Home
Jobs

1810 Nist Jobs - Page 9

Filter
Filter Interviews
Min: 0 years
Max: 25 years
Min: ₹0
Max: ₹10000000
Setup a job Alert
JobPe aggregates results for easy application access, but you actually apply on the job portal directly.

3.0 years

0 Lacs

Hyderabad, Telangana, India

On-site

Linkedin logo

About Darwinbox : We’re designing the future of work by building the world's best HR tech, driven by a fierce focus on employee experience, customer success, and continuous, iterative innovation. Founded in 2015, we now serve over 2.5 million employees in 750+ enterprises, and that includes massive conglomerates to unicorn start-ups, like MakeMyTrip, JSW, Vedanta, Mahindra, Kotak, plus leading global brands like Nivea, Starbucks, Sephora, AXA, Cigna, T-Systems, and Calvin Klein. We’re backed by marquee investors like TCV, Salesforce, Sequoia, Lightspeed Ventures, Microsoft, and many others, which have put us on the pedestal of Unicorn valuation in the year 2022. But most importantly, we’re growing at a phenomenal pace, and that means exponential growth and learning opportunities for you, plus a band of passionate and fun people to work with within a place where your ideas take precedence over your designation. Why Join Us? The rate at which our product and market presence are growing is unprecedented. We’re a Rocketship. We’re not planning on slowing down anytime soon. And , that’s why we need you! You’ll experience a culture of: Disproportionate Rewards for top performance Accelerated Growth in a hyper-growth environment Wellbeing First culture focused on employee care Continuous Learning and Professional Development Meaningful Relationships and a Collaborative Environment Role Overview: We are seeking a detail-oriented and proactive Information Security Compliance Analyst (contractor) with 2–3 years of relevant experience. The ideal candidate will have a strong understanding of ISMS audits, Corrective Action Plan (CAP) closure, audit processes and terminology, third-party risk assessments, and deep familiarity with ISO 27001:2013 and ISO 27001:2022 standards. The candidate must be capable of conducting independent audits and demonstrate hands-on experience in audit execution. Basic knowledge of cloud technologies and backup processes is essential. Responsibilities Plan, execute, and report on ISMS audits, ensuring compliance with ISO 27001:2013 and ISO 27001:2022 standards. Independently conduct internal and external audits, including fieldwork, documentation, and wrap-up activities. Track and ensure closure of Corrective Action Plans (CAP) and audit findings. Perform and document third-party risk assessments, collaborating with stakeholders to mitigate identified risks. Maintain and update ISMS documentation, policies, and procedures as per regulatory and organizational requirements. Support audit preparation, evidence collection, and response to client security questionnaires. Assist in monitoring compliance metrics and identifying areas for improvement. Apply audit terminology and best practices to evaluate the effectiveness of IT security controls, policies, and procedures. Ensure basic compliance and security controls for cloud infrastructure and backup processes are in place and effective. Requirements: Bachelor's degree in Information Security, Computer Science, or a related field (preferred but not mandatory). 2–3 years of hands-on experience in information security compliance, audit, or risk management. Strong understanding of ISMS audits, audit terminology, and CAP closure processes. In-depth knowledge of ISO 27001:2013 and ISO 27001:2022 standards (mandatory). Experience conducting independent audits and preparing audit reports. Exposure to third-party risk assessments and vendor security evaluations. Basic knowledge of cloud computing concepts and backup technologies. Excellent written and verbal communication skills. Strong analytical, investigative, and problem-solving abilities. Ability to work independently and manage multiple priorities. Preferred Qualifications Professional certifications such as ISO 27001 Lead Auditor, CISA, CISM, or similar (preferred but not mandatory). Experience with compliance frameworks beyond ISO 27001 (e.g., SOC 2, NIST, PCI DSS) is an advantage. Familiarity with audit tools, GRC platforms, or compliance management software. Note: Only candidates with proven experience in audit and compliance, and a strong understanding of ISO 27001:2013/2022, will be considered. Basic cloud and backup knowledge is a must. Show more Show less

Posted 4 days ago

Apply

8.0 years

0 Lacs

Gurgaon, Haryana, India

On-site

Linkedin logo

Job Title: Business Analyst ? Cybersecurity Location : Noida/Gurgaon/Hyderabad/Bangalore/Pune Role Overview: We are seeking an experienced and detail-oriented Business Analyst with a strong focus on cybersecurity. The ideal candidate will play a pivotal role in bridging the gap between business needs and technical solutions, ensuring that cybersecurity considerations are integrated into all phases of project planning and execution. Key Responsibilities: Collaborate with stakeholders to gather, analyze, and document business and functional requirements, with an emphasis on cybersecurity impacts. Translate business objectives into clear and concise technical specifications. Support end-to-end project lifecycle activities, including planning, design, testing, and implementation. Identify process improvements and recommend solutions that enhance cybersecurity posture. Work closely with cybersecurity, IT, and business teams to ensure alignment on goals and deliverables. Required Skills & Experience: 5?8 years of experience as a Business Analyst, preferably in IT or cybersecurity-related domains. Strong analytical thinking, problem-solving abilities, and excellent documentation skills. Solid understanding of cybersecurity principles, frameworks, and compliance standards. Experience facilitating workshops, writing user stories, and defining acceptance criteria. Qualifications: Bachelor?s degree in Business, Information Technology, Computer Science, or a related field. Preferred Qualifications: Hands-on experience working on cybersecurity-focused initiatives or within security-sensitive environments. Familiarity with security tools, risk assessments, or regulatory requirements (e.g., NIST, ISO 27001, GDPR). Show more Show less

Posted 4 days ago

Apply

10.0 - 15.0 years

0 Lacs

Noida, Uttar Pradesh, India

On-site

Linkedin logo

Job Description As a Cyber Security Architect, you will contribute to telecom network security. You will be responsible for providing expert security guidance, designing secure network solutions, and implementing best practices for our complex and dynamic telecom network infrastructure. How You Will Contribute And What You Will Learn You will be in part of developing and implementing secure network architectures, including firewall configurations, intrusion detection systems, VPNs, and network segmentation, tailored to the specific needs of telecom clients. You need to identify vulnerabilities and security weaknesses in existing telecom networks and recommend remediation strategies. You need to advise clients on best practices for securing their telecom networks, including threat modeling, vulnerability analysis, and risk mitigation strategies. You need to work with clients to establish comprehensive security policies and procedures that align with industry best practices and regulatory requirements. You will focus on threats and vulnerabilities specific to the telecom industry and recommend appropriate countermeasures for the network. You need to provide technical expertise and guidance related to security incidents affecting the telecom network. You will be designing training programs for the specific needs of personnel involved in managing and operating the telecom network. You will be focusing on the security strategy for the telecom network and its integration with the broader organizational security strategy. Key Skills And Experience You Have: Bachelor's degree in Computer Science, Information Security, or Electrical Engineering, with a minimum of 10-15 years of experience in security risk assessment, vulnerability management, or a related field within the telecom industry. Experience in security principles, methodologies, and best practices specifically relevant to telecom networks. Experience with security frameworks such as ISO 27001, NIST Cybersecurity Framework, or similar, with a focus on their application to telecom networks. Experience on conducting threat modeling, vulnerability analysis, and impact assessments for telecom network infrastructure. Experience with network security technologies such as firewalls, intrusion detection systems, VPNs, and network segmentation. Familiarity with telecom protocols and standards (e.g., SS7, Diameter, SIP) and their security implications. It would be nice if you also had: Certifications - ISO 270001 LA/LI, CISA , ITIL V3/4. Exposure to complex problem-solving and managing multiple projects simultaneously. About Us Come create the technology that helps the world act together Nokia is committed to innovation and technology leadership across mobile, fixed and cloud networks. Your career here will have a positive impact on people’s lives and will help us build the capabilities needed for a more productive, sustainable, and inclusive world. We challenge ourselves to create an inclusive way of working where we are open to new ideas, empowered to take risks and fearless to bring our authentic selves to work What we offer Nokia offers continuous learning opportunities, well-being programs to support you mentally and physically, opportunities to join and get supported by employee resource groups, mentoring programs and highly diverse teams with an inclusive culture where people thrive and are empowered. Nokia is committed to inclusion and is an equal opportunity employer Nokia has received the following recognitions for its commitment to inclusion & equality: One of the World’s Most Ethical Companies by Ethisphere Gender-Equality Index by Bloomberg Workplace Pride Global Benchmark At Nokia, we act inclusively and respect the uniqueness of people. Nokia’s employment decisions are made regardless of race, color, national or ethnic origin, religion, gender, sexual orientation, gender identity or expression, age, marital status, disability, protected veteran status or other characteristics protected by law. We are committed to a culture of inclusion built upon our core value of respect. Join us and be part of a company where you will feel included and empowered to succeed. About The Team In Mobile Networks , our ambition is to become the trusted partner of choice for Communications Service Providers (CSPs), as well as for non-CSP entities in sectors like utilities, transportation, public services, and defense. We strive to deliver unbeatable customer experiences in wireless connectivity. Show more Show less

Posted 4 days ago

Apply

8.0 years

0 Lacs

Bangalore Urban, Karnataka, India

On-site

Linkedin logo

Job Title: SOAR Administration Manager Location: Bangalore Experience: 8-15 Years Required Skills Technical Proficiency: Deep understanding of security technologies, including SOAR (Security Orchestration and Response solution) platforms, threat intelligence platforms , SIEM solutions and other cyber monitoring tools and technologies . Design, implement, optimize security workflows, Create automated playbooks and ensure proper orchestration between multiple security tools and systems Automation and Scripting: Proficiency in scripting languages such as Python, PowerShell, or Bash to automate repetitive tasks and integrate different security tools. Incident Response: Strong knowledge of incident response processes and frameworks, including the ability to coordinate response efforts during security incidents. Analytical Skills: Ability to analyze complex security data, identify patterns, and make informed decisions to enhance security operation. Project Management: Experience in managing projects, including planning, execution, and monitoring of SOAR implementations and improvements. Key Responsibilites Classification: Internal Use SOAR Manager is a SME role who has overall responsibility for SOAR processes withing the Security Incident Response domain and supporting the Head of Cyber Defense Center to achieve organization’s Information Security strategy and goals. Confirm adequacy of the process controls against Security Incident response policies, standards and applicable regulatory requirements. 9 Knowledge, Skills, And Experience Essential knowledge Have over 8+ years of rich experience in information security domain and at least 4-6 years of dedicated experience in Security Incident Response using SOAR solutions. Hands on experience in implementing and operationalizing SOAR tools preferably on Sentinel or Splunk SOAR, Palo Alto Cortex XSOAR, or IBM Resilient Familiarity with advanced SOC monitoring technologies, risk, threat and security measures. Knowledge across the SOC domains including governance, control frameworks, policies, compliance management, risk management and incident response etc. Preferably worked in BFSI domain with proven experience in SOC function. Knowledge of key security standards and regulations such as NIST 800-61, CERT/CC, PCI, ISO 27035 etc. Skills and Application Show more Show less

Posted 4 days ago

Apply

8.0 years

0 Lacs

Noida, Uttar Pradesh, India

On-site

Linkedin logo

Job Title: Business Analyst ? Cybersecurity Location : Noida/Gurgaon/Hyderabad/Bangalore/Pune Role Overview: We are seeking an experienced and detail-oriented Business Analyst with a strong focus on cybersecurity. The ideal candidate will play a pivotal role in bridging the gap between business needs and technical solutions, ensuring that cybersecurity considerations are integrated into all phases of project planning and execution. Key Responsibilities: Collaborate with stakeholders to gather, analyze, and document business and functional requirements, with an emphasis on cybersecurity impacts. Translate business objectives into clear and concise technical specifications. Support end-to-end project lifecycle activities, including planning, design, testing, and implementation. Identify process improvements and recommend solutions that enhance cybersecurity posture. Work closely with cybersecurity, IT, and business teams to ensure alignment on goals and deliverables. Required Skills & Experience: 5?8 years of experience as a Business Analyst, preferably in IT or cybersecurity-related domains. Strong analytical thinking, problem-solving abilities, and excellent documentation skills. Solid understanding of cybersecurity principles, frameworks, and compliance standards. Experience facilitating workshops, writing user stories, and defining acceptance criteria. Qualifications: Bachelor?s degree in Business, Information Technology, Computer Science, or a related field. Preferred Qualifications: Hands-on experience working on cybersecurity-focused initiatives or within security-sensitive environments. Familiarity with security tools, risk assessments, or regulatory requirements (e.g., NIST, ISO 27001, GDPR). Show more Show less

