Description :
- Red Team Assessment / Support
- SAP Security, Authorizations and GRC Access Control
- IT / OT Security Assessments and Implementation
- ISO 27001 ISMS Implementation and Certification
- Vendor Security & Risk Assessment
- Cyber / Security Incident Response, Investigation, Root Cause Analysis, Corrective and Preventive Action Plans
- Supporting various Internal / External / Cybersecurity and Certification Audits
- Providing information security support for IT / Business projects and enquiries from other functions and business across the APAC / EMEA Region
- Assessing and managing risks, vulnerabilities, threats and compliance within the Region
- Develop, use and continuously improve a formal set of processes by which the organization can identify various security concerns, gaps and remedial actions to ensure the appropriate IT Security resilience of the infrastructure
- Implement and sustain the Group Standards / Policies and Guidelines on Information Security
- Develop Local / Regional specific Security Guidelines / Processes and implement in APAC Region, as needed
- Co-ordinate with Internal Teams within IT / Business and ensure critical audit findings and gaps are addressed in timely manner
- IT Security / Cybersecurity Projects Business Case Preparation, Project Management and Governance
Your Role & responsibilities :
Primary Responsibilities :
Internal and External Vulnerability Assessment and Penetration Testing All kind of applications Client / Web / Mobile, IT Infrastructure and Network DevicesRetesting / Revalidation, post remediation if vulnerabilitiesPreparing VAPT Report and provide the walkthrough of findings and evidences to IT Infrastructure, Application Support and Development TeamsSupporting the implementation of DevSecOpsSecondary Skills / Responsibilities :
Red Teaming / Purple Team operationsInternal Red Team AssessmentIT / OT Cybersecurity Assessment and Penetration TestingWiFi Pen TestYour profile :
Bachelors degree in Computer Science, Information Technology or Engineering degree in any discipline with experience / skills in Information Security / Cybersecurity.Must have at least one practical / lab / challenge penetration testing certification (OSCP, OSWE, OSCE, OSEE, SANS, eCPPTv2, eCPTX, eWPTXv2, etc.);CEH / CFIH / CISSP / CISM / CRISC certifications are optional / added advantageYour experience :
At least 5+ years of experience in Information Security / Cybersecurity, primarily in performing VulnerabilityAssessment and Penetration Testing for Web / Mobile / Client Applications, IT Infrastructure and Network Devices,Red Team Assessment, OSINT, Purple Teaming, etc.Required skills :
Penetration Testing using various open source and professional tools and methodologies.Good command over Kali Linux and ToolsNIST Cybersecurity and MITRE FrameworkOpen Source Intelligence (OSINT)Knowledge and Experience in VA / PT Tools like Kali Linux, Nessus, MetaSploit, Acunetix, BurpSuite, MobSF, etc.Top 10 OWASP Vulnerabilities and Attack VectorsPhishing and Social Engineering Attack vectorsPrivilege Escalation TechniquesApplication Security / SSDLC / DevSecOpsNetworking and IT Security FundamentalsLeadership & Soft skills :
Open-minded, collaborative and an effective team player.Ability to work in a multicultural and diverse team.Good in Document / report preparation for Penetration TestingCommitted to deliver the VAPT and report in the agreed time / SLADriven for success and aspiring to a culture of service excellence, always putting the customer, our people and our business at the center of everything he / she does.Ability to deal with ambiguity / conf. to work proactively and under pressure considering the criticality required to ensure the right quality of service for the business.Lead by example on values and culture.Key Personal Attributes :
Security and Continuous Improvement Mind-setBusiness focused, Customer & Service mindedStrong Consultative and Management skillsConfident in advising, developing and articulating solutionResult oriented and with a work ethic of delivering on-time and in scopeOpen to Change and Attitude to challenge the Status Quo, as neededLanguage Requirements :
Fluent written and spoken English with good command on inter personal and business communication.Work Location :
Navi Mumbai, IndiaHybrid working / Remote working model as per company policyTravel requirements :
May be required, depending on the business / project requirements
(ref : hirist.tech)