Cyber Sec Archt/engr II

Honeywell Honeywell · Industrial · Bengaluru, Karnataka, India

Cyber Security Engineer II responsible for assessing and evaluating the security posture of Honeywell HCE Products and partner technologies. This role involves security services delivery, including the use of various security toolsets, detection of security defects, and remediation consultation. The goal is to identify potential attack techniques and improve the product development lifecycle.

What you'd actually do

  1. Deliver Security Testing across all HCE products.
  2. Report observations using our standardized reporting structure
  3. Work with cross functional teams to develop remediation suggestions
  4. Develop methodologies, determine scoping requirements
  5. Assist in the development of modular, repeatable, effective Security Testing processes

Skills

Required

  • Bachelor’s degree in computer science or software engineering, electrical engineering or equivalent experience
  • Cyber Security or Information Technology experience
  • pentesting experience
  • penetration tests (Manual & Automated)
  • Analyze pen test results to identify the security vulnerabilities and suggest countermeasures for threat mitigation
  • Secure Development Lifecycle processes
  • OWASP Top 10 and SANS Top 25
  • attack frameworks like MITRE, VASTO, CIS Benchmarks
  • manual product penetration testing experience
  • penetration testing tools and frameworks like Nessus, Web Inspect, Nmap, Burp Suite, AppScan, ZAP, Kali Linux tools, IDA Pro, GHidra, OWASP, Metasploit, Nessus, Nmap, MObSF, Genymotion, Frida, APK Tool
  • Encryption tools and techniques
  • application protocols, development, and common attack vectors
  • cybersecurity capabilities
  • software engineering skills
  • current and emerging security threats and techniques for exploiting security vulnerabilities
  • Effective oral and written communication and negotiation skills
  • interpersonal skills
  • Ability to work with geographically distributed, cross-functional teams

Nice to have

  • Scripting experience in Python, Powershell and Bash
  • Experience working with other languages such as C, C++, Java, .NET or javascript
  • Certification such as CEH, OSCP, OSWE, CCSP, CCSK, GPEN, CRTP, CRTO
  • Strong Secure SDLC concepts
  • Experience in integrating pentest tools to CI/CD pipeline

What the JD emphasized

  • 2+ years of Cyber Security or Information Technology experience
  • 2+ years of pentesting experience preferably in – Web, Mobile, Network, Thick Client, API, Web services, Cloud, Containers, AI ML, Embedded security ( Hardware and Firmware) , Protocol fuzzing
  • Demonstrated manual product penetration testing experience