Posted 4 days ago

Apply

8.0 years

0 Lacs

Pune, Maharashtra, India

On-site

Linkedin logo

Job Title: Business Analyst ? Cybersecurity Location : Noida/Gurgaon/Hyderabad/Bangalore/Pune Role Overview: We are seeking an experienced and detail-oriented Business Analyst with a strong focus on cybersecurity. The ideal candidate will play a pivotal role in bridging the gap between business needs and technical solutions, ensuring that cybersecurity considerations are integrated into all phases of project planning and execution. Key Responsibilities: Collaborate with stakeholders to gather, analyze, and document business and functional requirements, with an emphasis on cybersecurity impacts. Translate business objectives into clear and concise technical specifications. Support end-to-end project lifecycle activities, including planning, design, testing, and implementation. Identify process improvements and recommend solutions that enhance cybersecurity posture. Work closely with cybersecurity, IT, and business teams to ensure alignment on goals and deliverables. Required Skills & Experience: 5?8 years of experience as a Business Analyst, preferably in IT or cybersecurity-related domains. Strong analytical thinking, problem-solving abilities, and excellent documentation skills. Solid understanding of cybersecurity principles, frameworks, and compliance standards. Experience facilitating workshops, writing user stories, and defining acceptance criteria. Qualifications: Bachelor?s degree in Business, Information Technology, Computer Science, or a related field. Preferred Qualifications: Hands-on experience working on cybersecurity-focused initiatives or within security-sensitive environments. Familiarity with security tools, risk assessments, or regulatory requirements (e.g., NIST, ISO 27001, GDPR). Show more Show less

Posted 4 days ago

Apply

4.0 years

0 Lacs

Delhi

On-site

Indeed logo

Job requisition ID :: 82321 Date: Jun 13, 2025 Location: Delhi Designation: Deputy Manager Entity: Your potential, unleashed. India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realise your potential amongst cutting edge leaders, and organisations shaping the future of the region, and indeed, the world beyond. At Deloitte, your whole self to work, every day. Combine that with our drive to propel with purpose and you have the perfect playground to collaborate, innovate, grow, and make an impact that matters. The team Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks Your work profile As Deputy Manager in our Cyber Team you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations: - We are seeking a skilled QRadar Engineer to manage, maintain, and enhance our QRadar SIEM platform, ensuring effective monitoring, detection, and response to security incidents. The ideal candidate will have strong experience in QRadar administration, threat detection, and SOC operations to provide continuous security improvements and support to the SOC team. Key Responsibilities: QRadar Administration: Install, configure, and manage QRadar components, including log sources, custom log parsers, and correlation rules. Log Source Management: Integrate and manage various log sources from network devices, servers, applications, and security tools to ensure proper log ingestion and parsing. Rule Development: Develop and fine-tune correlation rules, offenses, and custom use cases to detect malicious activity. Threat Detection: Monitor, analyze, and respond to security events and incidents detected by QRadar. Performance Tuning: Optimize QRadar’s performance, including storage management, event processing, and tuning for high EPS environments. Integration and Customization: Work with APIs and custom integrations to extend the capabilities of QRadar with other security tools (firewalls, EDR, DLP, etc.). Incident Response Support: Collaborate with the SOC team in investigating security incidents, using QRadar for root cause analysis and mitigation strategies. Dashboard & Report Creation: Design and manage QRadar dashboards and reports for management and security operations teams. Compliance and Auditing: Ensure QRadar operations align with regulatory standards, such as GDPR, HIPAA, or PCI-DSS, as required. Troubleshooting: Resolve QRadar-related issues, including log ingestion problems, performance issues, and system errors. Upgrades and Patching: Plan and execute system upgrades, patching, and version updates to maintain system integrity and security. Desired qualifications Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent experience. 4+ years of experience with QRadar SIEM, including installation, configuration, and administration. Strong knowledge of SIEM operations, event correlation, and log management. Experience in SOC operations, threat detection, and incident response. Proficiency in scripting and automation (Python, Bash, or PowerShell) is a plus. Familiarity with network security tools, firewalls, IDS/IPS, EDR, and other security technologies. In-depth knowledge of security frameworks (e.g., MITRE ATT&CK, NIST, ISO 27001). Preferred Certifications IBM QRadar SIEM Certification. CISSP, CEH, CISM, or other relevant security certifications. Location and way of working Base location: Mumbai/Gurgaon Professional is required to work from office Your role as a Deputy Manager We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society. In addition to living our purpose, Senior Executive across our organization must strive to be: Inspiring - Leading with integrity to build inclusion and motivation Committed to creating purpose - Creating a sense of vision and purpose Agile - Achieving high-quality results through collaboration and Team unity Skilled at building diverse capability - Developing diverse capabilities for the future Persuasive / Influencing - Persuading and influencing stakeholders Collaborating - Partnering to build new solutions Delivering value - Showing commercial acumen Committed to expanding business - Leveraging new business opportunities Analytical Acumen - Leveraging data to recommend impactful approach and solutions through the power of analysis and visualization Effective communication – Must be well abled to have well-structured and well-articulated conversations to achieve win-win possibilities Engagement Management / Delivery Excellence - Effectively managing engagement(s) to ensure timely and proactive execution as well as course correction for the success of engagement(s) Managing change - Responding to changing environment with resilience Managing Quality & Risk - Delivering high quality results and mitigating risks with utmost integrity and precision Strategic Thinking & Problem Solving - Applying strategic mindset to solve business issues and complex problems Tech Savvy - Leveraging ethical technology practices to deliver high impact for clients and for Deloitte Empathetic leadership and inclusivity - creating a safe and thriving environment where everyone's valued for who they are, use empathy to understand others to adapt our behaviours and attitudes to become more inclusive. How you’ll grow Connect for impact Our exceptional team of professionals across the globe are solving some of the world’s most complex business problems, as well as directly supporting our communities, the planet, and each other. Know more in our Global Impact Report and our India Impact Report. Empower to lead You can be a leader irrespective of your career level. Our colleagues are characterised by their ability to inspire, support, and provide opportunities for people to deliver their best and grow both as professionals and human beings. Know more about Deloitte and our One Young World partnership. Inclusion for all At Deloitte, people are valued and respected for who they are and are trusted to add value to their clients, teams and communities in a way that reflects their own unique capabilities. Know more about everyday steps that you can take to be more inclusive. At Deloitte, we believe in the unique skills, attitude and potential each and every one of us brings to the table to make an impact that matters. Drive your career At Deloitte, you are encouraged to take ownership of your career. We recognise there is no one size fits all career path, and global, cross-business mobility and up / re-skilling are all within the range of possibilities to shape a unique and fulfilling career. Know more about Life at Deloitte. Everyone’s welcome… entrust your happiness to us Our workspaces and initiatives are geared towards your 360-degree happiness. This includes specific needs you may have in terms of accessibility, flexibility, safety and security, and caregiving. Here’s a glimpse of things that are in store for you. Interview tips We want job seekers exploring opportunities at Deloitte to feel prepared, confident and comfortable. To help you with your interview, we suggest that you do your research, know some background about the organisation and the business area you’re applying to. Check out recruiting tips from Deloitte professionals. *Caution against fraudulent job offers*: We would like to advise career aspirants to exercise caution against fraudulent job offers or unscrupulous practices. At Deloitte, ethics and integrity are fundamental and not negotiable. We do not charge any fee or seek any deposits, advance, or money from any career aspirant in relation to our recruitment process. We have not authorized any party or person to collect any money from career aspirants in any form whatsoever for promises of getting jobs in Deloitte or for being considered against roles in Deloitte. We follow a professional recruitment process, provide a fair opportunity to eligible applicants and consider candidates only on merit. No one other than an authorized official of Deloitte is permitted to offer or confirm any job offer from Deloitte. We advise career aspirants to exercise caution. In this regard, you may refer to a more detailed advisory given on our website at: https://www2.deloitte.com/in/en/careers/advisory-for-career-aspirants.html?icid=wn_

