementation of recommendations.
  • Monitor all product security and ISMS related KPIs and engage with product teams for continuous improvements.


Qualification:


  • Minimum of bachelor’s degree in Computer Science or IT related fields.
  • Prior experience in the Information Security activities for digital product engineering teams (2-4 Years)
  • Knowledge of standards such as CDSA, MULTISAFE etc
  • Knowledge of Azure, Microsoft Entra, Keycloak.
  • Good experience with any Endpoint security tools like ZScaler, Forcepoint, CrowdStrike etc.
  • Well versed with GDPR, SOC principles and relevant implementation
  • Well versed in multiple security technologies: SIEM, Antivirus, Intrusion Detection Systems, End-point security, Web Proxy/Content Filtering, DLP
  • Familiarity with DevSecOps
  • Working knowledge of VAPT tools like Nessus, Metasploit, Burp Suite etc.
  • 3 to 5 years of experience in Information Security or related fields with overall experience of 6+ years
  • Good knowledge of various authentication and authorization mechanisms for cloud native web applications and mobile (android/iPhone) applications.
  • Understanding of cyber security technologies & controls, processes, and threat landscape concepts.
  • Excellent verbal and written communication skills
  • Ability to influence a global team towards the change management needed to implement new processes.
  • Ability to communicate with the senior leadership about Cybersecurity
  • Ability to work collaboratively across multiple teams.
  • Ability to prioritize and execute tasks.