← WorkMundi · 1M+ jobs from around the world, liveSign inCreate free account

Security Platform Engineer (Contract) (India)

VettedBench · All India

📅 05/08/2026
🔔 Alert me about jobs like this
No password, no sign-up. Just the email — and you can leave the list anytime.
🔓 Apply — free →
Opens this job on WorkMundi. The account is free and takes under a minute.

See the other 113,540 jobs in India →

🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
Position Overview We are seeking a Security Platform Engineer specializing in Tool Configuration and Data Unification to bring deep security domain expertise to the hands-on configuration of our scanning and aggregation stack. This role is responsible for unifying the output of multiple security scanners into a single, coherent vulnerability language. You will tune what each tool detects, define how findings are normalized and deduplicated, and design the data model that transforms raw scanner output into defensible, evaluated vulnerability records. Working alongside DevSecOps engineers and GRC engineers, you will own the intelligence and structure of the security data pipeline determining what flows through it and how it is shaped to support FedRAMP compliance, audit evidence requirements, and actionable vulnerability management at scale. Key Responsibilities - Own scanner configuration and tuning across the detection fleet: scan policies, coverage scope, severity mappings, and signal quality for Trivy, Semgrep, Qualys, Tenable, AWS Inspector, CrowdStrike, and Dependabot - Design the deduplication and correlation strategy in DefectDojo: keying logic that recognizes the same vulnerability across image scans, runtime scans, host scans, and dependency scans, plus grouping rules that collapse duplicates into single actionable findings (target: ~70% ticket reduction) - Define the unified findings data model field schema, asset identity, component mapping that supports the FedRAMP 11-field vulnerability detail and 8-field accepted-vulnerability reporting schemas - Build the reachability signal layer: AWS Reachability Analyzer, service mesh, and eBPF-based signals feeding an internet-reachability (IRV/NIRV) determination per finding - Configure runtime visibility (CrowdStrike Falcon Cloud Security) and reconcile runtime observations against image-scan results to close the rebuilt-but-not-redeployed gap - Partner with the GRC engineer to ensure the data model captures everything the LEV IRV PAIN evaluation engine and audit evidence require - Validate detection coverage against the workplace (containers, hosts, serverless, dependencies, external surface) and identify blind spots Required Skills - 6+ years in security engineering with hands-on vulnerability management depth - Understanding of CVEs, CPE/PURL identity, scanner false-positive patterns, and scanner disagreement analysis - Demonstrated experience configuring and tuning multiple commercial and open-source scanning tools in production - Strong data modeling skills applied to security findings: normalization, deduplication, enrichment, asset correlation - Cloud security expertise in AWS including container security (image scanning, registry policy, runtime security) on EKS/ECS - Working knowledge of exploitability intelligence: CISA KEV, EPSS, VEX, and vulnerability prioritization - Experience with Trivy, Semgrep, Qualys, Tenable, AWS Inspector, CrowdStrike, and Dependabot - Experience with DefectDojo for vulnerability aggregation and deduplication Preferred (Bonus) Skills - DefectDojo experience, particularly its deduplication engine, parsers, and API - Experience with network reachability analysis (AWS Reachability Analyzer, service mesh telemetry, eBPF tooling) - Familiarity with FedRAMP VDR/VER concepts: LEV (Likely Exploitable), IRV/NIRV (Internet-Reachable), PAIN ratings, and timeframe classes - Experience writing custom scanner parsers or findings-transformation code in Python .
Read the rest of the job →
For people searching Engineer

144,883 engineer jobs are open right now

Here's how to pick the right one and stand out in your application.

144.883Jobs
31.687IN
81%EN

That number is real. WorkMundi's database shows 144,883 open engineer roles across the world. India has the most with 31,687 jobs, followed by the United States with 30,084. If you just finished reading one job ad and felt paralyzed by choice, you're not alone—but this scale is actually an advantage. It means you can afford to be selective.

Start by geography and language. The majority of engineer ads—117,837 of them—have the job posting text written in English. Use that as one filter, but remember: the ad text language tells you nothing about whether the role actually requires you to speak English day-to-day. Read the job description carefully. Then check which countries have the volume you're targeting. Singapore, Poland, and Australia round out the top five after India and the US.

Next, learn who's hiring. Accenture has posted 2,801 engineer roles. andurilindustries, speechify, and jobgether are also actively recruiting. If you're applying to one of these names, research their hiring patterns and interview style before you apply. That homework pays off.

When you interview, expect the question every engineer hears: 'Tell me about a time you had to debug a problem that wasn't in your job description.' Have a specific story ready—not a general one. Name the tools, the deadline pressure, and what you learned. Hiring managers listen for whether you see problem-solving as part of the role itself, not a favour.

👁 21 have read this
0 comments
Want to comment?

Leave your e-mail to comment, react and follow the posts for your role. It is free.

Similar jobs

Job on WorkMundi — the world's largest job board. See more jobs from every continent, updated live.

📢
🎁

Before you apply, rehearse this interview.

Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card.

I want my training →