Lead Security Engineer
Job Description
Huron is redefining what a global consulting organization can be. Advancing new ideas every day to build even stronger clients,...
Job Description
Huron is redefining what a global consulting organization can be. Advancing new ideas every day to build even stronger clients, individuals and communities. We’re helping our clients find new ways to drive growth, enhance business performance and sustain leadership in the markets they serve. And, we’re developing strategies and implementing solutions that enable the transformative change they need to own their future.
As a member of the Huron corporate team, you’ll help to evolve our business model to stay ahead of market forces, industry trends and client needs. Our accounting, finance, human resources, IT, legal, marketing and facilities management professionals work collaboratively to support Huron’s collective strategies and enable real transformation to produce sustainable business results.
Join our team and create your future.
The individual will work closely with security, infrastructure, and application teams to identify risks, provide actionable remediation guidance, and help define and mature enterprise security best practices.
Requirements:
Application Security Assessments (AppSec)
- Perform application security assessments across web, API, and internal applications using OWASP methodologies (OWASP Top 10, OWASP ASVS, OWASP Testing Guide) and other industry‑accepted frameworks.
- Conduct Dynamic Application Security Testing (DAST) to identify runtime vulnerabilities such as injection flaws, authentication/authorization issues, session management weaknesses, and business logic flaws.
- Perform Static Application Security Testing (SAST) to analyze source code and binaries for insecure coding patterns, vulnerabilities, and compliance with secure coding standards.
- Carry out manual secure code reviews to identify complex vulnerabilities that automated tools may miss, including logic flaws, insecure cryptographic usage, and improper input validation.
- Provide clear, actionable remediation guidance to development teams, including secure coding recommendations and examples.
- Work closely with application owners and developers to retest fixes and confirm successful remediation.
- Conduct vulnerability scanning, monitoring, and reporting across enterprise assets using Tenable and other relevant tools.
- Analyze vulnerability scan results, validate findings, eliminate false positives, and prioritize remediation activities.
- Provide clear mitigation and remediation recommendations to infrastructure, application, and operations teams.
- Proactively follow up on remediation efforts and track vulnerability closure to ensure risk reduction.
- Assist in designing, developing, and executing penetration testing plans for applications, networks, cloud, and infrastructure environments.
- Perform manual and automated security testing to identify vulnerabilities, misconfigurations, and exploitable weaknesses.
- Develop and maintain custom scripts and security tools to enhance penetration testing, automation, and validation efforts.
- Collaborate with cross‑functional teams to perform security reviews and assessments for applications and network components.
- Perform basic to intermediate threat analysis and malware analysis to understand attacker techniques and behaviors.
- Research emerging threats, vulnerabilities, exploits, and attack techniques relevant to the organization.
- Recommend security enhancements, tools, and process improvements based on threat intelligence and industry trends.
- Bachelor’s or master’s degree in computer science or related on field experience is a must.
- Experience using Burp Suite, Owasp ZAP and other application security assessment tools.
- Experience of performing secure code reviews and static reviews using different tools or manually.
- Strong hands‑on experience with vulnerability assessment and penetration testing.
- Experience using Tenable (Nessus/) for vulnerability management and other penetration testing tools like nmap, Metasploit etc.
- Solid understanding of network, application, endpoint, and infrastructure security.
- Proficiency in scripting or programming (, Python, Bash, PowerShell, or similar) for custom security tools and automation.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS, authentication mechanisms, and common attack techniques.
- Ability to clearly document findings and communicate risks to both technical and non‑technical stakeholders.
- Proactive mindset with the ability to identify, track, and follow up on security risks.
- Good to have Knowledge or experience in threat intelligence, malware analysis, or reverse engineering
Vulnerability Management
Offensive Security & Penetration Testing:
Threat, Malware & Research (Good to Have)
Preference:
Position Level
Senior AssociateCountry
IndiaBelow are some other jobs we think you might be interested in.
