We aim to bring a touch of magic to create inspiring and enduring core memories for the world.
Senior/Lead Security Researcher
Location
India
Posted
74 days ago
Salary
0
Seniority
Senior
Job Description
Senior/Lead Security Researcher
Key & Cornerstone Pte Ltd
• Research into threats (such as root/jailbreak and hiding thereof, app tampering, runtime tampering, etc.) in mobile phone operating systems and applications on Android / iOS / Harmony OS Next. • Work with the team to develop protection mechanisms through reverse engineering, vulnerability research, exploitation and mitigation techniques and mobile/embedded development. • Work with the team to perform penetration test on V-Key’s products and applications. • Work with the team to script attacks and defences for mobile devices in general and for mobile applications. • Develop customer-facing security attack and defense demonstrations. • Work with the team on security solutions architectures involving not just the mobile device, but also other networked components, leveraging authentication protocols (OAuth2, FIDO2, etc.), and understanding and assessing cryptographic protocols and algorithms as needed.
Job Requirements
- Should have 5+ years of experience into this relevant field.
- Good understanding of operating system internals (one or more of Android, iOS, Harmony OS Next, Linux, etc.) and app development (especially mobile).
- Familiar with rooting/jailbreaking, runtime tampering, app tampering, and tools that can be used to hide them.
- Familiar with attack and reverse engineering tools such as Frida, Theos, Ghidra, and IDA Pro.
- Familiar with web VAPT tools like Burp Suite.
- Familiar with how various tools/methodologies work, allowing innovation and creative solutions, not just comfortable using the tools as is.
- Good understanding of threat modelling, including familiarity with at least one threat modelling framework.
- A strong self-starter and able to work with minimal supervision, while still receptive to suggestions and ways to improve.
- Detail oriented with a strong focus on quality.
- Ability to work in a dynamic, fast moving and growing environment.
- Positive work attitude, proactive and highly driven.
- Critical thinker and problem-solving skills.
- Nice to have Degree in Computer Science, Information Systems, Math (especially related to cryptography) or related field.
- Certifications related to information security, ethical hacking, security solution design.
- Have built tools/scripts to help with various security research tasks.
Benefits
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Implement and maintain cloud security controls in AWS and Azure environments in support of Enhanced Domain Awareness systems. • Ensure compliance with NIST 800-53 Rev. 5, FedRAMP, and DoD IL 2/4/5 security requirements. • Configure and manage Identity and Access Management (IAM) solutions and enforce least-privilege access. • Perform vulnerability assessments and support remediation activities across cloud-hosted resources. • Monitor cloud environments using SIEM and cloud-native security tools to detect and respond to threats. • Support Zero Trust architecture and continuous monitoring initiatives. • Collaborate with DevOps, infrastructure, and application teams to integrate security into the development and deployment lifecycle.
Physical Security Technical Project Manager
ZBeta, Inc.Security that protects. Solutions that empower.
• Support security design and installation projects throughout North, South, and Central America, including new sites and expansion projects, post-occupancy projects, and technology upgrade projects. • Manage all aspects of project delivery, including collaborating with key stakeholders, managing multiple projects, and scopes of work. • Identify project schedule, scope parameters, and oversee security design and implementation per client design requirements and standards. • Manage early project initiation activities and develop project security scope, schedule, critical deliverables, and requirements. • Manage scheduling, status, and tracking of critical project tasks, issues, and deliverables. • Assist with the bid and award process. • Review bid leveling documentation and provide feedback on the award recommendation. • Evaluate SOW responses and prepare evaluation reports, to include evaluation criteria, scoring, and recommendation details. • Perform security site evaluations of potential client properties and review proposed design concepts. • Apply client system design standards to in-progress site design, collaborate with client owner and user group stakeholders to define use cases and verify functional requirements, and produce a security functional specification for the project. • Review all security system design documentation for compliance with published security requirements, technical standards, and installation standards. • Collaborate with project teams and stakeholders while managing site activation activities for physical security among project parties and stakeholders to drive schedule, quality, and cost.
Role Description We’re looking for a Senior Cybersecurity Engineer to design, build, and operate preventative and detective security controls and automation across our AWS‑first and enterprise environments. Reporting to the CISO, this role implements guardrails, platforms, and integrations and partners with infrastructure, platform, and application teams to embed security by default in our AWS cloud and enterprise environments. The role will perform hands-on engineering in multiple security domains including: - Network security - Endpoint security - Email security - Data security - Vulnerability management - Container security - Identity and access management Qualifications - 7+ years in security engineering with production AWS (multi‑account/Organizations) and automation‑first delivery. - Domain experience in at least three of the following: - Network security (segmentation, routing, firewall, proxy, WAF) - Endpoint security (EDR/EPP, hardening, health attestation) - Email security (phishing protection, authentication, inbound/outbound controls) - Data security (classification, DLP, encryption, key management) - Vulnerability management (scanning, prioritization, remediation pipelines) - Container security (image scanning, runtime policy, supply chain) - Identity and access management (policy design, federation, least privilege) - IaC proficiency (Terraform preferred) and Python for automation; CI/CD integration experience (e.g., GitHub Actions, GitLab, CodePipeline). - Experience with root‑cause analysis and remediation of control failures (not incident RCA). - Demonstrated ability to independently drive complex projects to completion, as well as collaborate effectively with a complex set of stakeholders. Requirements - Design, implement, and maintain controls in AWS (IAM, KMS, VPC, GuardDuty, Security Hub, Detective, CloudTrail/CloudWatch), network, endpoint, email, data