FULLTIME
Principal Security Engineer
GeoServe
Not specified · onsite · Posted today
Your match
Sign in to see your match score, skill gaps & tailored resume.
Section · 01
About this role
About the Role Geoserve Energy Transport is seeking a hands-on
Principal Security Engineer to build, own, and run the organization's information and application security function. This is a working leadership role — you will personally drive vulnerability management, penetration testing, and perimeter security, not just oversee it. You'll be the single point of accountability for the security posture of Geoserve's product suite and supporting infrastructure, reporting directly to the Head of Engineering.
Key Responsibilities
- Own end-to-end VAPT (penetration testing) across web, API, mobile, network, and cloud environments; manage vendors, validate findings, and drive remediation to closure with SLA-based severity tracking
- Deploy and manage automated security tooling (SAST/DAST/SCA, container scanning) integrated into CI/CD pipelines for shift-left security
- Maintain vulnerability inventory, risk register, and regular scanning cadence across all assets
- Own perimeter and infrastructure security — firewalls, WAF, IDS/IPS, VPN, network segmentation, and AWS cloud security posture (IAM, encryption, logging)
- Build incident detection and response capability (SIEM, alerting, runbooks)
- Develop security policies aligned with ISO 27001; own audit/regulatory readiness for a maritime/energy logistics business
- Report security posture and risk to leadership; mentor and grow the security function
- Drive security awareness training org-wide
Required Qualifications
- Bachelor’s degree in computer science, Information Security, or related field (Master's a plus)
- 8–12+ years in information security, with at least 3–4 years in a security leadership role
- Demonstrated hands-on experience running VAPT programs and vulnerability management at scale
- Strong working knowledge of OWASP Top 10, MITRE ATT&CK framework, and common exploitation/defense techniques
- Experience securing cloud environments (AWS strongly preferred; Azure/GCP a plus)
- Experience with CI/CD security integration and DevSecOps practices
Sourced from linkedin · view original
Let the agent run this one for you.
Tailored resume, auto-apply, and referral lookup — in under 2 minutes.
Section · 02