-
Lead Security Engineer
- Navi
- Bengaluru, KA, IN
Job Description About the Role\n\nWe are seeking a lead security engineer to architect our overarching security strategy, build robust defenses, and...15 Jun -
Lead Security Engineer
- Chargebee
- Chennai, TN, IN
Job Description About Chargebee: Chargebee is a subscription billing and revenue management platform powering some of the fastest-growing brands around...16 Jun -
Lead Security Engineer
- HighLevel
- India
About Us HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses...28 May -
Security Lead
- Eventus Security
- Ahmedabad, GJ, IN
Job Description Job Title: Security Lead - SOC Job Location: Ahmedabad Experience: 4-5 yrs of experience We are seeking an experienced Level 3...29 May -
Lead Security
- Adani Group
- Andhra Pradesh, India
About Business:Adani Group: Adani Group is a diversified organisation in India comprising 10 publicly traded companies. It has created a world class...12 Jun -
Security Engineer
- TAC Security
- New Delhi, DL, IN
Job Description Job description\nAs a Security Engineer - VAPT, you will be responsible for conducting comprehensive security assessments, identifying...14 Jun -
Lead Security Data Engineer
- NorthStar HR Consultants
- Pune District, MH, IN
Job Description Job Title - Lead Security Data Engineer Job Location - Pune, Maharashtra Must Have Skills - Python, Security Operations, Querying,...16 Jun -
Lead Security Data Engineer
- NorthStar HR Consultants
- Pune, MH, IN
Job Description Job Title - Lead Security Data Engineer\nJob Location - Pune, Maharashtra\nMust Have Skills - Python, Security Operations, Querying,...08 Jun -
Lead - Security
- Adani Group
- Singrauli, Madhya Pradesh, India
Educational Qualification: Bachelor's degree in Business Management or other relevant field Postgraduate degree in relevant field Preferable to have...12 Jun -
Lead -Security
- Adani Group
- Udupi, Karnataka, India
4-5 years of experience in security management Minimum Bachelor's degree in a related field Develop and implement security policies, procedures, and...26 May -
Lead - Security
- Adani Group
- Jharsuguda, Odisha, India
Educational Qualification: Bachelor's degree in Business Management or other relevant field Postgraduate degree in relevant field Preferable to have...12 Jun -
Lead AI Security Engineer
- AU SMALL FINANCE BANK
- Jaipur, RJ, IN
Job Description Role: Lead AI Security Engineer We are seeking an experienced Lead AI Security Engineer to lead the secure design and implementation of...16 Jun -
Lead Product Security Engineer
- Cloud Software Group
- Bangalore,19,IN,560001
About Cloud Software GroupCloud Software Group combines the capabilities of both Citrix and TIBCO, creating one of the world’s largest cloud software...12 Jun -
Lead Application Security Engineer
- InMobi
- Bangalore, Karnataka, India
What does the team do? Opportunity is part of the evolving cyber security group which is laser focussed on setting up industry benchmarks in managing &...27 May -
Lead AWS Security Engineer
- Hapag-Lloyd AG
- Chennai, India
The Security Engineer plays a crucial role in ensuring the security and compliance of cloud environments. They combine deep technical knowledge of AWS...23 May -
Lead Cloud Security Engineer
- InMobi
- Bengaluru
About the job What does the team do? Opportunity is part of the evolving cybersecurity group, which is laser-focused on setting up industry benchmarks...16 Jun -
Lead Information Security Engineer
- Principal Global Services
- Hyderabad,Telangana,India,500032
Responsibilities What Makes This Opportunity UniqueAt Principal Financial Group, we prioritize creating an extraordinary environment where our...13 Jun -
Senior Security Engineer
- Eventus Security
- Mumbai, MH, IN
Job Description Job Title: Senior Security Engineer Job Location: Sanpada, Navi Mumbai Experience: 3+ yrs of experience Job Summary We are...16 Jun -
Lead Engineer - Cloud Application Security
- Emerson
- PUNE, MAHARASHTRA, India
Position Summary: As part of Emerson's Cross Portfolio, Technology, and Innovation (CPTI) team within Measurement Solutions, the Lead Engineer - Cloud...27 May -
Principal Application Security Engineer I
- RSA Security
- Bangalore,India,560048
Product OverviewOutseer Fraud Manager is an advanced, omnichannel fraud detection hub that provides risk-based, multi-factor authentication for...18 May