Identification and remediation of new vulnerabilities and risk analysis for Infrastructure is a key responsibility.
Identifying and maintaining Key metrics and SLA on Infrastructure Security.
Ensure that vulnerability assessments are performed to evaluate effectiveness of security controls in applications, middleware, databases, network and operating systems.
Thorough experience in configurations reviews against CIS benchmarks and security standards.
Ensure all Hardening and Patching activities are conducted and tracked as per defined policies.
Create/Update hardening documents and build audit file for automated testing.
Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities.
Conduct security penetration testing to identify vulnerabilities and potential security risks along with designing and implement security solutions to protect enterprise systems, applications, data, assets, and people.
Collaborate with crossfunctional teams to ensure security measures are integrated into all aspects of the organizations operations.
Perform Internal/ External Penetration Testing on Jio Infrastructure and producing reports with recommendations for detailed penetration testing findings.
Ability to analyse vulnerabilities to appropriately characterize threats and provide remediation advice. Familiarity with classes of vulnerabilities, appropriate remediation, and industrystandard classification schemes (CVE, CVSS, CPE).
Extensive experience in vulnerability management, including the ability to forecast potential threats and develop proactive mitigation plans.
Hands on experience in testing diverse infra components including various enterprise platforms such as private clouds, OpenShift infra, dockers/container infra etc
The candidate should be able to perform manual & automated penetration testing for internal, external perimeter, web applications, IT infrastructure, endpoints, cloud etc using hacking tools; eg Nuclei, Acunetix, BURP, Wireshark, Nmap, netcat, Firebug, Nessus, Kali OS, Parrot, Metasploit, Aircrackng
Proven ability to develop and test Proof of Concept (PoC) exploits as part of vulnerability assessment and penetration testing exercises.
Mandatory skill sets
Identifying and maintaining Key metrics and SLA on Infrastructure Security.
Preferred skill sets
Identifying and maintaining Key metrics and SLA on Infrastructure Security.
Years of experience required
46 years of experience
Education qualification
bachelors/masters in CS, IT, or related field (B.E./B.Tech/MCA)
Education
Degrees/Field of Study required Master of Engineering, Bachelor of Engineering
Degrees/Field of Study preferred
Required Skills
Good Clinical Practice (GCP)
Accepting Feedback, Accepting Feedback, Active Listening, Agile Methodology, Analytical Thinking, Azure Data Factory, Coaching and Feedback, Communication, Creativity, Cybersecurity, Cybersecurity Framework, Cybersecurity Policy, Cybersecurity Requirements, Cybersecurity Strategy, Embracing Change, Emotional Regulation, Empathy, Encryption Technologies, Inclusion, Intellectual Curiosity, Learning Agility, Managed Services, Optimism, Privacy Compliance, Professional Courage {+ 13 more}