security, vulnerability, and identity domains. - Define SLOs for control availability, latency, coverage, and drift; implement telemetry to continuously measure those SLOs. - Partner with infrastructure, platform, and application teams to build IaC modules (Terraform/CloudFormation) and platform automations (e.g., Python/Lambda, Step Functions) to enforce guardrails (account vending, baseline hardening, logging enablement, key policies, SCPs) using Git. - Implement break‑glass patterns and least‑privilege workflows that are auditable and reversible. - Engineer data pathways (e.g., CloudTrail, VPC Flow, ECS audit, identity logs) into SIEM/MDR tooling; ensure completeness, timeliness, and schema quality. - Translate Detection and Response Lead feedback on false positives/gaps into logging or control adjustments. - Own scanners/integrations, asset coverage, tagging standards, and develop risk‑based remediation pipelines (ticketing, auto‑remediation for low‑risk classes). - Partner with owners to remove friction (pre‑approved windows, canaries, rollbacks). - Engineer least‑privilege patterns, permission boundaries, conditional access, and automated key/secret lifecycle (rotation, discovery, usage attestations). - Provide ready‑to‑consume roles/policies to teams. - Maintain runbooks, design docs, and reusable modules; ensure changes are versioned, peer‑reviewed, and tested. - Participate in control‑health and platform on‑call (e.g., logging ingestion failures, drift, outages). - Escalate security events to the Detection & Response Lead/MDR. Benefits - Employee Ownership Program - every eligible employee shares in the financial rewards that grow when the company grows. - Professional development opportunities. - Owner Referral Program. - Work from home reimbursement for remote/hybrid roles. - Canary emergency financial assistance program. - Comprehensive medical, dental, vision insurance. - Life/AD&D Insurance. - Confidential, Employee Assistance Program. - Health Savings Account, includes company contribution. - Short-term disability. - Voluntary benefits - supplemental accident, critical illness, hospital insurance. - Employee discounts. - 401(k) Plan with company match contribution. - Addition Wealth Financial Wellness Program. - Various Time Off Programs. - 11 company paid holidays.
AWS Cloud Security Engineer
Fluent, LLCFluent, Inc. (NASDAQ: FLNT) is a commerce media solutions provider connecting top-tier brands with highly engaged consumers. Leveraging diverse ad inventory, robust first-party data, and proprietary machine learning, Fluent unlocks additional revenue streams for partners and empowers advertisers to acquire their most valuable customers at scale. Founded in 2010, Fluent uses its deep expertise in performance marketing to drive monetization and increase engagement at key touchpoints across the customer journey.
Role Description We're seeking an AWS Cloud Security Engineer to strengthen our cloud security posture and ensure the secure operation of our AWS infrastructure. This role focuses on implementing security controls, managing cloud security tools, responding to security findings, and ensuring compliance across our AWS environment. What You'll Do - Cloud Security & Infrastructure - Design, implement, and maintain security controls across AWS services (EC2, S3, RDS, EKS, ECS, Lambda, API Gateway) - Configure and optimize AWS security services including GuardDuty, CloudTrail, CloudWatch, Security Hub, and AWS Config - Implement VPC security architecture, network segmentation, security groups, and NACLs - Manage CloudFront and ALB security configurations including WAF rules - Secure containerized workloads and serverless architectures - Identity & Access Management - Design and implement least-privilege IAM policies, roles, and permission boundaries - Manage AWS Identity Center (SSO) and integration with Okta - Conduct access reviews and support user provisioning while maintaining security standards - Implement secure service-to-service authentication patterns - Security Monitoring & Response - Monitor and respond to security alerts from GuardDuty, CloudTrail, and AWS security services - Investigate and remediate security findings from Wiz cloud security platform - Perform threat analysis and security incident investigation - Develop security incident response playbooks for cloud threats - Databricks & Compliance - Implement and maintain security controls for Databricks workspaces on AWS - Support SOC 2 and other compliance audit requirements - Maintain security documentation and audit trail evidence - Enforce security policies and compliance standards across AWS accounts - Collaboration & Automation - Partner with Engineering, DevOps, and IT teams to integrate security into cloud operations - Automate security processes using Infrastructure as Code - Document security architectures, procedures, and runbooks - Provide security guidance on AWS best practices - Coordinate with external security vendors, testers, and auditors as needed Qualifications - 3+ years of hands-on experience securing AWS environments - Deep technical expertise with AWS security services: IAM, Identity Center, GuardDuty, CloudTrail, CloudWatch, Security Hub, AWS Config - Strong experience with core AWS services: EC2, S3, RDS, EKS, ECS, VPC/Networking, Lambda, SQS/SNS, CloudFront, ALBs, API Gateway - Experience with Databricks on AWS, including security configurations and best practices - Hands-on experience with Wiz or similar cloud security posture management (CSPM) tools - Knowledge of identity and access management principles, including federated identity (Okta, SAML, OIDC) - Experience supporting compliance frameworks such as SOC 2, ISO 27001, or similar standards - Scripting skills (Python, Bash, PowerShell) for security automation - Understanding of network security, encryption, and security monitoring in cloud environments - Strong problem-solving skills with ability to investigate and remediate security issues Benefits - Competitive compensation - Ample career and professional growth opportunities - New Headquarters with an open floor plan to drive collaboration - Health, dental, and vision insurance - Pre-tax savings plans and transit/parking programs - 401K with competitive employer match - Volunteer and philanthropic activities throughout the year - Educational and social events - The amazing opportunity to work for a high-flying performance marketing company! Company Description Fluent, Inc. (NASDAQ: FLNT) is a commerce media solutions provider connecting top-tier brands with highly engaged consumers. Leveraging diverse ad inventory, robust first-party data, and proprietary machine learning, Fluent unlocks additional revenue streams for partners and empowers advertisers to acquire their most valuable customers at scale. Founded in 2010, Fluent uses its deep expertise in performance marketing to drive monetization and increase engagement at key touchpoints across the customer journey.

