Website:
network.ind.in
Job details:
Job Title: Security Engineer - IAM Platform
Exp: 8+ year.
Remote
The role is
the identity and access management platform for the Software portfolio.
As Security Engineer, you are the right hand of the Platform Architect on every security specific topic across the
platform, and the person who makes sure the rest of builds on top of it
securely. The role has two sides. In the first phase, you work deep inside the
architecture and the software development lifecycle of itself: securing the
identity core, the authorization layers, and the pipelines that build and
deploy them. As the platform matures and other product teams connect to it,
your focus shifts toward supporting those teams: helping them implement
security correctly against the IAM architecture, the platform's guidelines, and
our security policies, and acting as the person other teams turn to when they
need to get security right. This is a hands-on role. You build tooling and
produce evidence yourself. It is also a teaching role. Part of your job is
making sure other engineering teams understand and adopt the security approach,
not just following it because you told them to. You report to the Global
Produce Security Manager and work closely with the Platform Architect and the
Product Security function. What you will do During the platform build phase,
close to the Platform Architect: ·
Own and run static and dynamic security testing tools in the continuous
integration pipeline, and decide when a finding should block a release. · Review the architecture
and implementation of the identity, authorization, and token layers for
security gaps, working directly alongside the Platform Architect. · Run threat modeling and
risk assessments on platform components, with particular attention to how
tokens are issued and revoked and how services authenticate to each other. · Build the security
tooling, automation, and secure defaults that later get handed to consuming
teams as self-service capability. ·
Produce compliance evidence for security certifications directly, as a personal
deliverable, not a coordination task. As other product teams connect to: · Act as the main point of
contact for product teams implementing security against the platform's IAM
architecture, guidelines, and the policies set by the security officer. · Evangelize secure
implementation practices across teams: run sessions, write practical guidance,
and review designs before they ship, rather than only auditing after the fact. · Support incident response
when a security event touches the identity platform or a connected product. · Test authentication and
authorization integrations for common vulnerability patterns, including token
handling issues and unsafe redirect behavior. ·
Work with product teams to fix findings from security audits, and help them
build the secure coding habits that prevent the same finding from recurring.
Technical skills we are looking for ·
Strong infrastructure and cloud security background (IaaS), including cloud
security architecture, network segmentation, secure landing zones, and Zero
Trust design principles. This is a core requirement, not a secondary one. · Hands-on ownership of
static and dynamic application security testing tools inside a CI/CD pipeline.
You should be able to describe pipelines you personally built or ran, and how
you decided when to block a release. ·
Strong application security background: secure code review, vulnerability
assessment, and working directly with engineers to fix what you find. · IAM and PAM architecture
knowledge: single sign-on, multi-factor authentication, role based access
control, and privileged access management, well enough to guide other teams'
implementation decisions, not just review them. ·
Direct experience producing compliance evidence for security certifications
such as SOC 2 or ISO 27001, ideally evidence that went to an external auditor. · Strong Azure security
experience, including Microsoft Entra ID, Key Vault, Defender, Sentinel, and
managed identity patterns. ·
Working knowledge of OAuth 2.0 and OpenID Connect from an attacker's
perspective: the common implementation mistakes and how you test for them.
Skills that strengthen your application ·
Experience across multiple cloud providers, not only Azure, since you will be
advising product teams that do not all run on the same stack. · Experience with security
testing and vulnerability management practices, manual and automated. · Enough scripting or
automation ability to extend or build your own security tooling rather than
relying only on vendor products. ·
Familiarity with product security regulations for connected software, and what
secure by-default and vulnerability disclosure obligations mean in practice. · Experience running
training, workshops, or internal guild sessions to spread a security practice
across teams that do not report to you. Who succeeds in this role · You build things and ship
them. You are not satisfied with recommending a fix; you want to own it through
to done. · You
can teach a security concept to a team that does not have your background, and
get them to adopt it because they understand it, not because you insisted. · You can hold a firm line
on a security standard while staying constructive when a product team pushes
back. · You communicate risk
clearly to engineers and to non-technical stakeholders, without exaggerating or
minimizing it. · You
are comfortable operating close to architecture early on, then shifting toward
cross team enablement as the platform matures, without needing the role redefined
for you each time. · You
take ownership of compliance evidence as a personal deliverable, with the same
rigor you would apply to production code. ·
You are comfortable using AI tools to support security analysis and automation,
and you know how to check their output rather than trust it blindly.
Click on Apply to know more.