Cyber Sec Archt/engr II

Honeywell Honeywell · Industrial · Bengaluru, Karnataka, India

Cyber Security Engineer II responsible for assessing and evaluating the security posture of Honeywell IA Products and partner technologies. This role involves delivering security testing services, including the use of various security toolsets, detection of security defects, and remediation consultation. The goal is to identify potential attack techniques and improve the product development lifecycle.

What you'd actually do

  1. Deliver Security Testing across all IA products.
  2. Report observations using our standardized reporting structure
  3. Work with cross functional teams to develop remediation suggestions
  4. Develop methodologies, determine scoping requirements
  5. Assist in the development of modular, repeatable, effective Security Testing processes

Skills

Required

  • Cyber Security or Information Technology experience
  • Secure Development Lifecycle processes
  • OWASP Top 10 and SANS Top 25
  • application protocols, development, and common attack vectors
  • cybersecurity capabilities
  • software engineering skills
  • communication and negotiation skills
  • interpersonal skills
  • work with geographically distributed, cross-functional teams

Nice to have

  • pentesting experience
  • Web, Mobile, Network, Thick Client, API, Web services, Cloud, Containers, AI ML, Embedded security ( Hardware and Firmware) , Protocol fuzzing
  • penetration tests (Manual & Automated)
  • reverse engineering tools, debuggers, and dynamic analysis techniques
  • Analyze pen test results to identify the security vulnerabilities and suggest countermeasures for threat mitigation
  • attack frameworks like MITRE, VASTO, CIS Benchmarks, Virtualization Assessment Toolkit
  • manual product penetration testing experience
  • penetration testing tools and frameworks like Nessus, Web Inspect, Nmap, Burp Suite, AppScan, ZAP, Kali Linux tools, IDA Pro, GHidra, OWASP, Metasploit, Nessus, Nmap, MObSF, Genymotion, Frida, APK Tool
  • Encryption tools and techniques
  • Scripting experience in Python, Powershell and Bash
  • Experience working with other languages such as C, C++, Java, .NET or javascript
  • current and emerging security threats and techniques
  • Certification such as CEH, OSCP, OSWE, CCSP, CCSK, GPEN, CRTP, CRTO
  • Strong Secure SDLC concepts
  • integrating pentest tools to CI/CD pipeline

What the JD emphasized

  • Bachelor’s degree in computer science or software engineering, electrical engineering or equivalent experience
  • 2+ years of Cyber Security or Information Technology experience
  • 2+ years of pentesting experience preferably in – Web, Mobile, Network, Thick Client, API, Web services, Cloud, Containers, AI ML, Embedded security ( Hardware and Firmware) , Protocol fuzzing