Posted 4 days ago

Apply

4.0 years

0 Lacs

Delhi

On-site

Indeed logo

Job requisition ID :: 82322 Date: Jun 13, 2025 Location: Delhi Designation: Assistant Manager Entity: Your potential, unleashed. India’s impact on the global economy has increased at an exponential rate and Deloitte presents an opportunity to unleash and realise your potential amongst cutting edge leaders, and organisations shaping the future of the region, and indeed, the world beyond. At Deloitte, your whole self to work, every day. Combine that with our drive to propel with purpose and you have the perfect playground to collaborate, innovate, grow, and make an impact that matters. The team Deloitte helps organizations prevent cyberattacks and protect valuable assets. We believe in being secure, vigilant, and resilient—not only by looking at how to prevent and respond to attacks, but at how to manage cyber risk in a way that allows you to unleash new opportunities. Embed cyber risk at the start of strategy development for more effective management of information and technology risks Your work profile As Assistant Manager in our Cyber Team you’ll build and nurture positive working relationships with teams and clients with the intention to exceed client expectations: - We are seeking a skilled SIEM QRadar Engineer to manage, maintain, and enhance our QRadar SIEM platform, ensuring effective monitoring, detection, and response to security incidents. The ideal candidate will have strong experience in QRadar administration, threat detection, and SOC operations to provide continuous security improvements and support to the SOC team. Key Responsibilities: QRadar Administration: Install, configure, and manage QRadar components, including log sources, custom log parsers, and correlation rules. Log Source Management: Integrate and manage various log sources from network devices, servers, applications, and security tools to ensure proper log ingestion and parsing. Rule Development: Develop and fine-tune correlation rules, offenses, and custom use cases to detect malicious activity. Threat Detection: Monitor, analyze, and respond to security events and incidents detected by QRadar. Performance Tuning: Optimize QRadar’s performance, including storage management, event processing, and tuning for high EPS environments. Integration and Customization: Work with APIs and custom integrations to extend the capabilities of QRadar with other security tools (firewalls, EDR, DLP, etc.). Incident Response Support: Collaborate with the SOC team in investigating security incidents, using QRadar for root cause analysis and mitigation strategies. Dashboard & Report Creation: Design and manage QRadar dashboards and reports for management and security operations teams. Compliance and Auditing: Ensure QRadar operations align with regulatory standards, such as GDPR, HIPAA, or PCI-DSS, as required. Troubleshooting: Resolve QRadar-related issues, including log ingestion problems, performance issues, and system errors. Upgrades and Patching: Plan and execute system upgrades, patching, and version updates to maintain system integrity and security. Desired qualifications Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent experience. 4+ years of experience with QRadar SIEM, including installation, configuration, and administration. Strong knowledge of SIEM operations, event correlation, and log management. Experience in SOC operations, threat detection, and incident response. Proficiency in scripting and automation (Python, Bash, or PowerShell) is a plus. Familiarity with network security tools, firewalls, IDS/IPS, EDR, and other security technologies. In-depth knowledge of security frameworks (e.g., MITRE ATT&CK, NIST, ISO 27001). Preferred Certifications IBM QRadar SIEM Certification. CISSP, CEH, CISM, or other relevant security certifications. Location and way of working Base location: Gurgaon Professional is required to work from office Your role as a Assistant Manager We expect our people to embrace and live our purpose by challenging themselves to identify issues that are most important for our clients, our people, and for society. In addition to living our purpose, Senior Executive across our organization must strive to be: Inspiring - Leading with integrity to build inclusion and motivation Committed to creating purpose - Creating a sense of vision and purpose Agile - Achieving high-quality results through collaboration and Team unity Skilled at building diverse capability - Developing diverse capabilities for the future Persuasive / Influencing - Persuading and influencing stakeholders Collaborating - Partnering to build new solutions Delivering value - Showing commercial acumen Committed to expanding business - Leveraging new business opportunities Analytical Acumen - Leveraging data to recommend impactful approach and solutions through the power of analysis and visualization Effective communication – Must be well abled to have well-structured and well-articulated conversations to achieve win-win possibilities Engagement Management / Delivery Excellence - Effectively managing engagement(s) to ensure timely and proactive execution as well as course correction for the success of engagement(s) Managing change - Responding to changing environment with resilience Managing Quality & Risk - Delivering high quality results and mitigating risks with utmost integrity and precision Strategic Thinking & Problem Solving - Applying strategic mindset to solve business issues and complex problems Tech Savvy - Leveraging ethical technology practices to deliver high impact for clients and for Deloitte Empathetic leadership and inclusivity - creating a safe and thriving environment where everyone's valued for who they are, use empathy to understand others to adapt our behaviours and attitudes to become more inclusive. How you’ll grow Connect for impact Our exceptional team of professionals across the globe are solving some of the world’s most complex business problems, as well as directly supporting our communities, the planet, and each other. Know more in our Global Impact Report and our India Impact Report. Empower to lead You can be a leader irrespective of your career level. Our colleagues are characterised by their ability to inspire, support, and provide opportunities for people to deliver their best and grow both as professionals and human beings. Know more about Deloitte and our One Young World partnership. Inclusion for all At Deloitte, people are valued and respected for who they are and are trusted to add value to their clients, teams and communities in a way that reflects their own unique capabilities. Know more about everyday steps that you can take to be more inclusive. At Deloitte, we believe in the unique skills, attitude and potential each and every one of us brings to the table to make an impact that matters. Drive your career At Deloitte, you are encouraged to take ownership of your career. We recognise there is no one size fits all career path, and global, cross-business mobility and up / re-skilling are all within the range of possibilities to shape a unique and fulfilling career. Know more about Life at Deloitte. Everyone’s welcome… entrust your happiness to us Our workspaces and initiatives are geared towards your 360-degree happiness. This includes specific needs you may have in terms of accessibility, flexibility, safety and security, and caregiving. Here’s a glimpse of things that are in store for you. Interview tips We want job seekers exploring opportunities at Deloitte to feel prepared, confident and comfortable. To help you with your interview, we suggest that you do your research, know some background about the organisation and the business area you’re applying to. Check out recruiting tips from Deloitte professionals. *Caution against fraudulent job offers*: We would like to advise career aspirants to exercise caution against fraudulent job offers or unscrupulous practices. At Deloitte, ethics and integrity are fundamental and not negotiable. We do not charge any fee or seek any deposits, advance, or money from any career aspirant in relation to our recruitment process. We have not authorized any party or person to collect any money from career aspirants in any form whatsoever for promises of getting jobs in Deloitte or for being considered against roles in Deloitte. We follow a professional recruitment process, provide a fair opportunity to eligible applicants and consider candidates only on merit. No one other than an authorized official of Deloitte is permitted to offer or confirm any job offer from Deloitte. We advise career aspirants to exercise caution. In this regard, you may refer to a more detailed advisory given on our website at: https://www2.deloitte.com/in/en/careers/advisory-for-career-aspirants.html?icid=wn_

Posted 4 days ago

Apply

5.0 years

0 Lacs

Mumbai, Maharashtra

Remote

Indeed logo

Security Solution Engineer Mumbai, Maharashtra, India Date posted Jun 13, 2025 Job number 1830846 Work site Up to 50% work from home Travel 25-50 % Role type Individual Contributor Profession Technology Sales Discipline Technology Specialists Employment type Full-Time Overview Are you insatiably curious and do you lean into uncertainty, take risks, and learn quickly from Are you passionate about cybersecurity? Do you enjoy working on a high-performing, fast-paced sales team? Are you insatiably curious and do you lean into uncertainty, take risks, and learn quickly from your mistakes? If so, we are looking for you! The Microsoft Security organization’s mission of making the world a safer place has never been more important. As threats become more frequent and sophisticated, we should work to keep our customers safe through our Security Solutions. The Solution Specialist Unit team within the Microsoft Security organization is at the forefront of this effort, engaging directly with customers to contribute to their success. With thousands of global security experts worldwide, $1 billion+ invested annually in security research and development, and the cutting edge AI- based Security innovations, Microsoft is ideally placed to think outside of the box and protecting customers, and partners around the world. We are looking for passionate, experienced, and credible Security Solution Engineer with a drive to help solve complex security challenges for our customers, enabling them to help modernize their security architecture and posture. We are keen to hear your thoughts on how we can further achieve our purpose. Join our team and discover unique opportunities to grow, develop and learn. As a Security Solution Engineer , you will be a senior technical sales leader and trusted customer advisor, working with cutting-edge security technologies such as Microsoft M365 Defender, Defender for Cloud and Sentinel. You will lead a virtual team of other internal, partner and consulting resources to help map Microsoft solutions to customer security challenges and priorities, demonstrate and prove our solutions, and win the technical decision enabling the team to achieve and even exceed quarterly and annual revenue targets. You will spend 75% of your work hours a week on qualified customer work – planning and orchestration, preparation, meetings (technical presentations, demos, POCs, compete positioning, workshops, etc.), while the other 25% of your time will be focused on further growing your technical, industry and competition acumen. Microsoft’s mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond. Qualifications 5+ years of Security Technology pre-sales or Security Technology consulting experience. OR Bachelor's Degree in Computer Science, Information Technology, or related field AND 4+ years of technical pre-sales or technical consulting experience. OR Master's Degree in Computer Science, Information Technology, or related field AND 3+ years of technical pre-sales or technical consulting experience OR equivalent experience. Experience with Microsoft security solutions (M365 Defender, Defender for Cloud, Sentinel) or, one or more related technologies such as Prisma Cloud, Crowdstrike, Proofpoint, Splunk, etc. Experience presenting the value of technology solutions and architectures through customer presentations, design sessions, POCs accelerating technical wins. Preferred Qualifications 8+ years technical pre-sales, technical consulting, or technology delivery, or related experience OR equivalent experience. 6+ years experience with cloud and hybrid, or on premises infrastructures, architecture designs, migrations, industry standards, and/or technology management. Certification in relevant technologies or disciplines (e.g., Office 365, Power BI, Azure Architect and Development exams, Cloud Platform Technologies, Information Security, Architecture). Certification in Microsoft 365 Security Administration or Azure Security One or more of Industry certifications such as CISSP, CCSP, iAPP, etc. Hands on technical knowledge of relevant products and solutions, but not limited to: Security Information and Event Management (SIEM) systems Next Gen Web Application Firewalls and Secure Web Gateways. Threat detection technologies Log analysis and Incident Response Cloud security technologies, architectures and concepts such as Zero Trust, cloud security posture management, cloud workload protection, Cloud code security and Cloud infrastructure entitlement management. Cloud Computing: Infrastructure as a service (IaaS), Platform as a Services (PaaS), and Software as a service. Demonstrated knowledge and understanding of one or more cloud security standards and frameworks such as CIS, NIST, CSA, etc. Technical Sales Acumen: Experience presenting the value of technology solutions and architectures through customer presentations, design sessions, POCs accelerating technical wins. Expertise in extended detection and response (XDR), zero trust and cloud security solutions & architectures Professional interpersonal skills, with the ability to present technical information clearly and concisely. Develop and maintain technical expertise: A technical specialist should stay up to date with the latest developments and advancements in security space including new tech, competitors, and internal product and services offerings. Growth Mindset. Experience and passion for learning (technical and professional skills); implementing practices from others; trying, failing, and learning from both successes and failures; sharing practices and knowledge for others’ benefit. Problem Solving: Excellent analytical and problem-solving skills, with the ability to think creatively and develop innovative solutions to technical challenges. Multi-Tasking: Ability to work independently and manage multiple priorities simultaneously. Responsibilities You will be the primary technical point of contact for potential customers during the sales process, owning and driving technical win for security opportunities. Deep technical understanding of cloud security architectures, solutions/technologies including Microsoft M365 Defender, Defender for cloud and Sentinel. Coordinate weekly with sellers and manager to understand opportunities, compete scenarios and engagements to focus on, engaging and driving to own and win the technical decisions Remediate blockers; leads and ensures technical wins for Microsoft Security and adjacent technologies. Engages with and reaches out to customers proactively and independently; builds credibility with customers as a trusted advisor for Microsoft Security; and searches for and uses Microsoft Security customer references; and drives customer intent to buy and facilitates handoff to customer success for post sales deployment. Develop strategies and recommendations to improve the client's security posture, shapes technical win plan and tailors Microsoft messaging to audience for security opportunities. Enhances team capabilities for extended detection and response (XDR), zero trust and cloud security and develops differentiated compete strategies for Microsoft Security for assigned customers. Lead technical presentations, demonstrations, workshops, architecture design sessions, explain, demonstrate, and architect the solution to help solve customer security challenges and priorities. Demonstrates and oversees proof of concepts, presents and applies architecture patterns, proves capabilities and integration into customer environment, and drives cross-workload support for Microsoft solutions for security. Leverages insights and coaches' teams to align new or changing technology to customer security needs. This would mean hands on knowledge on product stack, ability to conduct PoC and pilot by themselves when needed. A technical specialist is responsible for engaging with other teams within and outside the organization throughout the sales cycle. Engaging partners in sell-with scenarios and supporting their technical capabilities is key to scaling solution delivery. You will stay sharp, share your knowledge and best practices enabling further scale and growth for the security business. You would spend 20% of your work hours maintaining deep theoretical and experiential technical knowledge of MS security solutions, competitive landscape and industry trends. As a technical specialist you would document and share best practices and learning with others enabling and contributing to the success of others on your team Share knowledge and learnings with partners to drive the sale, deployment, and adoption of Microsoft solutions. Completes required training and obtains relevant product and role certifications aligned to the role and workload/industry. Other Embody our culture and values Benefits/perks listed below may vary depending on the nature of your employment with Microsoft and the country where you work.  Industry leading healthcare  Educational resources  Discounts on products and services  Savings and investments  Maternity and paternity leave  Generous time away  Giving programs  Opportunities to network and connect Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.

