1,536 Cybersecurity Manager jobs in India

Project Cybersecurity Manager

Bengaluru, Karnataka Alstom

Posted today

Job Viewed

Tap Again To Close

Job Description

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling, and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

Your future role

Take on a new challenge and apply your engineering expertise in a new cutting-edge field. You’ll work alongside passionate, motivated, and dedicated teammates.

You'll analyze project and program security needs (including laws and local regulations), determine security objectives, and develop strategies to address key security risks. Day-to-day, you’ll work closely with teams across the business on cybersecurity architecture definition, requirement allocation, and much more.

You’ll specifically take care of defining the cybersecurity context and conducting cybersecurity risk analyses, but also contribute to the implementation of security measures and governance.

We’ll look to you for:

  • Leading and contributing technically to the architectural elements in the tender and project design phases

  • Planning security activities within the development lifecycle, estimating costs and durations, and identifying training needs

  • Providing expertise and governance to ensure adherence to product standards in technical design meetings for tenders and projects

  • Obtaining agreements from project/program stakeholders and customers on the set of security measures to be implemented

  • Promoting the Alstom Code of Ethics and adhering to the highest standards of ethical conduct

  • Reporting on program/project cybersecurity status related to architectural elements

  • Playing the role of project cybersecurity manager on selected projects, delivering on project quality, cost, and delivery (QCD) objectives while adhering to methodologies and standards


All about you

We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role:

  • Degree in Computer Engineering or Software Engineering

  • Experience with direct responsibility for hands-on architecture, design, and development

  • Experience related to cybersecurity, including deployment of security technologies

  • Knowledge of Alstom Products & Solution Portfolio

  • Experience in embedded or industrial systems (e.g., railway or aeronautics)

  • Familiarity with cybersecurity solutions and areas

  • Understanding of architecture concepts and techniques for systems, networks, operating systems, and associated programming languages

  • Knowledge of key cybersecurity standards and regulations, such as ISO 2700X, 62443, NIST, NIS, and French LPM

  • Expertise in network deployment (train communication system standpoint)

  • Experience with integrating networks (between Alstom networks and customer networks)

  • Ability to manage dataflow matrices between subsystems in external firewalls

  • Experience deploying ePo and syslog for standalone projects

  • Experience deploying IDS on-site


Things you’ll enjoy

Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career.

You’ll also:

  • Enjoy stability, challenges, and a long-term career free from boring daily routines

  • Collaborate with transverse teams and helpful colleagues

  • Contribute to innovative projects

  • Utilise our hybrid working environment

  • Steer your career in whatever direction you choose across functions and countries

  • Benefit from our investment in your development through award-winning learning programs

  • Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!

Important to note

As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63  countries we operate in. We’re committed to creating an inclusive workplace for everyone.

This advertiser has chosen not to accept applicants from your region.

Program Cybersecurity Manager

Bengaluru, Karnataka Alstom

Posted today

Job Viewed

Tap Again To Close

Job Description

At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, 80,000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

Could you be the full-time Program Cybersecurity Manager in (Bangalore) we’re looking for?

Your future role

Take on a new challenge and apply your comprehensive cybersecurity expertise in a new cutting-edge field. You’ll work alongside dedicated, innovative, and forward-thinking teammates.

You'll lead the charge in safeguarding our products and solutions, ensuring they meet the highest cybersecurity standards. Day-to-day, you’ll work closely with teams across the business (Engineering, Product Development, Legal), strategize cybersecurity approaches, and much more.

You’ll specifically take care of developing the Cybersecurity Management Plan, conducting Threat Modelling, and defining Cybersecurity Architecture and Requirements. Additionally, you will manage the evaluation of our Program’s cybersecurity level and provide pivotal support during cybersecurity audits.

