Job Title: IT Security Lead
Experience: 8–10 Yrs
Location: Visakhapatnam
Employment Type: Full time
Job Summary
The IT Security Lead is responsible for designing, implementing, and managing enterprise security programs with a strong focus on vulnerability assessment, penetration testing, and application security. This role requires deep technical expertise, leadership capability, and the ability to align security initiatives with business objectives while ensuring compliance with global standards.
Key Responsibilities
Security Governance & Strategy
- Define and enforce enterprise security policies, standards, and procedures
- Align security initiatives with regulatory frameworks (ISO 27001, SOC 2, GDPR, HIPAA, PCI-DSS, DPDP, etc)
Vulnerability Assessment & Penetration Testing (VAPT)
- Perform regular VAPT across infrastructure, applications, APIs, and cloud workloads
- Use industry-standard tools (Burp Suite, Metasploit, Nessus, Qualys, OWASP ZAP)
- Document findings, risk ratings, and remediation plans
- Validate fixes and maintain a vulnerability management lifecycle
Application Security
- Understand application framework and conduct VAPT to identify gaps, vulnerabilities and propose remediation to address them
- Implement DevSecOps practices and integrate security testing into CI/CD pipelines
- Apply OWASP Top 10 and SANS CWE guidelines for web/mobile applications
- Collaborate with developers to remediate vulnerabilities and enforce secure coding standards
Security Assessments & Audits
- Lead risk assessments, compliance audits, and penetration testing engagements
- Perform cloud security assessments (AWS, Azure, GCP) including IAM, encryption, and workload protection
- Oversee network, endpoint, and identity security controls
Incident Response & Threat Management
- Manage SIEM platforms (Splunk, QRadar, ELK) for proactive threat detection
- Investigate and respond to incidents with forensics and malware analysis
- Coordinate with SOC teams for real-time monitoring and escalation
Leadership & Reporting
- Mentor and manage a team of security analysts/engineers
- Prepare dashboards, metrics, and reports for senior management
- Drive employee awareness programs on cyber hygiene
Core Technical Skills
- VAPT Tools & Frameworks: Burp Suite, Metasploit, Nessus, Qualys, OWASP ZAP, Kali Linux
- Application Security: Secure coding, SAST/DAST tools (SonarQube, Checkmarx, Fortify), API security testing
- Cloud Security: AWS & Azure security controls, SIEM, XDR, IAM, encryption, workload protection, cost governance
- Network & Endpoint Security: Firewalls, IDS/IPS, VPNs, EDR solutions
- Automation & Scripting: Python, PowerShell, Bash for security automation
- DevSecOps: CI/CD pipeline security, container security (Docker, Kubernetes)
- Forensics & Malware Analysis: Tools like Volatility, Wireshark, Autopsy
Qualifications
- Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field
- 7–10 years of experience in IT security roles with hands-on VAPT and application security
- Prior experience in leading security operations or teams preferred
Certifications (Preferred)
- Core Security Leadership: CISSP, CISM, CISA.
- VAPT & Technical Security: CEH, OSCP, GPEN, GWAPT, CompTIA Security+, CompTIA CySA+.
- Application Security: CSSLP, GIAC Web Application Penetration Tester (GWAPT).
- Cloud Security: AWS Certified Security – Specialty, Azure Security Engineer Associate, Google Cloud Security Engineer.
- Compliance & Risk: ISO 27001 Lead Auditor/Implementer, PCI-DSS Professional.