Posted 4 days ago

Apply

8.0 years

0 Lacs

Chennai, Tamil Nadu, India

On-site

Linkedin logo

Job Title - Senior Security Engineer (Application & Cloud Security) Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the additional compliance framework to take care of local regulations and requirements. This results in decreased transaction costs, fx transparency and higher auth rates. They are licensed and backed by leading investors. www.tazapay.com What's exciting waiting for you? This is an amazing opportunity for you to join a fantastic crew before the rocket ship launch. It will be a story you will carry with you through your life and have the unique experience of building something ground up and have the satisfaction of seeing your product being used and paid for by thousands of customers. You will be a part of a growth story in securing critical payment infrastructure that spans both application security and cloud security across 70+ markets. We believe in a culture of openness, innovation & great memories together. About The Senior Security Engineer Role As a Senior Security Engineer, you will play a pivotal role in securing our entire technology stack - from application-level security to cloud infrastructure protection. You will lead comprehensive security initiatives across our AWS cloud environments and payment applications built with Node.js and GoLang microservices, while leveraging AWS security services and modern security tools to protect against evolving threats. This role combines deep technical expertise in both application security and cloud security with leadership responsibilities. Key Responsibilities Application Security Leadership Lead comprehensive security assessments of microservices-based applications built with GoLang, Java, or Scala Conduct advanced security reviews of Vue.js and ReactJS frontend applications and their integration with backend services Execute expert-level manual and automated web application penetration testing using industry-standard methodologies (OWASP Testing Guide, PTES) Design and implement vulnerability scoring and risk assessment frameworks using CVSS, OWASP Risk Rating, and custom business impact metrics Utilize govulncheck for Go-specific vulnerability detection and dependency analysis across microservices Deploy Semgrep/OpenGrep for advanced static code analysis and custom security policy enforcement Integrate Gitleaks for comprehensive secret detection across development workflows Lead secure development lifecycle (SDLC) integration and establish security standards for development teams Perform complex web application penetration testing including authentication bypass, authorization flaws, injection attacks, and business logic vulnerabilities AWS Cloud Security Architecture Design and implement enterprise-level security architecture for AWS cloud environments Configure and optimize AWS Shield (Standard and Advanced) for comprehensive DDoS protection Implement and manage AWS CloudFront security configurations including advanced WAF rules, SSL/TLS, and origin protection Secure complex AWS services including EC2, ECS, EKS, Lambda, RDS, S3, API Gateway, and multi-region deployments Design network security controls using VPC, Security Groups, NACLs, AWS Transit Gateway, and PrivateLink Establish and lead secure CI/CD pipeline implementations for Node.js applications and GoLang microservices Architect container security solutions for Docker and Kubernetes (EKS) environments Security Automation & Monitoring Implement comprehensive security monitoring using AWS CloudTrail, GuardDuty, and Security Hub Deploy and manage Prowler for continuous AWS security assessments and compliance validation Utilize ScoutSuite for multi-cloud security posture management and configuration auditing Configure Gitleaks for continuous secret monitoring across enterprise development workflows Implement Semgrep/OpenGrep rules for real-time security vulnerability detection and policy enforcement Lead automation initiatives using Infrastructure as Code (Terraform, CloudFormation, AWS CDK) Develop advanced security automation scripts and frameworks using Python, Bash, and AWS SDKs Create comprehensive security dashboards and executive reporting mechanisms Vulnerability Management & Risk Assessment Lead enterprise vulnerability management programs with comprehensive scoring using CVSS v3.1, OWASP Risk Rating, and custom business impact assessments Develop sophisticated risk scoring matrices incorporating technical severity, business impact, exploitability, and regulatory requirements Create detailed penetration testing reports with executive summaries, technical findings, and strategic remediation roadmaps Establish vulnerability SLA metrics and track remediation timelines based on risk scores and business priorities Conduct root cause analysis (RCA) on complex security incidents and implement preventive measures Lead threat modeling sessions and strategic risk assessments for new features and infrastructure changes Mentor junior security engineers and provide technical guidance on vulnerability remediation Compliance & Regulatory Security Ensure comprehensive compliance with financial industry regulations (PCI DSS, SOX, GDPR, PSD2) Lead compliance audits and regulatory assessments using Prowler for AWS compliance validation Implement ScoutSuite for comprehensive multi-cloud security auditing Design and maintain data protection controls for sensitive payment processing workloads Develop and maintain disaster recovery and business continuity security plans Lead security aspects of vendor risk assessments and third-party integrations Represent security requirements to business leadership and regulatory bodies Technical Leadership & Strategy Serve as technical security leader for complex cross-functional projects Influence security strategies, standards, and architectural decisions across the organization Lead security initiatives and mentor junior engineers on advanced security practices Participate in strategic security planning and technology evaluation Drive security culture transformation and champion security best practices Represent security needs to executive leadership and board-level communications Experience Required Qualifications 8+ years of experience in information security with demonstrated expertise in both application security and cloud security Extensive experience securing microservices architectures, particularly those built with GoLang, Java, or Scala Advanced experience with AWS cloud security including Shield, CloudFront, and comprehensive security service management Expert-level web application penetration testing experience including complex business logic vulnerabilities and multi-tier architectures Proven leadership in vulnerability scoring and risk assessment using industry-standard frameworks Hands-on expertise with security automation tools: govulncheck, Gitleaks, Semgrep/OpenGrep, Prowler, ScoutSuite Strong experience securing Node.js applications and modern JavaScript frameworks (Vue.js, ReactJS) Experience leading security teams and influencing organizational security strategy Technical Skills Expert-level proficiency in AWS security services including Shield, CloudFront, GuardDuty, Security Hub, WAF, and comprehensive service portfolio Advanced application security expertise across GoLang, Java, Scala, Node.js, Vue.js, and ReactJS technologies Mastery of security automation tools: govulncheck (Go vulnerability scanning), Gitleaks (secret detection), Semgrep/OpenGrep (static analysis), Prowler (AWS security assessment), ScoutSuite (multi-cloud auditing) Expert-level web application penetration testing skills using advanced tools and custom exploitation frameworks Comprehensive knowledge of vulnerability scoring frameworks including CVSS v3.1, OWASP Risk Rating, and FAIR methodology Advanced Infrastructure as Code proficiency (Terraform, CloudFormation, AWS CDK) Expert container and orchestration security (Docker, Kubernetes/EKS, service mesh security) Advanced scripting and automation capabilities (Python, Bash, PowerShell, Go) Enterprise network security and cloud networking expertise Security Expertise Deep understanding of application security principles and advanced penetration testing methodologies Expert knowledge of cloud security frameworks (NIST, CSA, AWS Well-Architected Security Pillar) Advanced understanding of financial services security and payment processing compliance requirements Expertise in security architecture design for complex distributed systems Advanced threat modeling and risk assessment capabilities Comprehensive knowledge of cryptography, PKI, and secure communication protocols Expert-level incident response and forensic analysis skills Advanced understanding of regulatory compliance frameworks and audit requirements Nice to Have Certifications AWS Security Specialty certification (required) Advanced penetration testing certifications (OSCP, GWEB, eWPT, eWPTX) Security leadership certifications (CISSP, CISM, CISSP) Cloud architecture certifications (AWS Solutions Architect Professional, DevOps Engineer Professional) Additional cloud security certifications (Azure Security, GCP Security) Additional Skills Experience with multi-cloud security architectures and hybrid environments Advanced knowledge of serverless security (AWS Lambda, API Gateway, serverless frameworks) Expertise in security orchestration and automated response (SOAR) platforms Experience with machine learning/AI security applications and threat detection Advanced understanding of payment processing security and financial services infrastructure Experience with regulatory examination processes and security audit leadership Knowledge of emerging security technologies and threat landscape evolution Experience with security product evaluation and vendor management Advanced presentation and executive communication skills Key Abilities And Traits Technical Excellence: Demonstrated ability to architect and implement comprehensive security solutions across complex application and cloud environments processing sensitive financial data. Leadership: Proven capability to lead security initiatives across multiple teams, influence strategic decisions, and mentor engineering talent while representing security needs to executive leadership. Strategic Thinking: Ability to balance immediate security needs with long-term strategic objectives, translating business requirements into technical security solutions. Problem-Solving: Expert-level analytical and problem-solving skills with the ability to address complex security challenges spanning application code to cloud infrastructure. Communication: Exceptional verbal and written communication skills, capable of explaining complex security concepts to technical teams, business stakeholders, and executive leadership. Continuous Innovation: Commitment to staying current with emerging security threats, technologies, and industry best practices while driving security innovation within the organization. Project Management: Advanced ability to manage multiple complex security initiatives simultaneously while ensuring compliance with regulatory requirements and business objectives. Mentorship: Strong commitment to developing junior security talent and fostering a security-conscious culture across engineering teams. Join our team and let's groove together to the rhythm of innovation and opportunity! Your Buddy, Tazapay Show more Show less

Posted 4 days ago

Apply

4.0 years

0 Lacs

Chennai, Tamil Nadu, India

On-site

Linkedin logo

Job Title - Cloud Security Engineer Location: Chennai About Tazapay Tazapay is a cross border payment service provider. They offer local collections via local payment methods, virtual accounts and cards in over 70 markets. The merchant does not need to create local entities anywhere and Tazapay offers the additional compliance framework to take care of local regulations and requirements. This results in decreased transaction costs, fx transparency and higher auth rates. They are licensed and backed by leading investors. www.tazapay.com What's exciting waiting for you? This is an amazing opportunity for you to join a fantastic crew before the rocket ship launch. It will be a story you will carry with you through your life and have the unique experience of building something ground up and have the satisfaction of seeing your product being used and paid for by thousands of customers. You will be a part of a growth story in securing critical cloud infrastructure that powers cross-border payments across 70+ markets. We believe in a culture of openness, innovation & great memories together. About The Cloud Security Engineer Role As a Cloud Security Engineer, you will be responsible for designing, implementing, and maintaining security controls for our AWS cloud infrastructure. You will ensure the security of our payment processing platform built on Node.js applications and GoLang microservices, while leveraging AWS security services including Shield and CloudFront to protect against threats and ensure optimal performance across global markets. Key Responsibilities AWS Cloud Security Architecture Design and implement comprehensive security architecture for AWS cloud environments Configure and manage AWS Shield for DDoS protection across payment processing infrastructure Implement and optimize AWS CloudFront security configurations including WAF rules, SSL/TLS, and origin protection Secure AWS services including EC2, ECS, EKS, Lambda, RDS, S3, and API Gateway Design and implement network security controls using VPC, Security Groups, NACLs, and AWS Transit Gateway Establish secure CI/CD pipelines for Node.js applications and GoLang microservices Application & Infrastructure Security Secure Node.js applications running on AWS infrastructure including container and serverless environments Implement security controls for GoLang microservices deployed across multiple AWS regions Configure and manage AWS WAF rules for web application protection Implement container security for Docker containers running Node.js and GoLang applications Secure Kubernetes clusters (EKS) hosting microservices architecture Manage secrets and configuration security using AWS Secrets Manager and Parameter Store Monitoring & Incident Response Implement comprehensive security monitoring using AWS CloudTrail, GuardDuty, and Security Hub Deploy and manage Prowler for continuous AWS security monitoring and compliance validation Utilize ScoutSuite for regular multi-cloud security posture assessments Configure Gitleaks monitoring for continuous secret detection across development workflows Implement OpenGrep rules for real-time security vulnerability detection in application code Configure CloudWatch alarms and automated incident response workflows Develop and maintain security dashboards and reporting mechanisms Respond to security incidents and conduct forensic analysis in cloud environments Implement automated threat detection and response capabilities Monitor and analyze CloudFront access logs and security events Compliance & Risk Management Ensure AWS infrastructure compliance with financial industry regulations (PCI DSS, SOX, GDPR) Conduct regular security assessments using Prowler for AWS compliance validation and ScoutSuite for comprehensive security audits Implement continuous compliance monitoring through automated tools and custom security frameworks Implement and maintain data protection controls for payment processing workloads Perform risk assessments for cloud services and architectures Develop and maintain disaster recovery and business continuity plans Support compliance audits and regulatory assessments Automation & DevSecOps Implement Infrastructure as Code (IaC) security using Terraform, CloudFormation, and AWS CDK Integrate Gitleaks for automated secret scanning in CI/CD pipelines and repositories Deploy OpenGrep (Semgrep) for static analysis and security vulnerability detection in Node.js and GoLang codebases Utilize Prowler for comprehensive AWS security assessments and compliance checks Implement ScoutSuite for multi-cloud security auditing and configuration reviews Develop security automation scripts and tools using Python, Bash, and AWS SDKs Integrate security scanning and compliance checks into CI/CD pipelines Automate security policy enforcement across AWS accounts and regions Implement automated remediation for common security misconfigurations Experience Required Qualifications 4+ years of experience in cloud security, with strong focus on AWS cloud environments Hands-on experience with AWS Shield (Standard and Advanced) for DDoS protection Extensive experience securing AWS CloudFront distributions including WAF integration and SSL/TLS configuration Strong experience securing Node.js applications in cloud environments Proven experience with GoLang microservices security in containerized and serverless architectures Hands-on experience with security automation tools including Gitleaks, OpenGrep, Prowler, and ScoutSuite Experience with AWS security services (GuardDuty, Security Hub, Config, CloudTrail) Knowledge of financial services security requirements and payment processing compliance Technical Skills Advanced proficiency in AWS security services and best practices Deep understanding of AWS Shield and DDoS mitigation strategies Expert-level knowledge of AWS CloudFront security configurations and optimization Strong security knowledge for Node.js applications including dependency management and runtime security Comprehensive understanding of GoLang microservices security patterns and secure coding practices Proficiency with security automation tools: Gitleaks (secret scanning), OpenGrep/Semgrep (static analysis), Prowler (AWS security assessment), ScoutSuite (multi-cloud auditing) Proficiency in Infrastructure as Code (Terraform, CloudFormation, AWS CDK) Experience with container security (Docker, Kubernetes/EKS) Knowledge of network security protocols and AWS networking services Scripting and automation skills (Python, Bash, PowerShell) Security Expertise Deep understanding of cloud security frameworks (NIST, CSA, AWS Well-Architected Security Pillar) Knowledge of web application security and API security best practices Experience with vulnerability management and security testing tools Understanding of cryptography, PKI, and secure communication protocols Knowledge of identity and access management (IAM) and zero-trust architecture Experience with security monitoring, SIEM, and incident response Nice to Have Certifications AWS Security Specialty certification AWS Solutions Architect or DevOps Engineer certifications Additional security certifications (CISSP, CCSP, CEH, CISSP) Cloud security certifications from other providers (Azure, GCP) Additional Skills Experience with multi-cloud security architectures Knowledge of serverless security (AWS Lambda, API Gateway) Experience with compliance frameworks (SOC 2, PCI DSS, ISO 27001) Familiarity with threat modeling and risk assessment methodologies Experience with security orchestration and automated response (SOAR) Knowledge of machine learning for security analytics Experience with payment processing and financial services infrastructure Understanding of microservices mesh security (Istio, Consul Connect) Key Abilities And Traits Cloud Security Expertise: Demonstrated ability to design and implement comprehensive security controls for complex AWS environments processing sensitive financial data. Technical Leadership: Capable of leading cloud security initiatives, influencing architecture decisions, and mentoring team members on cloud security best practices. Problem-Solving: Strong analytical skills with the ability to troubleshoot complex cloud security issues and implement innovative solutions. Automation Mindset: Commitment to automating security processes and implementing security-as-code practices across the infrastructure lifecycle. Communication: Excellent verbal and written communication skills, capable of explaining complex cloud security concepts to both technical and business stakeholders. Continuous Learning: Commitment to staying current with evolving AWS services, cloud security threats, and industry best practices. Detail-Oriented: Meticulous attention to detail when implementing security controls and reviewing cloud configurations. Project Management: Ability to manage multiple cloud security projects simultaneously while ensuring compliance with regulatory requirements. Join our team and let's groove together to the rhythm of innovation and opportunity! Your Buddy, Tazapay Show more Show less

