Lead Information Security Engineer
New
T
ThoughtworksTechnology Consultancy
This role will be situated in India. The role is remote first, with some expectation to be able to work from the closest Thoughtworks office on a regular cadence., Calls and collaboration outside standard local business hours are a normal and expected part of the role.Full-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Languages
- A high standard of written and spoken English. Professional working proficiency equivalent to C1 in the CEFR is a minimum.
- Experience
- At least 5-7 years of hands-on experience in information security, spanning security engineering, testing, or architecture.
- Required Skills
- Python
Requirements
- At least 5-7 years of hands-on experience in information security (engineering, testing, or architecture).
- Ability to read, reason about, and contribute to code and scripts as a practitioner.
- Demonstrated experience leading initiatives across multi-disciplinary teams and managing competing priorities.
- Strong verbal and written communication skills with the ability to explain technical risk to non-technical stakeholders.
- High standard of English (Professional working proficiency equivalent to C1 in the CEFR).
- Experience operating in distributed, multicultural environments across different time zones.
- Strong understanding of cloud environment security (AWS, GCP).
- Familiarity with AI system security and LLM application risks.
- Practical experience with penetration testing (web, API, cloud) and OWASP Top 10 knowledge.
- Experience operating and tuning enterprise SIEM platforms.
- Bachelor's degree in computer science, information assurance, MIS, or equivalent experience.
Responsibilities
- Lead and contribute to hands-on security architecture initiatives across multi-functional, multi-disciplinary teams.
- Review and threat model system and application designs, providing actionable security recommendations.
- Harden security architecture for cloud and SaaS estates, including identity, network exposure, and configuration.
- Test AI and LLM-backed applications for security weaknesses, such as prompt injection and tool integration issues.
- Plan and run offensive security tests across web applications, APIs, and cloud environments.
- Write and contribute to scripts and automation to support security operations and testing workflows.
- Operate and maintain SIEM platforms, including tuning detection rules and improving alert quality.
- Contribute to incident response, post-incident reviews, and the development of SOAR playbooks.
View Full Description & ApplyYou'll be redirected to the employer's site