Lead Information Security Engineer

New
T
ThoughtworksTechnology Consultancy
This role will be situated in India. The role is remote first, with some expectation to be able to work from the closest Thoughtworks office on a regular cadence., Calls and collaboration outside standard local business hours are a normal and expected part of the role.Full-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Languages
A high standard of written and spoken English. Professional working proficiency equivalent to C1 in the CEFR is a minimum.
Experience
At least 5-7 years of hands-on experience in information security, spanning security engineering, testing, or architecture.
Required Skills
Python

Requirements

  • At least 5-7 years of hands-on experience in information security (engineering, testing, or architecture).
  • Ability to read, reason about, and contribute to code and scripts as a practitioner.
  • Demonstrated experience leading initiatives across multi-disciplinary teams and managing competing priorities.
  • Strong verbal and written communication skills with the ability to explain technical risk to non-technical stakeholders.
  • High standard of English (Professional working proficiency equivalent to C1 in the CEFR).
  • Experience operating in distributed, multicultural environments across different time zones.
  • Strong understanding of cloud environment security (AWS, GCP).
  • Familiarity with AI system security and LLM application risks.
  • Practical experience with penetration testing (web, API, cloud) and OWASP Top 10 knowledge.
  • Experience operating and tuning enterprise SIEM platforms.
  • Bachelor's degree in computer science, information assurance, MIS, or equivalent experience.

Responsibilities

  • Lead and contribute to hands-on security architecture initiatives across multi-functional, multi-disciplinary teams.
  • Review and threat model system and application designs, providing actionable security recommendations.
  • Harden security architecture for cloud and SaaS estates, including identity, network exposure, and configuration.
  • Test AI and LLM-backed applications for security weaknesses, such as prompt injection and tool integration issues.
  • Plan and run offensive security tests across web applications, APIs, and cloud environments.
  • Write and contribute to scripts and automation to support security operations and testing workflows.
  • Operate and maintain SIEM platforms, including tuning detection rules and improving alert quality.
  • Contribute to incident response, post-incident reviews, and the development of SOAR playbooks.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now