Esyasoft

Senior Lead Engineer - Security Consultant

Esyasoft

Joka, West Bengal, IndiaFull timePosted Jun 11, 2026

Job description

The Security Consultant is responsible for assessing, designing, implementing, and maintaining information security controls to protect organizational systems, networks, and data. The role ensures compliance with security standards, manages cyber risks, and supports secure digital transformation initiatives. Key Responsibility:

  1. Security Assessment & Risk Management Architect enterprise-wide Application Security (AppSec) programs across complex, distributed enterprise environments—embedding SAST, DAST, and SCA into CI/CD pipelines to enable secure-by-design architecture and reduce vulnerabilities. Define secure architecture patterns and guardrails, integrating AppSec controls into DevSecOps pipelines to standardize risk management across distributed engineering teams. Collaborated with Customer Security teams to embed security architecture principles to produce secure project environment. Experience in Application Security governance frameworks, aligning with NIST, ISO 27001, and PCI DSS to achieve compliance posture and audit readiness Conduct security risk assessments, vulnerability assessments, and threat modeling across applications, infrastructure, and networks. Identify security gaps and provide risk-based mitigation recommendations. Perform periodic security posture reviews and maturity assessments.
  2. Security Architecture & Solution Design Design and review secure architecture for applications, cloud, and on-premise systems. Ensure security-by-design principles are embedded in system development and integration. Review technical designs to ensure alignment with security standards and best practices.
  3. Application & Infrastructure Security Support and define application security testing (SAST, DAST, API security testing). Support secure coding practices and review source code for vulnerabilities. Assess infrastructure security including servers, databases, networks, and endpoints.
  4. Cloud & DevSecOps Security Implement and review cloud security controls for AWS, Azure, or GCP environments. Integrate security tools into CI/CD pipelines (DevSecOps). Lead full-lifecycle SIEM deployments, from HLD/LLD design through to steady-state operations. Produce detailed solution proposals, policies, and procedures to support secure, reliable SIEM services Ensure secure configuration, identity access management, and logging in cloud platforms.
  5. Security Operations & Incident Management Support security incident detection, response, and investigation activities. Perform root cause analysis and recommend corrective and preventive actions. Coordinate with SOC, IT, and business teams during security incidents.
  6. Compliance & Governance Ensure compliance with security frameworks and regulations (ISO 27001, NIST, GDPR, etc.). Support internal and external security audits and risk assessments. Develop and maintain security policies, standards, and procedures.
  7. Awareness & Stakeholder Engagement Provide security guidance to development, infrastructure, and business teams. Conduct security awareness sessions and training programs. Act as a trusted advisor on security best practices and emerging threats.
  8. Continuous Improvement & Reporting Stay updated with latest cyber security threats, vulnerabilities, and trends. Prepare security assessment reports, dashboards, and risk summaries for management. Recommend continuous improvements to enhance organizational security posture.

Requirements

Bachelor’s degree in Computer Science, Information Technology, Cyber Security, or related field. Professional Certificate Preferred: CISSP (Certified Information Systems Security Professional). CISM (Certified Information Security Manager). CEH (Certified Ethical Hacker). ISO/IEC 27001 Lead Implementer or Lead Auditor.

AWS / Azure / GCP Security Certification. CompTIA Security+ (added advantage). Years of Exp: 8-13 years of experience in information security, cyber security consulting, or related roles Job Specific Skill: Strong knowledge of cyber security principles, tools, and frameworks. Hands-on experience with vulnerability assessment and penetration testing tools.

Experience in application, infrastructure, and cloud security. Knowledge of security compliance and regulatory standards. Understanding of networking, operating systems, and databases. Strong documentation, reporting, and stakeholder communication skills.