We’ll look to you for:

  • Analysis of security needs and formulation of security objectives and strategies

  • Planning and integration of security activities within the development lifecycle

  • Expert guidance to teams on implementing cybersecurity features

  • Management of cybersecurity deliverables including quality, cost, and timeliness

  • Handling of vulnerabilities, cybersecurity issues, and action plans

  • Effective communication and reporting on cybersecurity status within the Program


  • All about you

    We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role:

  • Degree in Engineering or a related field

  • Experience or understanding of information technology and security

  • Knowledge of product security areas such as cryptography, network protection, and identity management

  • Familiarity with cybersecurity standards like ISO 2700X, IEC 62443, NIST

  • A cybersecurity certification such as GICSP, CISSP, GSEC, or CISM is desirable

  • Proven ability to manage quality, cost, and delivery of cybersecurity initiatives

  • Strong interdisciplinary collaboration skills


  • Things you’ll enjoy

    Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:

  • Enjoy stability, challenges and a long-term career free from boring daily routines

  • Work with cutting-edge security standards for rail signalling

  • Collaborate with cross-functional teams and supportive colleagues

  • Contribute to projects that redefine industry standards

  • Utilise our dynamic and innovative working environment

  • Steer your career in whatever direction you choose across functions and countries

  • Benefit from our investment in your development, through award-winning learning programs

  • Progress towards senior cybersecurity roles

  • Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)

  • You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!


    Important to note

    As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.


    Job Segment: Program Manager, Product Development, Manager, Management, Research

    This advertiser has chosen not to accept applicants from your region.

    Project Cybersecurity Manager

    Bengaluru, Karnataka Alstom

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    At Alstom, we understand transport networks and what moves people. From high-speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility, we offer our diverse customers the broadest portfolio in the industry. Every day, more than 80 000 colleagues lead the way to greener and smarter mobility worldwide, connecting cities as we reduce carbon and replace cars.

    Could you be the full-time Project Cybersecurity Manager in (Bangalore) we’re looking for?

    Your future role

    Take on a new challenge and apply your comprehensive cybersecurity expertise in a new cutting-edge field. You’ll work alongside dedicated and collaborative teammates.

    You'll safeguard our projects by establishing and managing cybersecurity activities. Day-to-day, you’ll work closely with teams across the business (Engineering, Operations, IT), manage system architectures related to cybersecurity requirements and much more.

    You’ll specifically take care of developing the Project Cybersecurity Management Plan, but also ensure compliance with security requirements and manage risk evaluations.

    We’ll look to you for:

  • Establishing and ensuring adherence to the Project Cybersecurity Management Plan

  • Distributing and ensuring compliance with applicable security requirements and regulations

  • Planning security activities and managing efficient system architecture design

  • Conducting cybersecurity risk analysis and managing project/business impacts

  • Reviewing deployment documents from a cybersecurity perspective

  • Defining and following up on action plans to resolve cybersecurity issues

  • Ensuring cybersecurity awareness is propagated to the Alstom team and suppliers


  • All about you

    We value passion and attitude over experience. That’s why we don’t expect you to have every single skill. Instead, we’ve listed some that we think will help you succeed and grow in this role:

  • Degree in Engineering or a related field

  • Experience or understanding of cybersecurity management and deployment of security technologies

  • Knowledge of cybersecurity risk analysis methods and industry standards (ISO 2700X, IEC 62443, NIST, etc.)

  • Familiarity with security products and protocols

  • A relevant certification (, GICSP, CISSP, GSEC, CISM)

  • Strong documentation and presentation skills

  • Proven ability to collaborate across functions and communicate effectively


  • Things you’ll enjoy Join us on a life-long transformative journey – the rail industry is here to stay, so you can grow and develop new skills and experiences throughout your career. You’ll also:

  • Enjoy stability, challenges and a long-term career free from boring daily routines

  • Work with cutting-edge security standards for rail signalling

  • Collaborate with transverse teams and helpful colleagues

  • Contribute to innovative projects that shape the future of mobility

  • Utilise our flexible working environment

  • Steer your career in whatever direction you choose across functions and countries

  • Benefit from our investment in your development, through award-winning learning programs

  • Progress towards leadership roles within the cybersecurity domain

  • Benefit from a fair and dynamic reward package that recognises your performance and potential, plus comprehensive and competitive social coverage (life, medical, pension)

  • You don’t need to be a train enthusiast to thrive with us. We guarantee that when you step onto one of our trains with your friends or family, you’ll be proud. If you’re up for the challenge, we’d love to hear from you!


    Important to note

    As a global business, we’re an equal-opportunity employer that celebrates diversity across the 63 countries we operate in. We’re committed to creating an inclusive workplace for everyone.


    Job Segment: Project Manager, Manager, Technology, Management

    This advertiser has chosen not to accept applicants from your region.

    Cyber Defense

    Bengaluru, Karnataka KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.
    -

    Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
    -
    This advertiser has chosen not to accept applicants from your region.