Posted 4 days ago

Apply

7.0 - 9.0 years

0 Lacs

Delhi, India

On-site

Linkedin logo

SIEM Implementation Lead Experience: 7-9 years Location: Pune Employment Type: Full-time Job Overview We are looking for an experienced SIEM Implementation Lead to manage and drive end-to-end SIEM deployments across enterprise environments. The ideal candidate will have deep technical expertise in security monitoring, incident detection, and security architecture using SIEM platforms. Key Responsibilities (KRAs) Lead the design, implementation, and configuration of SIEM platforms (e.g., Splunk, QRadar, ArcSight, LogRhythm) Integrate security data sources and ensure effective log management across all layers Define and tune use cases, correlation rules, and alerting mechanisms Work with SOC and IT teams to refine alert triaging and incident escalation workflows Perform SIEM health checks, capacity planning, and optimization Document SIEM architecture, configurations, and operational procedures Ensure compliance with relevant regulations (e.g., GDPR, HIPAA, ISO 27001) Required Skillsets Hands-on experience with leading SIEM tools (e.g., Splunk, IBM QRadar, ArcSight) Deep understanding of log parsing, normalization, and data ingestion techniques Strong knowledge of cybersecurity frameworks (e.g., MITRE ATT&CK, NIST) Experience in scripting languages (e.g., Python, Bash) for automation Familiarity with firewall, IDS/IPS, antivirus, endpoint security solutions Strong leadership and project management skills Certifications like SIEM Engineer, CISSP, or GCIA preferred (ref:hirist.tech) Show more Show less

Posted 4 days ago

Apply

3.0 years

0 Lacs

Chennai, Tamil Nadu, India

On-site

Linkedin logo

Project Role : Security Architect Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations. Must have skills : Data Loss Prevention (DLP) Good to have skills : NA Minimum 3 Year(s) Of Experience Is Required Educational Qualification : 15 years full time education Summary: As a Security Architect, you will define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Your typical day will involve collaborating with various teams to assess security needs, documenting security controls, and overseeing the transition to cloud security-managed operations, all while ensuring compliance with industry standards and best practices. Roles & Responsibilities: - Expected to perform independently and become an SME. - Required active participation/contribution in team discussions. - Contribute in providing solutions to work related problems. - Engage in continuous learning to stay updated with the latest security trends and technologies. - Assist in the development of security policies and procedures to enhance the overall security posture. Professional & Technical Skills: - Must To Have Skills: Proficiency in Data Loss Prevention (DLP). - Strong understanding of cloud security principles and practices. - Experience with security frameworks such as NIST, ISO 27001, or CIS. - Familiarity with risk assessment methodologies and tools. - Knowledge of incident response and management processes. Additional Information: - The candidate should have minimum 3 years of experience in Data Loss Prevention (DLP). - This position is based at our Chennai office. - A 15 years full time education is required. 15 years full time education Show more Show less

Posted 5 days ago

Apply

0 years

0 Lacs

Karnataka, India

On-site

Linkedin logo

About The Job Become a Part of the NIKE, Inc. Team NIKE, Inc. does more than outfit the world's best athletes. It is a place to explore potential, obliterate boundaries and push out the edges of what can be. The company looks for people who can grow, think, dream and create. Its culture thrives by embracing diversity and rewarding imagination. The brand seeks achievers, leaders and visionaries. At NIKE, Inc. it's about each person bringing skills and passion to a challenging and constantly evolving game. NIKE is a technology company. From our flagship website and five-star mobile apps to developing products, managing big data and providing leading edge engineering and systems support, our teams at NIKE Global Technology exist to revolutionize the future at the confluence of tech and sport. We invest and develop advances in technology and employ the most creative people in the world, and then give them the support to constantly innovate, iterate and serve consumers more directly and personally. Our teams are innovative, diverse, multidisciplinary and collaborative, taking technology into the future and bringing the world with it. Who Are We Looking For We're looking for an Information Security Analyst to join Nike's Corporate Information Security Governance, Risk, and Compliance (GRC) team, which is responsible for enterprise wide GRC ensuring Nike leadership has the information needed to make strategic risk-based decisions and maintain compliance with international regulations while enabling the achievement of Nike business objectives globally. This role will meet with business and technology teams across Nike and consult with them on their security and compliance requirements. We are looking for an individual who is passionate about GRC, someone with a good working knowledge of industry best practice frameworks, such as ISO, NIST and CoBIT. What Will You Work On If this is you, you'll be working with the GRC team and performing these key tasks: Assess moderately complex platforms against Nike security and configuration standards Evaluate and process exceptions to information security policies and standards Participate in complex internal risk assessments, identifying information security risks through analysis of threats and vulnerabilities, and reporting on those risks to Nike business and technology owners Perform risk assessments of critical third-party vendors and ensure the business objectives align with the type and volume of data used in maintaining a "need to know/use" mindset Utilize your thorough understanding of ITGC's to consult with Technology units on compliance matters Champion information security policies, standards, controls, and processes so that compliance requirements are addressed as part of "business as usual" operations Lead Nike business units in control design and control operations related in support of compliance requirements Perform Compliance control validation testing to determine the operating effectiveness of IT controls for scoped systems Provide analysis and insights into data supporting the effectiveness of technical and process-based cyber security controls and establish automated data pipelines that feed data visualization tools, such as Tableau Collaborate effectively with NIKE leaders, managers, employees, and partners to provide deliberate and thoughtful engagement throughout NIKE Help drive execution of the Information Security training programs. Ensure the workforce stays fully informed on information security through formal trainings and oversee the development and delivery of security training and awareness campaigns Effective, positive verbal and written communication skills and experienced creating and developing high-quality PowerPoint presentations Who Will You Work With You will report into the Governance, Risk and Compliance - India Technology Center Director , in support of global GRC processes and procedures, and will work cross-functionally within the Corporate Information Security (CIS) teams and across Nike. You will regularly meet with Nike business and technology teams. What You Bring Knowledge of information security principles and practices, general procedures and guidelines A general understanding of technology use, trends and risks as it applies in a business context and environment Experience reviewing third party SOC reports Experience/working knowledge with PCI DSS (Former QSA is a benefit). Knowledge of information security principles, frameworks, and best practices (e.g., PCI DSS, COBIT, COSO, NIST and ISO 27000) Excellent collaboration skills - must be eager to work as part of a cohesive team and work as a partner to others within Nike, Inc. both at WHQ and globally Experience with ServiceNow, Confluence or JIRA NIKE, Inc. is a growth company that looks for team members to grow with it. Nike offers a generous total rewards package, casual work environment, a diverse and inclusive culture, and an electric atmosphere for professional development. No matter the location, or the role, every Nike employee shares one galvanizing mission: To bring inspiration and innovation to every athlete* in the world. NIKE, Inc. is committed to employing a diverse workforce. Qualified applicants will receive consideration without regard to race, color, religion, sex, national origin, age, sexual orientation, gender identity, gender expression, veteran status, or disability. Benefits Whether it's transportation or financial health, we continually invest in our employees to help them achieve greatness - inside and outside of work. All who work here should be able to realize their full potential. Show more Show less

Posted 5 days ago

Apply

0 years

0 Lacs

Pune, Maharashtra, India

On-site

Linkedin logo

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! Job Summary: We are looking for a detail-oriented and technically skilled Windows Patch Catalog QA Engineer to join our security content or patch management team. The role focuses on validating and verifying the accuracy, completeness, and functionality of Windows patch catalogs across different platforms and tools. The ideal candidate will work closely with developers, content engineers, and system administrators to ensure reliable and high-quality patch metadata that supports secure and compliant system operations. Key Responsibilities: Review and validate Windows patch catalog entries (e.g., KB articles, supersedence, classification, severity, product applicability). Perform functional testing of detection logic for vulnerabilities and patch deployment workflows. Ensure alignment of patch metadata with Microsoft advisories, CVEs, and vendor bulletins. Verify applicability of patches across various Windows OS versions and editions (e.g., Windows 10/11, Server 2016–2022). Collaborate with developers to identify and resolve logic errors or metadata inconsistencies in the patch catalog. Conduct regression testing on recurring content updates (e.g., Patch Tuesday releases). Maintain QA test environments, virtual machines, and snapshots for validation across different system configurations. Create, maintain, and execute automated and manual test cases and checklists. Log and track defects in bug tracking systems (e.g., JIRA, Azure DevOps) and support timely resolution. Support documentation efforts, including test plans, validation reports, and release notes. Required Skills and Qualifications: Solid understanding of Windows patching mechanisms (Windows Update, WSUS, SCCM/Intune). Familiarity with Microsoft KB articles, CVE-based patching, and cumulative/superseded patch structures. Experience with QA methodologies and tools (manual and automated). Proficient in scripting (e.g., PowerShell) to assist with test automation or validation. Comfortable working with virtualization platforms (e.g., VMware, VirtualBox, Hyper-V). Experience with bug tracking and test case management tools (e.g., JIRA, TestRail, Zephyr). Strong analytical skills with high attention to detail and documentation accuracy. Preferred Qualifications: Exposure to security content platforms (e.g., Qualys, Tanium, BigFix, Ivanti, ManageEngine). Understanding of vulnerability management lifecycle and security configuration benchmarks (e.g., CIS, NIST). Experience testing patch-related functionality in enterprise environments. ISTQB or similar QA certification. Soft Skills: Strong problem-solving and communication skills. Ability to work in fast-paced environments with changing patch data. Passion for accuracy and consistency in metadata and patch intelligence. Collaborative team player with proactive QA mindset. Show more Show less

