Cyber Security Engineer

4 - 8 years

20 - 35 Lacs

Posted:None| Platform: Naukri logo

Apply

Work Mode

Work from Office

Job Type

Full Time

Job Description

Job Title: Cybersecurity PSIRT Engineer

Experience: 4-8Yrs

Job Location: Pune

Job Summary:

We are seeking a mid-to-senior level Cybersecurity PSIRT (Product Security Incident Response Team) Engineer Contractor to strengthen our product security posture through vulnerability triage, coordinated disclosure, and hardware-aware threat modeling. This individual will play a key role in enhancing our incident response and vulnerability management workflows, with an emphasis on IoT and network embedded device security, hardware-centric bug bounty support, and security hackathon initiatives.

This is an exciting opportunity to contribute to both operational response and strategic development, supporting the continuous improvement of product security controls and the security quality feedback loop.

Key Responsibilities:

  • Lead or assist in the triage, technical analysis, severity scoring, and remediation

coordination, and coordinated disclosure processes for product security vulnerabilities.

  • Investigate and manage hardware and firmware-related security vulnerabilities

across hardware products (e.g., routers, switches, IoT devices).

  • Perform code analysis and vulnerability reproduction testing to identify potential

security issues.

  • Collaborate cross-functionally with engineering, threat intelligence, incident

response, and vulnerability research teams to analyze, triage, and resolve firmware

vulnerabilities.

  • Support the full lifecycle of incident response: detection, analysis, containment,

mitigation, and postmortem.

  • Conduct impact and risk assessments on vulnerability submissions to inform

appropriate prioritization and response actions.

  • Engage with external security researchers and bug bounty platforms (e.g.,

HackerOne, Bugcrowd) to handle submissions, validate findings, and close the loop with

engineering.

  • Help build out and evolve hardware-focused bug bounty and security hackathon

programs, including defining scope, engagement guidelines, and validation workflows.

  • Contribute to the security quality feedback loop by ensuring lessons learned from

incidents and vulnerabilities inform secure development practices, testing, and tooling.

  • Develop and maintain threat intelligence feeds relevant to our product and device

ecosystem.

  • Support the creation of attack surface maps and device risk modeling profiles,

aligned with MITRE ATT&CK, EMB3D, and internal threat models.

  • Apply and interpret CVE, CVSS, CWE, and CWSS scoring to measure and

communicate risk.

  • Author internal reports, vulnerability advisories, and coordinate with external

researchers and CERTs when needed.

  • Develop and refine internal tools, frameworks, and processes in support of work

processes and activities.

  • Document incident workflows, threat analyses, and remediation guidance in

Atlassian tools (Jira, Confluence) and coordinate via Slack.

Required Qualifications:

  • Bachelors degree in computer engineering, Computer Science, Cybersecurity, or

related field.

  • 48+ years in cybersecurity, with experience in product security, PSIRT, or

vulnerability management, ideally in an embedded or device-centric environment.

  • 3+ years of experience in embedded systems or firmware development, security

research, or vulnerability analysis.

  • Experience with secure software development lifecycles, fuzzing, or static/dynamic

analysis tooling.

  • Solid understanding of common vulnerability types (buffer overflows, privilege

escalations, etc.) in low-level code.

  • Proficient in IoT/embedded systems security architecture (firmware, trust anchors,

bootloaders, secure boot, memory safety, and wireless protocols).

  • Familiar with MITRE ATT&CK and EMB3D frameworks, and how to apply them to

threat modeling or response.

  • Able to replicate and assess exploitability and business impact of submitted

vulnerabilities.

  • Working experience with bug bounty operations and direct researcher interaction.
  • Skilled in vulnerability triage, severity scoring (CVSS, CWE/CWSS), and root cause

identification.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You

bengaluru, karnataka, india

hyderabad, chennai, bengaluru

Bengaluru, Karnataka, India