Security Engineer – VAPT & SIEM
Location: Noida
Key Responsibilities
Conduct vulnerability assessments and penetration tests on web applications, REST APIs, and cloud environments.
Test AWS environments including serverless infrastructure, IAM, and cloud configuration against CIS and Well-Architected benchmarks.
Write detailed VAPT reports with CVSS ratings, proof-of-concept evidence, and remediation recommendations.
Deploy, configure, and optimise SIEM platforms for client environments.
Integrate log sources into SIEM — AWS, Microsoft 365, Active Directory, firewalls, endpoints, and applications.
Write and tune custom detection rules to reduce noise and improve alert quality.
Triage security alerts, investigate incidents, and respond within defined SLAs.
Map detections to compliance frameworks — HIPAA, SOC 2, NIST, ISO 27001, PCI DSS.
Produce SOC reports, incident RCAs, and remediation tracking documentation.
Must Have
2–4 years of hands-on experience in application security, penetration testing, or SOC operations.
Experience conducting VAPT on web applications, REST APIs, and cloud environments.
Hands-on SIEM experience — deployment, configuration, detection rule writing, and log source integration.
Knowledge of AWS security services — IAM, GuardDuty, CloudTrail, Security Hub, WAF.
Familiarity with OWASP Top 10 and OWASP API Security Top 10.
Strong report writing skills.
Good to Have
Security certifications — CCNA, AWS SA, CEH, CompTIA Security+.
Experience with Microsoft 365 security — Entra ID, Defender XDR.
Scripting in Python or Bash.
MITRE ATT&CK framework familiarity.
Cloud security certifications — AWS Security Specialty.