
Services Security Test Engineer (Ethical Hacker)
- Bangalore, Karnataka
- Permanent
- Full-time
- India - Karnātaka - Bangalore
- India - Karnātaka - BANGALORE
- Working with software designers, developers, project managers, and testers - developing close working partnerships with development teams - to review, assist and recommend changes and solutions to address the security of Lenovo- and third party-developed software
- Act as a trusted advisor and subject matter expert to product development and engineering teams - provide advice on secure application design, development and validation
- Identify and evaluate needed tools and refine processes and procedures to ensure security reviews are performed correctly.
- Define security requirements for Lenovo and third-party development teams.
- Act as a Secure Development Lifecycle evangelist, guiding and training development teams within SSG on how to effectively and efficiently apply secure development practices
- Conducting product and service security assessments, analyzing weaknesses, formulating mitigations or remediation measures, documenting findings, and working with global product and services teams to ensure proper corrective actions are implemented
- Identifying root cause of recurring issues and working with management and the larger SSG Product Security Office team to address programmatically
- Assessing risk and prioritizing mitigation and remediation activities
- Serving as a security subject matter expert and technical leader to internal and external product and services teams, suppliers, partners, security researchers, and business leaders
- Researching, identifying, developing, and/or customizing tools, tactics, and procedures for enhancing security assessment effectiveness
- Staying current on threats, vulnerabilities, attack techniques, new tools, and industry trends
- Facilitating, supporting, and managing assessments performed by our 3rd-party security partners
- Mentoring and collaborating with other security test engineers
- Supporting secure development lifecycle initiatives
- Installing, configuring, and using products, tools, and operating systems
- Five-plus (5+) years of practical experience assessing and securing integrated solutions built upon products that power data center and cloud environments - such as application software, APIs, clusters, cloud service configuration, embedded systems, microservices, network storage solutions, operating systems, web applications, etc.
- Expertise in hands-on technical security assessments (e.g., penetration testing, vulnerability assessment, red teaming, etc.)
- Deep understanding of security weaknesses, identification, exploitation, and remediation
- Mastery of security assessment tools and helpers, such as Burp Suite Pro, curl, IDA Pro, Kali, Metasploit, Nessus, nmap, Wireshark, and similar
- Mastery of security foundations such as authentication, hardening, least privilege, attack surface reduction, protection rings, cryptography use, static analysis, dynamic analysis, fuzzing, CVSS, CWE, OWASP/SANS/CIS Top X, etc.
- Deep knowledge of and comfort with TCP/IP, including using and securing fundamental networking protocols such as TCP, UDP, ICMP, DNS, HTTP, HTTPS, SSH, etc.
- Understanding, applied use, and compliance with security standards such as NIST SP800-series, NIST Cybersecurity Framework, FISMA/FedRAMP, ISO 27000-series, PCI-DSS, CIS Benchmarks, and similar
- Moderate programming and/or scripting skills in at least one modern programming language
- Ability to install, configure, and use products, tools, and operating systems
- Performing code reviews and reviewing the results of static analysis tools
- Working with geo-diverse teams across different time zones
- Strong collaboration skills over application sharing platforms and teleconferencing
- Technical consulting background
- Knowledge of Lenovo products and services
- Security certifications: CISSP, CSSLP, CEH, OSCP, or similar desired
- Self-motivated and results driven, able to effectively work independently or as part of a team, able to motivate and cultivate collaborative relationships
- A strong technical leader to internal and external teams, suppliers, partners, and security researchers, with the ability to persuade and influence
- A critical thinker and problem solver, who is naturally curious and a consummate learner
- A good communicator, capable of clearly explaining and documenting security findings and mitigations
- Able to navigate sometimes contentious situations and successfully resolve conflicts with respect and professionalism
- Adept at multi-tasking and achieving results in a high-pressure environment while adapting to fluid business demands
- India - Karnātaka - Bangalore
- India - Karnātaka - BANGALORE
- India
- India - Karnātaka
- India - Karnātaka - Bangalore , * India - Karnātaka - BANGALORE