    Cyber Defense

    Mumbai, Maharashtra KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.
    -

    Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
    -
    This advertiser has chosen not to accept applicants from your region.

    IT and Cybersecurity Manager

    New Delhi, Delhi Larsen & Toubro

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

  • Hands On experience on Cisco (3560,3850,2960,9300)-Aruba (2930F,3810M,6100,6300F,6300M,
  • 6410,6200)-Arista Switches (7050SX,7050TX3), HP (Flex Fabric 5945,5500,2530) etc.

  • Hands on experience on Cisco and HP Routers (MSR1003,MSR4060) etc.
  • Hands on experience on Aruba central and PRTG, SolarWinds.
  • Engineered, and implemented LAN/WAN networks using variety of Hardware/Software.
  • Responsible for Troubleshooting of network issues.
  • Testing and debugging skills includes Wire shark and Log analysis.
  • Configuring and Troubleshooting Router, Switch .
  • Configuration of Cisco 3560,Nexus9K,3850 and 2960, HP and Chassis Switches. 
  • Configuration of Aruba, HP and Chassis Switches.
  • Configuring VLANs, STP, HSRP, Switch Port Security, EIGRP, OSPF, BGP and Static Route and have implemented almost of these protocols in the hierarchical networks.
  • Network Migration experience.
  • Security Audit expertise.
  • Develop and Update the network topology diagrams for all applicable customer sites and ensure standards.
  • Upgrade of Cisco Switches and Routers and Fortigate Firewall. 
  • Creation and Management of Cat3850, Cisco9300 Switch Stacks.
  • Troubleshooting STP, High CPU, HA static routing issues on Cisco, HP switches.
  • Create and manage Vlans/VTP/access ports/trunk.
  • Load Balancing Protocols: HSRP, VRRP.
  • Perform Troubleshooting end-to-end between the two devices.
  • Troubleshooting all errors (layer 1 & layer 2) and recovery.
  • Understanding and troubleshooting Layer 3 switching.
  • Configuring and troubleshooting BGP like establishing neighbor, creating prefix-list, advertising route etc. 
  • Aruba central deployed in cairn India ltd.
  • This advertiser has chosen not to accept applicants from your region.

    Information Systems & Cybersecurity Manager

    Hyderabad, Andhra Pradesh Cognitus Consulting

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    Responsibilities:

    Looking for a 10+ years of seasoned Information Systems Security Manager, who can Develop and implement robust security strategies and policies to protect the company's assets, employees and facilities. Assessing potential risks and vulnerabilities, investigating security breaches and reinforcing appropriate measures to mitigate them. Ensure to develop a Business continuity and Disaster recovery plans. Be versatile and take up hands on work as needed.

    ▪ Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk.

    ▪ Advise senior management C-Suite (CIO/CTO) on risk levels and security posture

    . ▪ Advise appropriate senior leadership or Authorizing Official of changes affecting the organization's cybersecurity posture.

    ▪ Collect and maintain data needed to meet system cybersecurity reporting.

    ▪ Communicate the value of IT security throughout all levels of the organization stakeholders.

    ▪ Ensure that security improvement actions are evaluated, validated, and implemented as required.

    ▪ Ensure that cybersecurity inspections, tests, and reviews are coordinated for the network environment.

    ▪ Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s).

    ▪ Evaluate and approve development efforts to ensure that baseline security safeguards are appropriately installed.

    ▪ Identify alternative information security strategies to address organizational security objectives.

    ▪ Identify IT security program implications of new technologies or technology upgrades.

    ▪ Interpret patterns of noncompliance to determine their impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.

    ▪ Manage the monitoring of information security data sources to maintain organizational situational awareness.

    ▪ Oversee the information security training and awareness program across the organization.

    ▪ Participate in an information security risk assessment during the Security Assessment and Authorization process.

    ▪ Prepare, distribute, and maintain plans, instructions, guidance, and standard operating procedures concerning the security of network system(s) operations.

    ▪ Provide system-related input on cybersecurity requirements to be included in statements of work and other appropriate procurement documents.

    ▪ Recognize a possible security violation and take appropriate action to report the incident, as required.

    ▪ Recommend resource allocations required to securely operate and maintain an organization's cybersecurity requirements.

    ▪ Supervise or manage protective or corrective measures when a cybersecurity incident or vulnerability is discovered.

    ▪ Track audit findings and recommendations to ensure that appropriate mitigation actions are taken.

