Job Description
As a Signature Engineer you will be part of an engineering team that is responsible for the research, development, and delivery of compliance signatures for Cloud security product . In this team you will work on numerous Cloud platforms , Cloud Services and security standards like CIS, CSA-CCM, NIST, DISA, PCI-DSS and help customers assess the configurations and compliance.
Responsibilities:
Understand and explore APIs ( REST, Java, PowerShell, Shell) provided by Cloud service providers (AWS, Azure, Google Cloud Platform etc. )
Based on research develop signatures to identify and fix non-compliant cloud platforms/ services related configurations and settings using Java API calls and Json Processing
Research on hardening Cloud-Platforms and cloud services configurations/ settings
Research on public cloud platform architectures and services
Track updates pushed by cloud service provider on respective supported cloud platforms / services
Keep updates on recently disclosed vulnerabilities, mis-configurations using public channels/ blogs and suggest recommendations based on the same
Research on hardening OS es, Web/ Application Servers, database platforms etc.
Provide subject matter expertise to internal core engineering and infrastructure teams
Qualifications:
BS/ MS in Computer Science or a related field
Experience of 4 years with BS and 2 years with M. S , preferably in Information Security Domain
Experience in Java Programming
Proficient in Regular Expressions and Programming methods
S trong knowledge of Cloud Architectures and Security space
Experience and understanding with Cloud services/ Platforms and various cloud service provider offerings (AWS, Azure, Google)
Conversant with Shell, PowerShell scripting
Installation, Configuration and administration of Applications on Windows/ Linux/ Unix and other environments
Knowledge of programming in the Unix/ Linux/ windows environment
Good communication skills
Good understanding on domain of Information Security
Pluses:
Security Certifications like: CEH, CISA, CISM, CISSP, ISC2-CCSP
Cloud platform-based certifications like: AWS / Azure/ GCP Certified Developer/ Solution Architect
Exposure to Security benchmarks like CIS or SCCM, DISA and STIG
Basic understanding of security standards/ mandates like CSA-CCM, NIST, PCI-DSS etc.
EEO Employer/ Vet/ Disabled,
Employement Category:
Employement Type: Full time
Industry: IT - Hardware / Networking
Role Category: General / Other Software
Functional Area: Not Applicable
Role/Responsibilies: Signature Engineer, Cloud Security Compliance
Contact Details:
Company Name: QualysLocation(s): Pune