Application Security Engineer
Indexed description
In the assigned Job Role of Infrastructure Consultant 2, your Area Of Responsibility will be as below:
- Collaborate with internal and client teams to resolve complex incidents, conduct root cause analyses, and document findings with preventive recommendations
- Participate in evaluation of client IT infrastructure, prepare actionable assessment reports, and support due diligence to document infrastructure maturity and improvement opportunities
- Contribute to the design of scalable, cost-effective IT infrastructure solutions, review reusable components, and develop technical documentation for deployed systems
- Align release schedules and environment readiness, execute deployments as per protocols, perform post-deployment testing, and manage version control to track changes
- Co-ordinate maintenance schedules, emergency fixes, and technology upgrades while ensuring uninterrupted integration into existing systems and processes
- Facilitate performance data analysis across systems, coordinate insights on system behavior, and support capacity planning to optimize performance
- Conduct security checks, recovery drills, and compliance audits, implement security measures, and coordinate continuity plans to maintain adherence to standards
- Gather feedback to identify automation opportunities, analyze existing infrastructure processes, and propose enhancements for efficiency gains
- Act as liaison with onsite, offshore, and vendor teams to document project requirements, ensuring effective collaboration
- Develop a centralized repository of technical and procedural knowledge, leveraging insights from other projects to drive efficiency and retain organizational expertise
- A collaborative spirit and excellent communication skills.
- Ability to handle complex incidents and implement resolutions
- A knack for conducting IT infrastructure assessment and identifying key optimization opportunities
- Focused approach towards deployment management, system optimization, and process automation initiatives including sector specific focus
- The ability to work with cross-functional teams
- Threat Modeling such as: (STRIDE, PASTA, Attack trees, tooling, Att&ck) is an added advantage.
- Identifying vulnerabilities using CWE or OWASP.
- Security practices pertaining to: authentication, authorization, logging/monitoring, encryption, infrastructure security, network/segmentation is required.
- Operating systems and their hardening.
- Development concepts (such as: CICD, Pipelines, SDLC).
- Scripting languages, Infrastructure as Code (Terraform, CloudFormation) is a plus.
- Cloud Development Kit (CDK), GitOps.
- Understanding of docker/K8S/serverless/helm.
- Support or perform pen testing.
- Design and review technical architectures.
- Experienced working in a Cyber-Security or Information Security is a bonus
- Threat Modeling using a documented process.
- Development of automation tools as required.
- Operating in a DevOps / agile team structure.
- Jira or other ticketing systems is an added advantage.
- Maintain a high standard of work in identifying threats and specifying mitigating controls.
- Attending to the lifecycle of identified threats and controls.
- Delivery of threat models and supporting tasks within existing timeframes.
- Provide feedback, support, and improvements to the existing threat modeling process.
- Present work to seniors, the team, and other technical teams.
- Work with little supervision to complete work
- Analytical, diligence and attention to detail.
- Eagerness to research using vendor documentation.
- Create and maintain quality documentation.
- Experience of regulated environment.
- Adversary mindset.
- Work with diverse set of people and teams.
- Constant learner of new technologies and methodologies.
- Problem solver.
- Communication and collaboration skills.
- Snowflake/MongoDB/Terraform Cloud/GitHub/Databricks is a plus.
- Bachelor’s degree or foreign equivalent required from an accredited institution. Will also consider three years of progressive experience in the specialty in lieu of every year of education.
- This position may require relocation and/or travel to work/project location.
- Candidates authorized to work for any employer in the United States without employer-based visa sponsorship are welcome to apply. Infosys is unable to provide immigration sponsorship for this role now or in the future.
- Medical/Dental/Vision/Life Insurance
- Long-term/Short-term Disability
- Health and Dependent Care Reimbursement Accounts
- Insurance (Accident, Critical Illness , Hospital Indemnity, Legal)
- 401(k) plan and contributions dependent on salary level
- Paid holidays plus Paid Time Off
EEO
Infosys provides equal employment opportunities to applicants and employees without regard to race; color; sex; gender identity; sexual orientation; religious practices and observances; national origin; pregnancy, childbirth, or related medical conditions; status as a protected veteran or spouse/family member of a protected veteran; or disability.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search