    ▪ Promote awareness of security issues among management and ensure sound security principles are reflected in the organization's vision and goals.

    ▪ Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies.

    ▪ Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc.

    ▪ Assure successful implementation and functionality of security requirements and appropriate IT policies and procedures that are consistent with the organization's mission and goals.

    ▪ Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs)

    ▪ Continuously validate the organization against policies/guidelines/procedures/regulations/laws to ensure compliance.

    ▪ Good understanding of data backup and recovery.

    ▪ Good understanding of business continuity and disaster recovery continuity of operations plans.

    ▪ Knowledge of the organization's enterprise IT goals and objectives.

    ▪ Familiarity with SOX, ISO, NIST audits is a plus

    Core Competencies:

    ▪ Business Continuity & Disaster Recovery Planning

    ▪ Enterprise Architecture

    ▪ Information Systems/Network Security

    ▪ Policy Management

    ▪ Risk Management

    ▪ Technology Awareness ▪ Vulnerabilities Assessment

    ▪ Threat Detection & Analysis Education:

    Master’s degree in information systems/Cybersecurity.

    This advertiser has chosen not to accept applicants from your region.
    Be The First To Know

    About the latest Cybersecurity manager Jobs in India !

    Analyst - Cyber Defense

    Pune, Maharashtra KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

    Preferred Certifications: CEH, ECSA, OSCP, CISSP, CCSK, OCSE, CCSP, AWS Security

    • Desired skill set:

    1. Strong understanding of IT security standards and frameworks (OWASP, NIST, CIS)

    2. Strong understanding of security risks in networks and application platforms

    3. Strong understanding of network security, infrastructure security and application security

    4. Strong understanding of OSI, TCP/IP model and network basics

    5. Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming

    6. Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms

    7. Broad knowledge of security technologies for applications, databases, networks, servers, and desktops

    8. Solid technical skills in both information security architecture and penetration testing and ability to assess testing tools and deploy the right ones.

    9. Scripting and programming experience is beneficial

    10. Ability to perform manual penetration testing

    11. Experience in Application Security Testing (Web, Mobile & ERP (SAP)), or related functions Vulnerability Assessment, Penetration testing

    12. Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors

    13. Conduct security research on the latest emerging advanced persistent threats (APTs), malware, and other security developments to assist in enterprise security efforts. Apply this security research into assessments.

    14. Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.

    15. Train team members and colleagues on the latest cybersecurity tactics, techniques, and procedures (TTPs) to grow the skill of the firm

    16. Understanding of various security technologies including end point security, perimeter security, advanced threat protection, malware defense and security management

    17. Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

    18. Good Understanding of OWASP top 10 and mitigation techniques

    19. Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

    20. Database testing: MySQL, Oracle, NoSQL

    21. Understanding of cyber security management, cyber analytics, security intelligence platforms and threat intelligence frameworks

    22. Writing business proposals and response to client RFP/ RFIs

    23. Identifying business opportunities and lead delivery and program management for large cyber security programs

    24. Delivery team and client relationship management

    25. Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .


    Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
    /
    This advertiser has chosen not to accept applicants from your region.

    Consultant - Cyber Defense

    Mumbai, Maharashtra KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Jaipur, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.

    Preferred Certifications: CEH, ECSA, OSCP, CISSP, CCSK, OCSE, CCSP, AWS Security

    Desired skill set:

    1. Strong understanding of IT security standards and frameworks (OWASP, NIST, CIS)

    2. Strong understanding of security risks in networks and application platforms

    3. Strong understanding of network security, infrastructure security and application security

    4. Strong understanding of OSI, TCP/IP model and network basics

    5. Demonstrate technical penetration testing skills on IT infrastructure, web applications, mobile platforms and Red teaming

    6. Strong technical skills: Information security, network security, Windows security, UNIX/Linux security, web and mobile application security, Cloud platforms

    7. Broad knowledge of security technologies for applications, databases, networks, servers, and desktops

    8. Solid technical skills in both information security architecture and penetration testing and ability to assess testing tools and deploy the right ones.

    9. Scripting and programming experience is beneficial

    10. Ability to perform manual penetration testing

    11. Experience in Application Security Testing (Web, Mobile & ERP (SAP)), or related functions Vulnerability Assessment, Penetration testing

    12. Perform penetration testing of various thick client software, web applications, and communications infrastructure to assist in hardening the cybersecurity posture against malicious actors

    13. Conduct security research on the latest emerging advanced persistent threats (APTs), malware, and other security developments to assist in enterprise security efforts. Apply this security research into assessments.

