Senior Developer 2
On-siteBengaluru, Karnataka, India
Job Summary
Develop security detection code and integrations for the Aurora Exposure Management platform by building vulnerability and misconfiguration detection tools, including host-based and network-based tests, and automating configuration benchmarks. Establish push and pull data sharing via third-party APIs and vendor feeds to enhance coverage portfolios while participating in the full software development lifecycle. Collaborate cross-functionally with Product Management and Security Services to improve detection efficacy and resolve operational results. Leverage AI-powered tools as a core part of your workflow to accelerate delivery and improve code quality. This role requires 6+ years of backend experience with AWS, Docker, and Kubernetes, and is based in Bangalore.
Required Qualifications
- 6+ Yrs Experience in at least one backend language (any of Go, Python, Rust preferred)
- A full understanding/application of secure development practices
- Experience with AWS, Docker, Kubernetes, IaC
- Security minded practitioners experienced in operational or security engineering roles with an emphasis in vulnerability and misconfiguration detection tooling
- Full understanding and use of DevOps methods and practices
- Understanding and ability to work with test-driven development
- Fluency with AI-assisted development: you've made AI tools a natural extension of how you work, know where they help and where they fall short, and prior experience in adopting them effectively
- Must Build well-designed, testable, efficient, secure vulnerability and misconfiguration detection code
- Host based vulnerabilities (OVAL based)
- Network-based vulnerability tests (NVTs)
- Integration with Third Party APIs / Vendor feeds
- Configuration Benchmark automations development (i.e. CIS)
- Pipeline hardening checks and policy development
- Cloud Config and Posture Management
- Development of security policy in cloud service providers
- Assist in operational teams to resolve unexpected results, receive feedback and improve detection efficacy
- Leverage AI-powered tools (e.g., code assistants, AI-augmented debugging, and automated testing) as a core part of your development workflow using them to accelerate delivery, improve code quality, and explore solutions faster
- Only Bangalore Based Candidates
- Conducts duties and responsibilities in accordance with AWN's Information Security policies, standards, processes, and controls
- Background checks are required for this position
- Authorization to receive software or technology controlled under U.S. export control laws and regulations
Desired Qualifications
- Experience with 3rd Party Vulnerability Management tools (Qualys, Nessus, Rapid7, OpenVAS)
- Experience with Cloud-based configuration and Security Posture Management tools (Azure Security Centre, AWS Security Hub, Sonrai, Cloudsploit, Prisma Cloud)
- A background working with open-source vulnerability and pen-testing platforms such as Nmap, OpenVAS, Burp, or Metasploit
- IT Deployment backgrounds in particular leveraging deployment automation tools such as Salt or Ansible
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.