Security and GRC Specialist 5-10Yrs Hyderabad
Job Summary
Job Description: Lead Security GRC & Application Security
Role Summary
This role leads Pragma Edges end-to-end security function spanning governance/compliance application security cloud & infrastructure security threat monitoring and external attack surface management. The Lead owns the security posture across internal systems client-facing products and cloud/on-prem infrastructure and is the primary point of accountability for audit readiness client TPRM responses and remediation across every layer of the stack.
Core Responsibilities
1. Governance Risk & Compliance (GRC)
- Own and maintain security policies (Access Control Incident Response Data Protection SDLC) review and update on a recurring cycle.
- Conduct risk assessments and client Third-Party Risk Management (TPRM) reviews; maintain and update the Vanta risk register and track remediation to closure.
- Map controls to ISO 27001 SOC 2 NIST and OWASP standards.
- Own audit evidence collection logs screenshots approvals for both internal and external audits.
- Lead quarterly internal audits (client-specific) and HR audits; own annual external audit and ongoing Vanta compliance management.
2. Application Security & Secure Development
- Perform secure code reviews on critical APIs and backend services.
- Own OWASP Top 10 remediation (BOLA BFLA Injection Security Misconfigurations).
- Run Software Composition Analysis (SCA) dependency vulnerability management SBOM generation license review remediation validation.
- Own SAST scanning across JAR Python and Maven artifacts using Mend/WhiteSource; own DAST scanning (web app API) using OWASP ZAP and Burp Suite.
- Run container/image vulnerability scanning (Mend CLI).
- Coordinate SAST/DAST/SCA findings with development teams validate fixes and perform rescans.
3. Penetration Testing
- Build and execute pentesting plans for web applications APIs and products.
- Own client communication throughout pentest engagements produce findings reports and drive remediation to closure.
4. Cloud & Infrastructure Security
- Review cloud IAM network rules and storage exposure; own security hardening (insecure configs headers TLS secrets).
- Run infrastructure vulnerability assessments (Active Directory switches routers internal servers) via Nessus.
- Run cloud compliance scans and client-specific AWS security/compliance assessments via Nessus.
- Own network security review configuration validation and hardening recommendations.
- Manage on-prem security: installation requests firewall changes domain whitelisting and inbound/outbound IP access control.
- Validate backup restore and DR readiness; improve audit logging and SIEM integration.
5. Threat Monitoring & Security Operations
- Monitor security logs (Trend Micro) and firewall logs (Sophos) event review traffic analysis and investigation.
- Coordinate remediation with Infrastructure Cloud Networking and Development teams; produce vulnerability reporting across infrastructure cloud application and product layers.
6. External Attack Surface Management
- Run weekly public IP discovery and maintain external asset inventory.
- Perform external reconnaissance port scanning and service enumeration.
- Own subdomain enumeration takeover validation and DNS verification.
- Run external vulnerability scanning and validation; monitor for exposed company-sensitive information on the internet.
7. Training Awareness & Documentation
- Run security awareness training and phishing simulations; run developer secure-coding sessions (OWASP/API security).
- Prepare security assessments training plans test evaluations and score analysis.
- Own compliance documentation: Access Change Requests Device Disposal records Incident Response documentation Tabletop Exercise (TTE) documentation.
- Own security documentation: policies assessment reports remediation reports.
- Provide audit support: quarterly evidence compliance reporting vulnerability tracking and exit-access revocation verification.
Tools & Stack
Vanta (GRC/compliance) Mend/WhiteSource (SAST SCA container scanning) OWASP ZAP & Burp Suite (DAST) Nessus (infra/cloud vulnerability assessment) Trend Micro (log monitoring) Sophos (firewall monitoring).
Required Skills:
Job Description: Lead Security GRC & Application Security Role Summary This role leads Pragma Edges end-to-end security function spanning governance/compliance application security cloud & infrastructure security threat monitoring and external attack surface management. The Lead owns the security posture across internal systems client-facing products and cloud/on-prem infrastructure and is the primary point of accountability for audit readiness client TPRM responses and remediation across every layer of the stack. Core Responsibilities 1. Governance Risk & Compliance (GRC) Own and maintain security policies (Access Control Incident Response Data Protection SDLC) review and update on a recurring cycle. Conduct risk assessments and client Third-Party Risk Management (TPRM) reviews; maintain and update the Vanta risk register and track remediation to closure. Map controls to ISO 27001 SOC 2 NIST and OWASP standards. Own audit evidence collection logs screenshots approvals for both internal and external audits. Lead quarterly internal audits (client-specific) and HR audits; own annual external audit and ongoing Vanta compliance management. 2. Application Security & Secure Development Perform secure code reviews on critical APIs and backend services. Own OWASP Top 10 remediation (BOLA BFLA Injection Security Misconfigurations). Run Software Composition Analysis (SCA) dependency vulnerability management SBOM generation license review remediation validation. Own SAST scanning across JAR Python and Maven artifacts using Mend/WhiteSource; own DAST scanning (web app API) using OWASP ZAP and Burp Suite. Run container/image vulnerability scanning (Mend CLI). Coordinate SAST/DAST/SCA findings with development teams validate fixes and perform rescans. 3. Penetration Testing Build and execute pentesting plans for web applications APIs and products. Own client communication throughout pentest engagements produce findings reports and drive remediation to closure. 4. Cloud & Infrastructure Security Review cloud IAM network rules and storage exposure; own security hardening (insecure configs headers TLS secrets). Run infrastructure vulnerability assessments (Active Directory switches routers internal servers) via Nessus. Run cloud compliance scans and client-specific AWS security/compliance assessments via Nessus. Own network security review configuration validation and hardening recommendations. Manage on-prem security: installation requests firewall changes domain whitelisting and inbound/outbound IP access control. Validate backup restore and DR readiness; improve audit logging and SIEM integration. 5. Threat Monitoring & Security Operations Monitor security logs (Trend Micro) and firewall logs (Sophos) event review traffic analysis and investigation. Coordinate remediation with Infrastructure Cloud Networking and Development teams; produce vulnerability reporting across infrastructure cloud application and product layers. 6. External Attack Surface Management Run weekly public IP discovery and maintain external asset inventory. Perform external reconnaissance port scanning and service enumeration. Own subdomain enumeration takeover validation and DNS verification. Run external vulnerability scanning and validation; monitor for exposed company-sensitive information on the internet. 7. Training Awareness & Documentation Run security awareness training and phishing simulations; run developer secure-coding sessions (OWASP/API security). Prepare security assessments training plans test evaluations and score analysis. Own compliance documentation: Access Change Requests Device Disposal records Incident Response documentation Tabletop Exercise (TTE) documentation. Own security documentation: policies assessment reports remediation reports. Provide audit support: quarterly evidence compliance reporting vulnerability tracking and exit-access revocation verification. Tools & Stack Vanta (GRC/compliance) Mend/WhiteSource (SAST SCA container scanning) OWASP ZAP & Burp Suite (DAST) Nessus (infra/cloud vulnerability assessment) Trend Micro (log monitoring) Sophos (firewall monitoring).