    14. Perform technical writing to communicate the preparation, testing, and recommendation phases for various security tests. Work with stakeholders to remediate system vulnerabilities.

    15. Train team members and colleagues on the latest cybersecurity tactics, techniques, and procedures (TTPs) to grow the skill of the firm

    16. Understanding of various security technologies including end point security, perimeter security, advanced threat protection, malware defense and security management

    17. Expertise in the phases of penetration testing. Familiarity with Kali Linux distribution and the associated penetration testing tools suite. Experience in penetration testing simulations like Hack the Box or Capture the Flag exercises considered a plus.

    18. Good Understanding of OWASP top 10 and mitigation techniques

    19. Experience in performing web application security assessments using hands on techniques for identifying SQL injections, XSS, Security Misconfiguration, CSRF, authentication/ authorization issues

    20. Database testing: MySQL, Oracle, NoSQL

    21. Understanding of cyber security management, cyber analytics, security intelligence platforms and threat intelligence frameworks

    22. Writing business proposals and response to client RFP/ RFIs

    23. Identifying business opportunities and lead delivery and program management for large cyber security programs

    24. Delivery team and client relationship management

    25. Experience on both commercial, open source tools and frameworks but not limited: Burpsuite, Metasploit, Core-Impact, Kali-Linux, AppScan, WebInspect, SSLScan, Soap UI Pro, SonarQube, Qualys, Nikto, Nessus, nmap, sqlmap, OWASP ZAP .


    Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
    BE/ BTech
    This advertiser has chosen not to accept applicants from your region.

    Analyst - Cyber Defense

    Mumbai, Maharashtra KPMG India

    Posted today

    Job Viewed

    Tap Again To Close

    Job Description

    About KPMG in India

    KPMG entities in India are professional services firm(s). These Indian member firms are affiliated with KPMG International Limited. KPMG was established in India in August 1993. Our professionals leverage the global network of firms, and are conversant with local laws, regulations, markets and competition. KPMG has offices across India in Ahmedabad, Bengaluru, Chandigarh, Chennai, Gurugram, Hyderabad, Jaipur, Kochi, Kolkata, Mumbai, Noida, Pune, Vadodara and Vijayawada.

    KPMG entities in India offer services to national and international clients in India across sectors. We strive to provide rapid, performance-based, industry-focused and technology-enabled services, which reflect a shared knowledge of global and local industries and our experience of the Indian business environment.Equal employment opportunity information

