Cyber Sec Archt/engr II

Honeywell Honeywell · Industrial · Bengaluru, Karnataka, India

This role is for a Cyber Security Engineer II at Honeywell, responsible for assessing and evaluating the security posture of HCE Products and partner technologies. The role involves delivering security testing using various toolsets (including AI/ML security tools), detecting security defects, and providing remediation consultation. Key responsibilities include reporting observations, working with cross-functional teams, developing testing methodologies, and partnering with the Tools and Technology Team to automate testing. The role requires a Bachelor's degree in a relevant field and 2+ years of Cyber Security or IT experience, with preferred experience in penetration testing across various domains including AI/ML security.

What you'd actually do

  1. Deliver Security Testing across all HCE products.
  2. Report observations using our standardized reporting structure
  3. Work with cross functional teams to develop remediation suggestions
  4. Develop methodologies, determine scoping requirements
  5. Assist in the development of modular, repeatable, effective Security Testing processes

Skills

Required

  • Bachelor’s degree in computer science or software engineering, electrical engineering or equivalent experience
  • 2+ years of Cyber Security or Information Technology experience

Nice to have

  • 2+ years of pentesting experience preferably in – Web, Mobile, Network, Thick Client, API, Web services, Cloud, Containers, AI ML, Embedded security ( Hardware and Firmware) , Protocol fuzzing
  • Perform penetration tests (Manual & Automated) for products spanning Web, Mobile (Android and iOS), Cloud, Dockers, Containers and Thick Clients
  • Familiarity with reverse engineering tools, debuggers, and dynamic analysis techniques
  • Analyze pen test results to identify the security vulnerabilities and suggest countermeasures for threat mitigation
  • Good understanding of Secure Development Lifecycle processes
  • Good knowledge of OWASP Top 10 and SANS Top 25 and how to effectively remediate vulnerabilities associated with each
  • Knowledge of attack frameworks like MITRE, VASTO, CIS Benchmarks, Virtualization Assessment Toolkit to exploit virtualization systems
  • Demonstrated manual product penetration testing experience; for example, simulate a SQL injection attack without using tools, simulate XSS attack, X-Path Injection, etc.
  • Good knowledge and hands-on experience using various penetration testing tools and frameworks like Nessus, Web Inspect, Nmap, Burp Suite, AppScan, ZAP, Kali Linux tools, IDA Pro, GHidra, OWASP, Metasploit, Nessus, Nmap, MObSF, Genymotion, Frida, APK Tool
  • Encryption tools and techniques for securing mobile and virtual machines
  • Understanding of application protocols, development, and common attack vectors.
  • Good cybersecurity capabilities and strong software engineering skills
  • Scripting experience in Python, Powershell and Bash preferred.
  • Experience working with other languages such as C, C++, Java, .NET or javascript.
  • Up to date knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities
  • Effective oral and written communication and negotiation skills
  • Good interpersonal skills
  • Ability to work with geographically distributed, cross-functional teams
  • Certification such as CEH, OSCP, OSWE, CCSP, CCSK, GPEN, CRTP, CRTO will be highly desirable
  • Strong Secure SDLC concepts
  • Experience in integrating pentest tools to CI/CD pipeline

What the JD emphasized

  • 2+ years of Cyber Security or Information Technology experience
  • 2+ years of pentesting experience preferably in – Web, Mobile, Network, Thick Client, API, Web services, Cloud, Containers, AI ML, Embedded security ( Hardware and Firmware) , Protocol fuzzing