Website:
threatmodeler.ai
Job details:
About The Company
ThreatModeler Software Inc. is industry’s #1 automated Threat modeling platform. The successful team members will initially support our services clients, where ThreatModeler was awarded a single or multi-year competitive contract. The effort is to perform client implementations, ranging from gathering client requirements for Threat modeling services and rolling out ThreatModeler’s platform across the enterprise.
Reports to: Information Security Officer
Team: IT & Security
Location: India - Noida
Role: Full time - Permanent
Purpose of the Role
We are looking for a senior cybersecurity analyst with strong compliance experience to help manage and mature our security stack and compliance program across both corporate and product environments.
This is a senior and hands-on role suited to someone who can operate independently, make sound risk-based decisions, and own outcomes across security operations and tooling, governance, risk and compliance, and customer security requirements.
The role sits at the intersection of cybersecurity and compliance. The ideal candidate should be comfortable moving between hands-on security operations, including endpoint security, vulnerability management, incident response, cloud security, security tooling, logging and monitoring, etc., and compliance work, such as evidence gathering, policy and procedure review, risk management, and audit readiness.
Responsabilities
- Operate and improve the company’s security tooling across endpoint security, SIEM/SOAR, SASE/SWG/DLP/ZTNA, identity and access management, vulnerability management, and AWS-native security controls.
- Manage vulnerability management across both corporate and product environments.
- Support monitoring and incident response activities, including alert review, investigations, and root cause analysis.
- Review and improve AWS security controls, logging & monitoring, access management, secure configuration practices, etc.
- Identify technical security gaps and propose practical, risk-based improvements.
- Maintain and improve security policies, procedures, standards, and operational documentation.
- Support the operation and improvement of the ISMS, including ISO 27001 and SOC 2 readiness.
- Assist with risk assessments, treatment plans, control reviews, evidence collection, audit preparation, and remediation tracking.
- Respond to customer security questionnaires and support customer security reviews where needed.
- Work closely with engineering, infrastructure, IT, and product teams to ensure security and compliance requirements are implemented effectively.
What We Offer
- Competitive salary and performance-based bonuses.
- Opportunities for career growth and professional development.
- A collaborative and innovative work environment.
Requirements
Essential Skills
- Strong hands-on experience (5+ years) in information security, security operations, cloud/AWS security, or infrastructure security in a SaaS or technology environment.
- Practical experience with security tools such as EDR, SIEM/SOAR, vulnerability scanners, SASE, endpoint management, identity platforms, and AWS-native security services.
- Good understanding of patching, remediation prioritization, incident response, logging & monitoring, and secure baselining, development, and configuration management.
- Experience working with AWS or similar cloud environments, including IAM, logging & monitoring, and infrastructure security controls.
- Ability to assess technical security risks and communicate them clearly to other teams and business/technical owners.
- Good understanding of ISO 27001, SOC 2, ISMS operations, risk management, control ownership, evidence management, and audit readiness.
- Experience in supporting audits and compliance documentation.
- Strong ownership mindset, good judgment, and ability to work independently in a remote and distributed environment.
Desired Experience
- Experience with security tools and platforms such as CrowdStrike Falcon, Rapid7 InsightVM, Google SecOps or similar SIEM/SOAR, Netskope, Cloudflare One, or other SASE/SWG/DLP/ZTNA solutions, Okta, and AWS-native security services such as Security Hub, etc. would be highly valuable.
- Experience with vendor security reviews and third-party risk management.
- Certifications such as CISSP, OSCP, cloud security certifications, or equivalent practical experience.
Click on Apply to know more.