Role Details
42Gears is looking for a skilled candidate for the position of **Senior Security Engineer**. In this role, you will be responsible for designing and implementing security solutions, conducting security assessments, and developing security architecture frameworks for 42Gears products and infrastructure.
This role includes significant responsibility for designing and implementing secure cloud architectures across AWS and GCP platforms. 42Gears is seeking a strategic and analytical professional with solid security architecture and infrastructure experience who possesses strong technical communication and problem-solving skills. The role requires the ability to work collaboratively with cross-functional teams in a dynamic environment.
**Relevant Experience: 4-6 years**
## Responsibilities
* **Security Architecture:** Design and implement security architecture solutions aligned with business requirements and industry best practices.
* **Vulnerability Management:** Conduct security assessments and vulnerability analysis to identify and remediate gaps in existing infrastructure.
* **Documentation & Threat Modeling:** Develop comprehensive documentation, including threat models and architecture diagrams, to standardize security across the organization.
* **SDLC Integration:** Collaborate with cross-functional teams to integrate security controls directly into the software development lifecycle (SDLC).
* **Technology Evaluation:** Evaluate and pilot emerging security technologies to maintain a proactive defense posture against evolving threats.
* **Mentorship:** Mentor junior team members and lead security awareness initiatives to foster a culture of collective responsibility.
* **Cloud Security:** Architect secure cloud solutions that ensure continuous compliance with organizational policies and cloud-native best practices.
* **Infrastructure Hardening:** Perform cloud hardening by evaluating infrastructure configurations and implementing rigorous security benchmarks.
* **IAM Governance:** Oversee IAM strategies across multi-cloud environments (AWS/GCP) to enforce strict least-privilege access and identity governance.
* **Automation:** Automate security guardrails through Infrastructure as Code (IaC) to ensure consistent security deployment across all environments.
* **Observability:** Design centralized logging and monitoring frameworks to provide the visibility required for effective threat detection and response.
* **Pipeline Security:** Integrate SAST, DAST, and SCA tools into CI/CD pipelines to automate the detection of vulnerabilities in custom code and third-party libraries.
* **Container Security:** Develop security blueprints for containerized environments (Kubernetes/Docker) covering image signing, pod security, and runtime protection.
* **Data Protection:** Define Data Loss Prevention (DLP) architectures to monitor and control the movement of sensitive data across cloud and hybrid environments.
* **Compliance Mapping:** Map technical security controls to regulatory frameworks (SOC2, ISO 27001, GDPR) to ensure the architecture meets audit requirements.
## Critical Skills / Competencies
* **Security Frameworks:** Proficient in NIST CSF, ISO 27001, and SOC2 control mapping.
* **Cloud Architecture:** Security design knowledge for AWS (EC2, S3, VPC, Lambda, IAM), Azure (VMs, KMS, Storage, App Services), and GCP (Compute Engine, Cloud Storage, Identity Management) environments.
* **Threat Modeling:** Expert in STRIDE/PASTA methodologies and infrastructure risk assessment.
* **Identity & Access:** Advanced IAM governance, Zero Trust architecture, and JIT access.
* **Container Security:** Hardening and orchestration security for Docker and Kubernetes.
* **DevSecOps:** Integrating SAST/DAST/SCA gating into automated CI/CD pipelines.
* **Network Security:** Implementing micro-segmentation, WAF, and API Security Gateways.
* **Data Protection:** Centralized secrets management (Vault) and PKI/Encryption standards.
* **Security Observability:** Architecting SIEM/SOAR telemetry for high-fidelity detection.
* **Application Security:** Deep knowledge of OWASP Top 10 and secure coding practices.
* **Compliance:** Technical auditing against FedRAMP, HIPAA, PCI-DSS standards, and cloud security assessment methodologies.
## Certifications (Preferred)
Preference will be given to candidates who possess any of the following:
* **Advanced Certifications:** CISSP (Certified Information Systems Security Professional) or similar advanced security certification.
* **Management & Essentials:** CISM (Certified Information Security Manager) or GIAC Security Essentials (GSEC).
* **Cloud Certifications:** Cloud architect certifications such as AWS Solutions Architect Professional, Azure Solutions Architect Expert, or Google Cloud Professional Cloud Architect.
* **Container Certifications:** Kubernetes security certifications (CKA, CKAD) or cloud-native security certifications.
* **Frameworks:** Experience with enterprise security frameworks and governance standards (NIST, ISO 27001, SOC 2).
## Required Skills
* Cloud Security and Compliance
* Compliance
* Code Quality and Architecture
* Cyber Threat Awareness
* Collaboration & Communication
---
**Apply Now:** To apply for this position, please send your latest resume to [jobs@42gears.com](mailto:jobs@42gears.com).