Posted 5 days ago

Apply

3.0 years

0 Lacs

Bengaluru, Karnataka, India

On-site

Linkedin logo

Get to know Okta Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences. Join our team! We’re building a world where Identity belongs to you. As a Senior IT Internal Auditor, you will work with an agile team in a fast paced/high technology environment on multiple audit engagements across the enterprise throughout the audit cycle. You will participate in activities including identifying and assessing IT risks, developing and executing audit programs, completion of high-quality workpapers, identifying issues and reporting the results to audit stakeholders and management. This position will report to the Internal Audit Manager and will work closely with Business Technology (BT), Security, Engineering and other cross functional stakeholders. We’re looking for an individual with strong technology experience and an understanding of technology audit and IT risk, who is eager to join a small, growing team within a company continuing to experience rapid growth and expansion. Company Description: Okta is the foundation for secure connections between people and technology. By harnessing the power of the cloud, Okta allows people to access applications on any device at any time, while still enforcing strong security protections. It integrates directly with an organization’s existing directories and identity systems, as well as 4,000+ applications. Because Okta runs on an integrated platform, organizations can implement the service quickly at large scale and low total cost. Thousands of customers, including Adobe, Allergan, Chiquita, LinkedIn, and Western Union, trust Okta to help their organizations work faster, boost revenue, and stay secure. To learn more about Okta, visit: https://www.okta.com . Responsibilities: Evaluate the design and operational effectiveness of key cybersecurity and related controls used at Okta Conduct walkthroughs, test controls and document workpapers (in a manner that aligns to our department methodology), assess IT risks, design audit programs, execute fieldwork, and write audit reports Effectively partner with BT, Security, Engineering, and cross functional stakeholders to ensure completion of remediation activities agreed upon during audit projects Gain stakeholder agreement on root causes of issues and appropriate corrective actions, while maintaining positive client relationships Participate in providing risk-based consulting to assist management during the development of business process improvements or the implementation of new systems Provide guidance, training and mentorship to other team members, fostering professional growth and ensuring knowledge transfer across the team Exercise judgment regarding planning, risk assessments, and completion of objectives on complex projects Qualifications: Bachelor’s degree in computer science, information systems, “STEM” (Science, Technology, Engineering and Math) or related major 3+ years of experience in audit with a focus on technology and IT risk Process an understanding of IT general controls including cybersecurity, SDLC, access and change management, logging and monitoring, disaster recovery, and cloud computing Technical expertise in IT systems including infrastructure, cybersecurity, and familiarity with IT governance frameworks Analytical and critical thinking proficiency in analyzing complex data and extracting meaningful insights Ability to identify root causes of issues and recommend appropriate remediation and safeguards Big 4 or similar auditing experience is desirable Strong written and verbal communication skills, including listening and interviewing skills Experience using industry standards/framework such as NIST CSF and COBIT Proven ability to conduct a variety of operational audits, including financial, operational, and IT Experience with cloud-based or software as a service (SaaS) companies is a plus Maintains a CISM, CISSP, CEH, or CISA designation Excellent analytical, organizational, and written/verbal communication skills Position is eligible for hybrid work, so communication, collaboration, and organization are key to your success Ability to effectively discuss audit findings and develop impactful solutions with business partners, focusing on right-sized solutions given the size and complexity of the organization Solutions oriented, with a willingness to roll up your sleeves to “get it done” Ability and desire to work hands on in an evolving, fast-paced environment What you can look forward to as a Full-Time Okta employee! Amazing Benefits Making Social Impact Developing Talent and Fostering Connection + Community at Okta Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/. Some roles may require travel to one of our office locations for in-person onboarding. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/. Show more Show less

Posted 5 days ago

Apply

0 years

0 Lacs

Hyderabad, Telangana, India

On-site

Linkedin logo

Company Description We’re Entain. Powered by our very own technology and building products that push boundaries, Entain is home to a global family of more than 25 well-known brands and over 24,000 people, but we all play for the same team. When we win, we win together. Our vision is to be the world leader in betting, gaming, and interactive entertainment by bringing moments of excitement into people’s lives. We will achieve this through our focus on sustainability and growth, driving change in the fast-paced world of entertainment. This is a position for an experienced technical compliance professional who wishes to start a role within a busy global Cybersecurity team. As a Cybersecurity Governance Specialist with a focus on our US business you will be working within a team responsible for reviewing that the operations of Entain, adhering to our Cybersecurity and Technical Compliance requirements, designing and implementing improvements to address & identify gaps and to help adapt the security posture of the organisation to the evolving global threat and regulatory landscape. PLEASE NOTE: The successful candidate would need to have a strong understanding of US frameworks and industry standards such as GLI-19, GLI-33, MICS, etc. Job Description Primary Responsibilities: Come to terms with all relevant Cybersecurity methodology, terminology and Technology Governance processes. Design Cybersecurity controls to adapt to new emerging threats and challenges. Establish relationships with internal business sponsors and key stake holders to ensure requests are processed with minimal business disruption. Understand complex IT requests and be able to translate them into simple but accurate requests. Design and implement changes in the Technology platform to align with Cybersecurity compliance requirements. Comfortable with Identifying and escalating audit management issues to the relevant parties. Driving technical compliance checks and raising awareness of technical compliance requirements within the group. Comfortable with engaging with technical teams to drive remediation of audit findings. Qualifications Essential Excellent understanding of standards, compliance and regulatory requirements and objectives. Strong understanding of US frameworks and industry standards such as GLI-19, GLI-33, MICS, etc. Strong understanding of the different audit standards such as ISO27001, PCI-DSS, SOC, and NIST. Customer-oriented person, with the ability to educate a non-technical audience Process driven and delivery focused. Eagerness to learn and adapt. Project management skills. Experience in the following areas: IT Audits US Information Security frameworks Risk Management Desired Previous experience of being involved in audits Experience of working with the external audit companies Relevant security audit certification (CISA, CISSP, etc) Industry experience Application Security knowledge Relevant professional qualifications will be considered, although not a requirement. Additional Information With the capacity to display initiative as part of a very strong Technology Governance team, this position plays a key role in ensuring the continued alignment of our Technology department with business objectives. The Candidate should be able to think laterally; suggest process improvements; drive results; Confident with other team members and able to engage with Vendor third parties to ensure Entain’s' data and confidentiality is maintained to the highest of security standards. At ivy, we do what’s right. It’s one of our core values and that’s why we're taking the lead when it comes to creating a diverse, equitable and inclusive future - for our people, and the wider global sports betting and gaming sector. However you identify, across any protected characteristic, our ambition is to ensure our people across the globe feel valued, respected and their individuality celebrated. We comply with all applicable recruitment regulations and employment laws in the jurisdictions where we operate, ensuring ethical and compliant hiring practices globally. Show more Show less

Posted 5 days ago

Apply

8.0 - 10.0 years

10 - 12 Lacs

Mumbai

Work from Office

Naukri logo

Sales Specialist Meet the Team Indian enterprise sector is going through huge digital transformation. Areas like Cloud adaption, Sophisticated Analytics, AI, IOT, Block chain & Robotic Process Automation, Information Security are key building block towards this transformation. You would be responsible for Building Cisco Security Business pipeline & achieve the Security Annual targets in the large enterprise segment Your Impact Lead Large Customer Engagement with CISO level conversation within Ciscos top enterprises and conglomerate. Support Sales Account Management (AMs) as Cyber Security Sales Specialist in large sophisticated projects (comprising of Zero Trust Architecture, Securing cloud work loads, transforming SOC, Micro segmentation and others) Understand the client/sector requirements and Map Cisco Security products & Services & Build Solution Stack for Sales Account Managers Understand NIST, CERTIN guidelines, mitre att&ck framework, OT Security. Good understanding of Cisco Security products. Well engaged with Tier-1 & Tier-2 SI Drive Cisco Security product sales within commercial segment in Manufacturing, PSU, ITeS, Digital Native and Pharma Who You'll Work With GSSO SE team Account Manager Product Engineering BU across vertical Regional SE Team Regional Channel Team Minimum Qualifications 8-10 Years of experience in Security OEM / Service Provider Environment in managing Sales/ Pre-Sales/Product Management function Good understanding of business scenarios with solution expertise to formulate a realistic and executable strategy for Security adoption among enterprises. Possess blend of technology expertise across various cyber security vendors, enterprise networks, datacenter, cloud networking and Information systems security. Good connects with Cybersecurity decision makers in enterprises

Posted 5 days ago

Apply

2.0 years

0 Lacs

Pune/Pimpri-Chinchwad Area

On-site

Linkedin logo

Company Description Strategy (Nasdaq: MSTR) is at the forefront of transforming organizations into intelligent enterprises through data-driven innovation. We don't just follow trends, we set them and drive change. As a market leader in enterprise analytics and mobility software, we've pioneered the BI and analytics space, empowering people to make better decisions and revolutionizing how businesses operate. But that's not all. Strategy is also leading a groundbreaking shift in how companies approach their treasury reserve strategy, boldly adopting Bitcoin as a key asset. This visionary move is reshaping the financial landscape and solidifying our position as a forward-thinking, innovative force in the market. Four years after adopting the Bitcoin Standard, Strategy's stock has outperformed every company in S&P 500. Our people are the core of our success. At Strategy, you'll join a team of smart, creative minds working on dynamic projects with cutting-edge technologies. We thrive on curiosity, innovation, and a relentless pursuit of excellence. Our corporate values—bold, agile, engaged, impactful, and united—are the foundation of our culture. As we lead the charge into the new era of AI and financial innovation, we foster an environment where every employee's contributions are recognized and valued. Join us and be part of an organization that lives and breathes innovation every day. At Strategy, you're not just another employee; you're a crucial part of a mission to push the boundaries of analytics and redefine financial investment. Job Description Join Strategy’s IT Security group as an Application Security Engineer and play a crucial role in safeguarding Strategy’s software applications while using modern security and AI tooling. In this position, you will be responsible for integrating security practices throughout the software development lifecycle, ensuring that our software products are resilient against vulnerabilities. Secure SDLC Integration: Work closely with development teams to integrate security into the SDLC, including threat modeling, secure code reviews, and security testing. Vulnerability Management: Identify, triage, and remediate security vulnerabilities through static and dynamic application security testing (SAST/DAST) and software composition analysis (SCA) tools. Security Assessments & Penetration Testing: Conduct manual and automated penetration testing of web, mobile, and cloud applications to detect security flaws. Secure Code Review: Analyze source code and provide security recommendations to developers to ensure adherence to secure coding best practices. Threat Modeling & Risk Analysis: Perform threat modeling to anticipate potential attack vectors and improve security architecture. DevSecOps Enablement: Support and enhance DevSecOps initiatives by integrating security automation within CI/CD pipelines. Incident Response & Remediation: Assist in investigating security incidents related to applications and work with engineering teams to remediate threats. Security Awareness & Training: Educate and mentor developers on OWASP Top 10, SANS 25, and other security best practices. Job Location Application Security Engineer Pune, India Full-time in person from Strategy Office Qualifications Bachelor’s degree in Computer Science, Engineering, or related field Minimum 2 years of software development or software security experience in an agile environment Hands-on experience with SAST, DAST, IAST, and SCA tools (e.g., Checkmarx, Fortify, Veracode, SonarQube, Burp Suite, ZAP). Fluent in one or more programming languages, such as Python, Java, JavaScript Strong knowledge of secure coding principles and application security frameworks Familiarity with security tools (e.g., static and dynamic analysis tools, vulnerability scanners) Understanding of security standards and regulations (e.g., OWASP, NIST) Hands-on experience with Generative AI and/or ML in creating innovative applications that enhance productivity and efficiency, coupled with a strong eagerness to learn Experience with cloud security best practices in AWS, Azure, or GCP. Strong work ethic with a commitment to meeting business needs and effectively collaborating with global colleagues Effective interpersonal skills; ability to collaborate successfully with both technical and non-technical stakeholders Ability to articulate complex technical concepts with clarity, supported by effective written and verbal communication skills Additional Information The recruitment process includes online assessments as a first step (English, logic, design, technical) - we send them via e-mail, please check also your SPAM folder Show more Show less