    KPMG India has a policy of providing equal opportunity for all applicants and employees regardless of their color, caste, religion, age, sex/gender, national origin, citizenship, sexual orientation, gender identity or expression, disability or other legally protected status. KPMG India values diversity and we request you to submit the details below to support us in our endeavor for diversity. Providing the below information is voluntary and refusal to submit such information will not be prejudicial to you.
  • Monthly VAPT planning, scan scheduling, scanning and reporting.
  • Review of VAPT report and provided necessary comments
  • Conduct vulnerability Compliance check/Revalidation
  • Track vulnerabilities in all technologies on a continuous basis in view of the Cyber Security Advisories.
  • VA reporting, remediation support, tracking and dashboard reporting.
  • Monitoring the progress of scanning and troubleshooting the failed scans in coordination with PIM/ server admin/app admin teams.
  • Coordination with application and infra teams to provide continuous inputs. 8. Timely communicate to hardware and software teams the MIS reporting of vulnerabilities along with recommendation
  • False positive review and exception management.
  • Adhoc request handling, management and Vulnerability Management reporting.
  • Availability of resources, as per the VA and patching schedule, for off office hours as well as weekends as per program requirement.
  • Periodical review and updation of details of servers/devices
  • Maintain an up-to date plan for deploying and managing patch management
  • Implement patches as per approved deployment strategy
  • Regularly patch the infrastructure and software in order to be complaint to the Client's policy and guidelines, and advisories from regulatory, information security and statutory authorities
  • Notify sufficiently in advance about patching (including emergency patching) and seek approval from the Client, such that there is no disruption in services to the Client and its customers
  • The vulnerabilities reported/ identified during the project/ application go-live to be remediated as per the Information Security policy of the Client
  • Carry out patch governance, ongoing deployment tracking and compliance thereof
  • Carry out VAPT remediation including configuration and hardening level changes, security updates and patching
  • Conduct continuous review and collection of patches released and vulnerabilities identified including zero day vulnerabilities, and its applicability with respect to the Asset Inventory
  • Review existing patch management process and provide recommendations
  • Prepare Patch plan for OS/DB Server/End points, its execution and reporting, attend to hotfix
  • Identification of Top 10 critical & high patches for OS and application software 11
  • Plan, prioritize (on the basis of criticality of application, tier rating etc )schedule and carryout continuous patching/ support for Windows, Linux and AIX platform, Database, Middleware and all other various software components and Development tools where vulnerabilities are reported during VAPT scanning in close co-ordination and follow-up with respective Application, Infra, Network and Security teams
  • Help in implementing workaround provided by respective OEM for the reported vulnerability
  • Coordination for downtime to complete the schedule patching
  • Take necessary approval from Client for shutdown, if required, for patch or update implementation
  • Schedule shutdown of production system and inform respective application users
  • Implement patches as per approved deployment strategy
  • Testing of patches before rollout and provide observations
  • Rollback efforts in case of issues
  • A practical and up-to date roll back plan has to be adopted in case of failures
  • Follow up and co-ordinate with OEM/3rd party support vendors for patch deployment
  • Coordination with OEM/ Vendor in case of any dependency
  • Coordination and patching of app related vulnerabilities with App Support
  • The technical resources should be competent to Handle/ Integrate/Implement/Test patches within Client's stipulated time 22
  • Catalogue updation for different flavors of operating systems like Windows/RHEL/AIX/SOLARIS and all other supporting software's
  • Assist, Develop, Manage and Monitor suitable Policies, Procedures and deployment strategy for Patch Management
  • Raise Change Management for deployment of patches or updates
  • Capability to identify the devices where patches are applied but not yet activated (pending restart) And carrying out other related activities
  • Prepare and maintain Standard Operating Procedure (SOP) document pertaining to the remidiation services
  • This advertiser has chosen not to accept applicants from your region.
     

    Nearby Locations

    Other Jobs Near Me

    Industry

    1. request_quote Accounting
    2. work Administrative
    3. eco Agriculture Forestry
    4. smart_toy AI & Emerging Technologies
    5. school Apprenticeships & Trainee
    6. apartment Architecture
    7. palette Arts & Entertainment
    8. directions_car Automotive
    9. flight_takeoff Aviation
    10. account_balance Banking & Finance
    11. local_florist Beauty & Wellness
    12. restaurant Catering
    13. volunteer_activism Charity & Voluntary
    14. science Chemical Engineering
    15. child_friendly Childcare
    16. foundation Civil Engineering
    17. clean_hands Cleaning & Sanitation
    18. diversity_3 Community & Social Care
    19. construction Construction
    20. brush Creative & Digital
    21. currency_bitcoin Crypto & Blockchain
    22. support_agent Customer Service & Helpdesk
    23. medical_services Dental
    24. medical_services Driving & Transport
    25. medical_services E Commerce & Social Media
    26. school Education & Teaching
    27. electrical_services Electrical Engineering
    28. bolt Energy
    29. local_mall Fmcg
    30. gavel Government & Non Profit
    31. emoji_events Graduate
    32. health_and_safety Healthcare
    33. beach_access Hospitality & Tourism
    34. groups Human Resources
    35. precision_manufacturing Industrial Engineering
    36. security Information Security
    37. handyman Installation & Maintenance
    38. policy Insurance
    39. code IT & Software
    40. gavel Legal
    41. sports_soccer Leisure & Sports
    42. inventory_2 Logistics & Warehousing
    43. supervisor_account Management
    44. supervisor_account Management Consultancy
    45. supervisor_account Manufacturing & Production
    46. campaign Marketing
    47. build Mechanical Engineering
    48. perm_media Media & PR
    49. local_hospital Medical
    50. local_hospital Military & Public Safety
    51. local_hospital Mining
    52. medical_services Nursing
    53. local_gas_station Oil & Gas
    54. biotech Pharmaceutical
    55. checklist_rtl Project Management
    56. shopping_bag Purchasing
    57. home_work Real Estate
    58. person_search Recruitment Consultancy
    59. store Retail
    60. point_of_sale Sales
    61. science Scientific Research & Development
    62. wifi Telecoms
    63. psychology Therapy
    64. pets Veterinary
    View All Cybersecurity Manager Jobs