Senior security consultant
Eventus Security · Navi mumbai, India
Job Description
We are seeking a highly skilled and experienced Principal / Senior Security Consultant (L3) to join our Cyber Resilience team. The ideal candidate should possess strong expertise across Application Security, Infrastructure Security, Cloud Security, AI Security, and Dev Sec Ops, with the ability to independently lead complex security engagements for enterprise clients.
The role requires hands-on technical expertise, client-facing communication, project ownership, mentoring junior consultants, and contributing to the organization's cybersecurity strategy and innovation initiatives.
Key Responsibilities
1. Security Assessments
Perform Web Application Penetration Testing. Conduct Mobile Application Security Testing (Android & i OS). Execute API Security Assessments. Perform Thick Client Application Security Assessments. Conduct Internal and External Infrastructure Vulnerability Assessment & Penetration Testing. Perform Active Directory Security Assessments. Execute Wireless Security Assessments. Conduct Database Security Assessments and Secure Configuration Reviews. Perform Cloud Security Assessments across AWS, Azure, and GCP environments. Conduct AI Security Assessments for LLM-based applications, AI APIs, chatbots, and intelligent agents. Identify business logic flaws, authentication bypasses, privilege escalation issues, and advanced attack vectors. Validate remediation through retesting and provide detailed technical guidance.2. Dev Sec Ops & Secure SDLC
Perform Static Application Security Testing (SAST). Perform Dynamic Application Security Testing (DAST). Conduct Software Composition Analysis (SCA). Review open-source dependencies and third-party libraries for security risks. Perform Secure Code Reviews and identify coding vulnerabilities. Integrate security testing into CI/CD pipelines and Dev Sec Ops workflows. Recommend secure coding practices and development standards. Support organizations in implementing Secure SDLC processes.3. AI Security & Emerging Technologies
Assess AI and Large Language Model (LLM) applications for security risks. Perform Prompt Injection and Jailbreak Testing. Identify AI data leakage and model abuse scenarios. Evaluate AI plugins, agents, and integrations for security weaknesses. Assess AI APIs and underlying infrastructure. Recommend security controls based on industry best practices and the OWASP Top 10 for LLM Applications.4. Threat Modeling & Architecture Review
Conduct Threat Modeling using methodologies such as STRIDE. Perform Attack Surface Analysis for critical applications. Review Data Flow Diagrams (DFDs) and identify trust boundaries. Conduct Security Architecture Reviews for enterprise applications and platforms. Perform Network Architecture Reviews to identify design-level security gaps. Conduct Network Segmentation Reviews and validate isolation between critical environments. Provide recommendations aligned with Zero Trust Architecture principles.5. Infrastructure & Configuration Security
Perform Secure Configuration Reviews for Cloud, Infrastructure and Network devices. Review Identity and Access Management (IAM) configurations. Assess containerized environments and Kubernetes security configurations. Validate compliance against security benchmarks and industry standards.6. Project Delivery & Management
Lead end-to-end cybersecurity assessment engagements independently. Plan and execute projects within agreed timelines and scope. Coordinate with clients and internal stakeholders throughout the project lifecycle. Manage multiple security engagements simultaneously. Ensure adherence to internal quality standards and delivery processes. Track project progress and escalate risks proactively.7. Client Engagement
Conduct project kick-off meetings. Understand business and technical requirements from clients. Present technical findings and executive summaries to stakeholders. Provide remediation guidance and best-practice recommendations. Participate in closure meetings and answer client queries. Build strong client relationships through technical excellence and professionalism.8. Reporting & Documentation
Prepare comprehensive technical assessment reports. Develop executive summaries for management teams. Ensure accurate CVSS scoring and business impact mapping. Review reports prepared by junior consultants. Maintain documentation in accordance with organizational standards.9. Leadership & Mentoring
Mentor and guide L1 and L2 Security Consultants. Review technical deliverables and provide constructive feedback. Conduct internal training sessions and knowledge-sharing initiatives. Support recruitment through technical interviews and candidate evaluations. Contribute to the development of internal SOPs and technical playbooks.10. Research & Innovation
Stay updated with emerging threats, vulnerabilities, and attack techniques. Research new security technologies and methodologies. Develop custom scripts and automation to improve testing efficiency. Contribute to internal security tools and frameworks. Publish technical blogs, advisories, and research papers where applicable.11. Presales & Solutioning Support
Support RFP and RFI responses. Assist in project effort estimation and solution design. Review Statements of Work (SOW) and technical requirements. Participate in customer demos and technical discussions. Provide cybersecurity consulting support during presales activities.Qualifications
Bachelor's degree in computer science, Information Technology, Cyber Security, or a related field. 6–9 years of hands-on cybersecurity experience. Strong understanding of enterprise security architecture and modern attack techniques.Preferred Certifications
OSCP, OSCE CRTP, CRTO, CISSP, CISM, Comp TIA Security+, AZ-500Designation will be finalized based on the interview evaluation
Details
| Company | Eventus Security |
| Location | Navi mumbai, India |
| Type | FULL TIME |
| Niche | general |
| Experience | permanent |