Posted 5 days ago

Apply

2.0 - 3.0 years

0 Lacs

Mumbai Metropolitan Region

On-site

Linkedin logo

Job Description About Us : Tsaaro is dedicated to Data Privacy and Security as its core focus. Our team comprises specialized data privacy consultants, information security experts, and penetration testers, all working to empower our clients with seamless and highly efficient security solutions. Our approach is centered around customization, understanding the unique needs of each organization, and finding solutions that align with their budget and resource constraints. At Tsaaro, we adopt a pragmatic, risk-based strategy to deliver practical and effective advice. By providing real-world guidance, support, and actionable recommendations, we confidently equip our clients to address a broad spectrum of security and privacy challenges. Responsibilities As a Senior Data Privacy Consultant, you will be entrusted with the following key responsibilities: Design and implement data protection and privacy programs that cater to our clients' specific business needs, ensuring their sensitive information is well safeguarded. Evaluate and assess our clients' data protection and privacy practices, offering valuable insights and actionable recommendations for continual improvement. Demonstrate expertise in various standards, such as ISO 27001/2, ISO 22301, ISO 27018, NIST standards on Cyber Security, HITRUST, ISO 27701, etc., to assist clients in compliance and governance. Provide guidance and support to clients in adhering to a complex web of national and international laws and regulations, including the EU General Data Protection Regulation (GDPR) and other privacy laws. Assist in preparing policies, reports, and schedules for clients and relevant stakeholders, ensuring clear communication and alignment with industry best practices. Conduct thorough audits of Privacy controls to monitor program effectiveness and compliance, ensuring data protection is at its optimal level. Utilize online tools to facilitate Incident Management and Data Subject Rights processes, ensuring efficient and timely responses to potential data incidents. Foster and maintain productive working relationships with client personnel, promoting effective collaboration and understanding of their specific needs. Demonstrate a strong commitment to adhering to workplace policies and procedures, maintaining the highest standards of professionalism and confidentiality. Contribute to cybersecurity engagements, developing cybersecurity strategies, governance, risk, and compliance activities, and cybersecurity policies in line with ISO 27001 and ISO 27701. Perform Gap Assessments, Risk Assessments, ISMS Documentation, Internal Audits, and support during Certification Audits to strengthen overall security frameworks. Requirements To be considered for this role, the candidate must meet the following requirements: Possess a sound knowledge of fundamentals of information security systems. Have 2-3 years of relevant experience in the field. Demonstrate proficiency in standards such as ISO 27001/2, ISO 22301, ISO 27018, NIST standards on Cyber Security, HITRUST, ISO 27701, etc. Exhibit a good understanding of GDPR, CCPA, or other privacy laws. Display competence in governance and reporting, as well as a strong grasp of cyber and privacy risks. Hold relevant qualifications such as CIPM, CIPT, CIPP/E. Showcase excellent communication skills, both written and verbal. Benefits Competitive salary and performance-based bonuses. Professional development opportunities, including training and certifications. Flexible working hours. Collaborative and inclusive work environment. Opportunity to work with a passionate team dedicated to making a difference in data privacy and security. check(event) ; career-website-detail-template-2 => apply(record.id,meta)" mousedown="lyte-button => check(event)" final-style="background-color:#6875E2;border-color:#6875E2;color:white;" final-class="lyte-button lyteBackgroundColorBtn lyteSuccess" lyte-rendered=""> Show more Show less

Posted 5 days ago

Apply

4.0 - 8.0 years

10 - 15 Lacs

Bengaluru

Work from Office

Naukri logo

The SIEM Administrator will be responsible for administering the deployed SIEM service. The candidate is also expected to have hands on experience of deploying a SIEM solution from scratch, where the candidate should have the skills and knowledge to gather all the required information to build the SIEM solution. In-depth knowledge of technical approaches in security analytics, monitoring and alerting. Maintains technical knowledge within areas of expertise. This role is also responsible for identifying, analyzing, developing new or tuning & Refinement of the content or use cases. Strong problem solving and troubleshooting skills including the ability to perform root cause analysis for preventative investigation Required education Bachelor's Degree Preferred education Master's Degree Required technical and professional expertise Should have experience in any of the query language i.eAQL ,KQL, SPL, LEQL etc for writing the complex queries & saved search creation. Should have strong knowledge of different cybersecurity frameworks i.e.MITRE, NIST and Cyber kill chain model. Should have understanding of regular expression writing and custom parsing Preferred technical and professional experience Collaborate with key stakeholders within technology, application and cyber security to develop use cases to address specific business needs. Create technical documentation around the content deployed to the SIEM. Creates and develops correlation and detection rules with SIEM solution, reports & dashboards to detect emerging threats

Posted 5 days ago

Apply

3.0 - 7.0 years

7 - 11 Lacs

Bengaluru

Work from Office

Naukri logo

Generate compliance reports from an existing dashboard or build requirements to create a new reporting dashboard Proactively Monitor, track, and report on security compliance status across systems and processes. Analyze large datasets to identify trends, anomalies, and compliance risks. Support security audits, assessments, and certification efforts through data collection and analysis. Possess strong communication skill, collaborate with cross-functional matrix teams to drive root cause analysis, corrective actions and improvements based on data insights. Maintain and enhance compliance reporting dashboards and metrics for leadership visibility and decision making. Required education Bachelor's Degree Required technical and professional expertise Experience working with security architects and technical security teams to define and implement security processes and procedures based on industry-standard best practices and compliance requirements. Defining the requirements and validating the procedures and audit testing methodology Working with the Development teams to ensure automation of evidence collection and evidence management is always in line with compliance expectations, otherwise, identifies specific actions and owners to meet the expectations. Assisting team members in addressing highly complex security issues applicable to enterprise environment Ability to utilize project management principles to properly scope compliance work efforts by service lines, identify common areas of work, and create a measurable milestone plans across service lines to enable completion of compliance work items on time. Ability to manage multiple priority projects simultaneously under a short timeline Experience/familiar with enterprise risk management (ERM) framework, service delivery operations, software development lifecycle and be able to understand when to request and integrate risk items into compliance reporting. Experience with compliance programs such as FedRAMP/ FISMA, HIPAA, GDPR, SOC 2, PCI, NIST, ISO, ITAR, etc. Conducting regular reviews on compliance progression of systems and hosting internal audit/assessment as required to maintain compliance certifications. Ability to translate and interpret regulatory compliance requirements into technical controls Ability to understand cloud enterprise business computing operations/requirements, and effectively communicate to service lines what is expected in order to consider a work item complete. Also, will possess good understanding of networking security including security systems such as firewalls, intrusion detection, vulnerability scanning, OS patching, health-checking Diagnosing the root cause of problems and propose solutionsExamples would be failed patches, tooling issues, false positives on system tests, authentication problems. Drive and track audit, security and compliance finding remediation to closure. Experience with enterprise configuration Management database (CMDB) or IT Asset inventory Management. Understand CMDB's structure, data quality, relationships between CIs (Configuration Items), and updates. Use the CMDB for risk, audit, and compliance analysis and reporting Proficiency in SQL, Excel (advanced levelpivot tables, macros), and ServiceNow— data analytics and visualization functionalities Ability to process large datasets, identify and handle missing data, data transformation, normalization, and data quality checks. Ability to perform data analysis to discover patterns and trends to mitigate security risks and drive business results Work with stakeholders to define key metrics and KPIs; develop dashboards and reports for business users. Collaborate with database engineers, data owners, security focal, product managers, and broader metrics teams to understand data needs. Results oriented with intense focus on achieving both short and long term goals. He/she should be able to drive and execute an agenda in a fast paced, dynamic environment. Strong project management skills with ability to design visual and appealing presentations Strong collaboration, problem-solving and critical-thinking abilities. Excellent communication skills — ability to explain technical findings to non-technical audiences. Good time management, organizational skills, and ability to prioritize tasks. Curiosity and a continuous learning mindset. A highly organized with strong attention to detail, analytical and project management skills Work independently within a team focused organization. Preferred technical and professional experience Experience or familiar with cloud service models; IaaS preferred. Project management and consulting experience is a plus Experience with process automation is a plus Experience with Linux Shell, Perl or Python is a plus

Posted 5 days ago

Apply

10.0 years

0 Lacs

Pune, Maharashtra, India

On-site

Linkedin logo

TransUnion's Job Applicant Privacy Notice What We'll Bring TransUnion works with businesses and consumers to gather, analyze, and deliver critical information needed to build strong economies around the world. Protection of that information is critical to our customers and business. As part of our 2020 transformation journey, we became Global Audit & Advisory (GAA), formerly Internal Audit. As a Specialist III you will be part of the GAA team and be responsible for conducting Cybersecurity and IT audit engagements throughout the organization that support business objectives, best practices, and regulatory requirements. The incumbent will be responsible for the planning, execution, reporting, and follow-up on all audit engagements by participating on an audit team or at times independently leading engagements under the direction of GAA Management. This position will report directly to the Senior Lead and will work closely with other GAA Team Associates on key projects and initiatives as well as coordinate closely with our external auditors. The Global Audit & Advisory team is an independent and objective assurance and consulting activity that is guided by a philosophy of adding value to improve the operations of TU. GAA assists the organization in accomplishing its objectives by bringing a systematic and disciplined approach to evaluate and improve the effectiveness of the organization's risk management, control and governance processes. GAA collaborates with the Business Units, Functional leadership and their Associates in developing strong, professional and independent relationships to ensure a comprehensive understanding of the business to enable value added recommendations that improve efficiency and effectiveness. What You'll Bring Perform detailed examinations of cybersecurity and IT practices and controls throughout the organization using an established assessment process and framework. The essential duties are as follows: Independently perform Information technology (IT) security reviews. Initiate, scope, plan, research and conduct IT controls assessments and audits. Lead and coordinate with process owners to initiate, scope, plan, and execute periodic controls assessments as part of the internal audit function, focusing on identifying risks by evaluating the design and operating effectiveness of internal controls. Actively support security audit initiatives by aligning audit procedures with cybersecurity frameworks (e.g., NIST, ISO 27001 etc.), conducting control walkthroughs, testing IT security and IT general and application controls, and assessing compliance with internal security policies. Document the results of audit procedures performed that support the conclusions reached. Prepare audit reports based on the adequacy and effectiveness of controls evaluated. Support external audits and regulatory examinations as needed. Analyze information security areas including (but not limited to these) governance and risk management, access and password controls, cloud security, cybersecurity, physical security, system security architecture and design, BCP and Disaster Recovery, network security, application and operations security, Incident Management, data migrations and system implementations etc. Lead engagement and communicate issues to process owners, ensuring understanding of risks and actions needed to remediate risks and subsequently track remediation activities. Cross train members of the Global Audit Team, including new hires and mentor junior IT staff. Continuously monitor emerging security trends and evolving threat landscapes through ongoing research and professional development. Insights gained are integrated into the audit universe to ensure risk assessments and audit planning remain current and aligned with the organization’s security posture. Perform risk assessments and assist in the development of the annual audit plan. Participate in departmental initiatives, administrative matters, and special projects. Assist with other audit engagements as needed to broaden exposure across various risk areas and support the timely execution of the overall audit plan. Impact You'll Make What You Will Bring: 6 – 10 years of experience in an IT/Security Audit and Assessment, or Information Security Technical, Management and/or Governance role. Bachelor’s or Master’s degree in computer science/information technology, management information systems or related field. Industry certification such as CISSP, CISA, CISM, CEH and/or CIA required. Experience with Cloud Security audits (AWS, Azure, GCP). Knowledge of data protection laws and industry standards. Familiarity with GRC platforms (e.g., AuditBoard, Onspring, Archer). Demonstrated in-depth knowledge of concepts, best practices and controls in a breadth of Information Security areas/domains. These include governance & risk management, access control, cybersecurity, physical security, security architecture and design, business continuity/disaster recovery, network security, application and operations security and compliance/incident management. Demonstrated ability to understand complex technologies, business processes, regulations and emerging risks. Strong technical and/or IT and Security audit background with practical knowledge of a wide variety of technologies including server infrastructure and operating systems, network and web infrastructures, database architecture, vulnerability and penetration testing assessment and Intrusion Detection/Prevention Systems. Good understanding of SOX legislation and IT and Security frameworks including COSO and COBIT. Self-starter with the ability to manage and prioritize responsibilities. Team player with proven skills in influencing people without having direct management authority. Self-driven performer with established skills in tracking self and project performance, anticipating and recognizing problems and escalating issues appropriately. Strong ability to interact and communicate both written and verbally with people at all levels, both technical and non-technical, in a dynamic environment where interactions are not always in person. Strong risk analysis and problem solving skills. Must be flexible to ensure assessments are performed timely and manage multiple assessments simultaneously. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. TransUnion Job Title Consultant, Audit and Advisory Show more Show less

Posted 5 days ago

Apply

7.0 - 11.0 years

4 - 8 Lacs

Bengaluru

Work from Office

Naukri logo

Skill required: Pharmacovigilance Services - Safety Writing Designation: Pharmacovigilance Services Specialist Qualifications: Bachelor of Pharmacy Years of Experience: 7 to 11 years About Accenture Combining unmatched experience and specialized skills across more than 40 industries, we offer Strategy and Consulting, Technology and Operations services, and Accenture Song all powered by the worlds largest network of Advanced Technology and Intelligent Operations centers. Our 699,000 people deliver on the promise of technology and human ingenuity every day, serving clients in more than 120 countries. Visit us at www.accenture.com What would you do Prepare and review PSUR/ PBRER/DSUR/PADER/ Addendum Statement/Addendum to clinical overview/US IND reports/ Aggregate finding safety reports/Local reports/ Cumulative Review/Health Authority requests / Health Authority assessment reports as per the applicable procedural documents on the project.Perform scheduling of reports, and author, peer review, publishing, tracking and management activities of assigned reports.Perform request for inputs activity for the reports (based on the RFI [request for information] and as per the applicable process and SOPs).Send the case closure request and request for Line Listings/ Summary Tabulations, as applicable.Initiate, organize, and lead the strategy meeting for evaluation of safety topic/request. Prepare meeting minutes and distribute final minutes with all invitees.Review the information received from contributors and obtain any missing information.Draft aggregate report using clients templates including analysis of safety, clinical and other global line function data. Summarize literature information for applicable reports.Perform peer review of the draft report.Share the draft for quality review.Address the comments from the peer reviewer, quality reviewer and incorporated into the report.Share the draft report with client (or external) stakeholders for review (as applicable).Incorporate and address the comments from stakeholders into the draft report and seek clarification where applicable.Schedule meetings with project safety physicians to resolve report related queries and prepare submission ready draft report.Perform final peer review of draft reports and provide feedback with the duly filled defect tracker.Share the final draft along with the QC scorecard results to client (as applicable).Obtain Client/ESP signature/approvals for the finalized report.Complete and finalize report according to the procedural document requirements.Ensure compliance of finalized report with applicable process and SOPs.Obtain signature/approval for the finalized reports as defined in procedural document What are we looking for Ability to establish strong client relationship Roles and Responsibilities: Prepare/compile the final report and confirm that document is complete, including it contains all the applicable annexes as needed and instructed by client, and then submit the finalized report to client.Notify client (regulatory team) that the final report has been submitted to client and confirm all prepared submission documents are uploaded into client environment.Archive AR-related information in dedicated folders on client shared drives or other electronic repositories (as agreed in the procedural document).Perform HA submission tracking of applicable Aggregate ReportsCapture quality data for metrics reporting.Responsible for knowledge sharing, coaching, review and providing feedback of reports processed by the Mentees.Complete all trainings assigned by internal and client on their LMS within due date.Notify critical and major deviations (referred as Quality Issues) within one business days and minor deviations- three business days to Accenture Quality Management team.Organize, action, and archive the communication received at and sent from AR mailbox appropriately.Share/forward product/document type relevant emails to the appropriate user/owner as required and ensure closure.Management of Accenture personal assigned to the AR function.Oversight on the AR mailbox managementEnsure teams delivery of reports within agreed timelines with SLAs and KPIs.Liaising with client or any issue mitigation and troubleshooting.Ensure the retention.Ensure training and mentoring of new associates and documentation of the same.Address any quality related issues and implementation of quality improvement initiatives for the team. Qualification Bachelor of Pharmacy

Posted 5 days ago

Apply

2.0 - 7.0 years

8 - 12 Lacs

Bengaluru

Work from Office

Naukri logo

Job Title - IT Audit Senior Analyst Management Level: ML10 Location: Bangalore Must have skills: IT Audit experience, Understanding of Security Standards like ISO27001, PCI DSS, HIPAA, NIST 800-53 Good to have skills: Possession of a one or more of these professional certifications (ISO27001 Lead Auditor, CISA, CISSP, CIA, CCSK, AWS Cloud Practitioner, Azure Fundamentals) is preferred. Job Summary : Roles & Responsibilities: Participate in execution of the risk-based audit plan, reporting results to Accenture Leadership and the Audit Committee of the Board of Directors Conduct a wide-ranging scope of audits with an emphasis on assessing emerging areas of risk including cyber security, artificial intelligence, cloud computing, robotic process automation, and the Internet of Things. Through advisory services, work with our business partners to help them proactively identify and manage risk in new technologies, new go-to-market offerings, and critical corporate initiatives. Shape the future of the Accenture Internal Audit through involvement in departmental initiatives that enable us to become more efficient and effective in everything we do. Ensure your technical skill set and business acumen stay current and relevant through participation in our robust training program. Professional & Technical Skills: Experience conducting IT external and internal audits or assessments, preferably for a global organization. Strong IT knowledge in infrastructure technologies (networking, data centers and hosting, virtualization, cloud etc.), application development and support, and emerging technologies. Experience leveraging predictive models and custom analytics in audit planning and execution is preferred. Technical knowledge and familiarity with control requirements in areas including ERP applications, Windows and Unix operating systems, cyber security, and vendor management. Strong verbal and written communication skills and proficiency with the English language. Demonstrated analytical thinking, teamwork, and collaboration skills. Possession of a relevant professional certification (CISA, CISSP, CIA, CPA, CCSK) is preferred. Ability to adopt flexible work hours to collaborate with global teams and travel (up to 20%). Additional Information: We Are: Accenture is helping transform leading organizations and communities around the world. Choose Accenture and make delivering innovative work part of your extraordinary career. Accenture works at the intersection of business and technology to help clients improve their performance and create sustainable value for their stakeholders. Accenture is consistently recognized onFORTUNEs 100 Best Companies to Work Forand DiversityIncs Top 50 Companies for Diversitylists. The Internal Audit Department provides the Audit Committee of the Board of Directors with an independent and objective assessment of the reliability and integrity of financial and select operating information, the effectiveness and efficiency of Accenture plc and its consolidated subsidiaries (the Company) systems and internal controls, and compliance with the Companys policies and procedures. Internal Audit Services also provides advisory services designed to add value and improve the Companys operations through bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, controls, operations, and governance processes. You Are: An agile, highly-motivated, innovative thinker with a background in audit, risk, or compliance looking to join a fast-paced, global internal audit organization that has embraced transformative capabilities including advanced analytics, dynamic risk assessment processes, and automation to retain its role as a trusted advisor to the business. Why Should I Join the Accenture Team You are looking for an internal audit role that provides you with exposure to senior levels of leadership, enables you to work with emerging technologies, provides opportunities for international travel and flexible work arrangements (work from home), requires little to no SOX testing, and offers a competitive salary and benefits package. About Our Company | AccentureQualification Experience: Minimum 2 years experience in IT auditing, testing IT General controls and information security controls, or related technical role focusing on security compliance activities Strong IT knowledge in infrastructure technologies (networking, data centers and hosting, virtualization, cloud etc.), application development and support, and emerging technologies. Educational Qualification: Undergraduate degree in Computer Science, Information Systems, Accounting, Business Administration, or Finance. MBA, Masters in Engineering.

Posted 5 days ago

Apply

Exploring NIST Jobs in India

The job market for NIST (National Institute of Standards and Technology) professionals in India is rapidly growing. As more companies focus on cybersecurity and data protection, the demand for individuals skilled in NIST guidelines and frameworks is on the rise. Job seekers with expertise in NIST can find a variety of opportunities across different industries in India.

Top Hiring Locations in India

  1. Bangalore
  2. Hyderabad
  3. Mumbai
  4. Delhi
  5. Pune

These cities are known for their thriving tech industries and have a high demand for NIST professionals.

Average Salary Range

The average salary range for NIST professionals in India varies based on experience level. Entry-level positions may start around INR 4-6 lakhs per year, while experienced professionals can earn upwards of INR 15-20 lakhs per year.

Career Path

In the field of NIST, a typical career path may include roles such as NIST Analyst, NIST Consultant, and NIST Manager. As professionals gain more experience and expertise, they can progress to Senior NIST Consultant, NIST Architect, and even Chief Information Security Officer (CISO).

Related Skills

In addition to expertise in NIST, employers often look for professionals with the following related skills: - Cybersecurity - Risk management - Compliance - Information security - Security frameworks (e.g., ISO 27001)

Interview Questions

  • What is NIST and why is it important? (basic)
  • Can you explain the difference between NIST 800-53 and NIST 800-171? (medium)
  • How do you ensure compliance with NIST guidelines in a cloud environment? (advanced)
  • What are the key components of a NIST risk management framework? (medium)
  • Have you ever led a NIST compliance audit? If so, can you describe the process? (advanced)
  • How do you stay updated with the latest NIST guidelines and updates? (basic)
  • Can you give an example of a security control outlined in NIST 800-53? (medium)
  • What is the role of NIST in incident response planning? (medium)
  • How do you handle security incidents in accordance with NIST guidelines? (advanced)
  • Have you worked with NIST SP 800-171 requirements? If so, can you describe your experience? (medium)
  • How do you prioritize security controls when implementing NIST guidelines in an organization? (advanced)
  • What are the key differences between NIST and other security frameworks like ISO 27001? (medium)
  • Can you explain the concept of continuous monitoring in the context of NIST? (medium)
  • How do you ensure data integrity in accordance with NIST guidelines? (advanced)
  • Have you implemented multi-factor authentication in compliance with NIST recommendations? If so, what challenges did you face? (medium)
  • How do you handle vulnerabilities identified through NIST risk assessments? (advanced)
  • Can you describe a successful NIST implementation project you were involved in? (medium)
  • How do you communicate NIST compliance requirements to non-technical stakeholders? (medium)
  • How do you approach security awareness training in alignment with NIST guidelines? (medium)
  • What are the key considerations when developing a NIST-compliant security policy? (medium)
  • How do you assess the effectiveness of security controls based on NIST recommendations? (advanced)
  • Can you provide an example of a security incident response plan based on NIST guidelines? (medium)
  • How do you ensure data privacy in alignment with NIST standards? (medium)
  • What are the key challenges organizations face when implementing NIST guidelines? (medium)

Closing Remark

As you explore opportunities in the NIST job market in India, remember to showcase your expertise, stay updated with industry trends, and prepare thoroughly for interviews. With the right skills and preparation, you can confidently pursue a successful career in NIST in India. Best of luck!

cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

Featured Companies