567 Information Security jobs in Bengaluru
Sr. Cloud Solution Architect - Security
Posted 2 days ago
Job Viewed
Job Description
As a Cloud Solution Architect, you will guide the development of business solutions, provide deep technical insights, and accelerate the growth of Microsoft Tech priorities. You will work closely with partners to understand their technical requirements and business objectives, and guide them through architectural design sessions, developing proof of concepts, and help them transition from legacy systems to modern cloud environments, ensuring that their solutions are optimized for performance and cost-efficiency.
Join our team as a Cloud Solution Architect and play a pivotal role in guiding our most significant partners to designing and implementing innovative scalable, secure, and efficient cloud architectures that meet market needs. By leveraging your skills in technical leadership, cloud computing, software development, problem solving and systems architecture, you will drive business impact by enabling digital transformation, optimizing performance, and driving innovation through the effective use of cloud technologies.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others, and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
**Responsibilities**
As a Partner Solution Architect (PSA), you will serve as the deep technical SME to partners' technical force & own the partner's technical strategy plan for their Cloud Solution Area (CSA). Withing your responsibilities are:
+ Guide Solution Development & Activation - You'll lead the development and activation of new or enhanced partner offerings that align with Microsoft Cloud priorities. Your focus will be on ensuring these solutions are robust, scalable, secure, and tailored to meet evolving customer needs.
+ Empower Innovation - You'll run technical innovation workshops, tech briefings, and envisioning sessions to build technical intensity across partner teams. By collaborating with engineering and product teams, you'll help accelerate the adoption of emerging technologies and shape partner offerings that align with both business goals and technical requirements.
+ Strategic Sales Enablement - You'll play a key role in activating transformational deals by providing architectural guidance, resolving technical blockers, and enhancing solution design. Your work will directly contribute to workload consumption and revenue impact.
+ Champion Technical Excellence - You'll guide partners through architecture design sessions, proof-of-concepts, and MVP builds. You'll ensure that solutions follow Microsoft's Cloud and AI best practices and are optimized for performance, scalability, and security.
+ Thought Leadership & Stakeholder Management - You'll build long-term engagements with strategic partners, influencing their adoption of Microsoft technologies. You'll develop deep technical relationships with CXOs and foster executive alignment to support joint success.
+ Partner Enablement & Business Acumen - You'll coach broader partner technical teams to ensure pre-sales, deployment, and consumption are embedded in solution development. You'll help partners build resilience to technical challenges, navigate competitive landscapes, and translate technical concepts into business value.
**Qualifications**
**Required (RQs)**
+ Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, or related field AND 10+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting
+ OR master's degree in computer science, Information Technology, Engineering, Business or related field AND 6+ years technical consulting, technical consultative selling, product development, or related
+ OR equivalent experience.
+ Proven experience in cloud architecture, solution design, and partner enablement, particularly in large-scale or global engagements
+ Demonstrated ability to lead technical innovation workshops, architecture reviews, and build-to-consume engagements with partners
+ 10 + years of related experience in technology IP solutions or services development, with a deep understanding of digital transformation business drivers, cloud platforms, and emerging cloud trends like generative AI (ARTIFICIAL INTELLIGENCE) and SaaS (Software as a Service) services
+ Strong background and in-depth knowledge of cloud technologies, with a focus on Microsoft's cloud offerings (Azure, Dynamics 365, Microsoft 365)
+ M365 and Azure Security platform value and multi-tenancy management
+ Security, governance, data access, and incident response best practices
+ Managed security services and modern SOC architecture and best practicesSecurity Well Architected Framework (WAF)
**Preferred Qualifications (PQs)**
+ Bachelor's Degree in Computer Science, Information Technology, Engineering, Business, or related field AND 8+ years experience in cloud/infrastructure technologies, information technology (IT) consulting/support, systems administration, network operations, software development/support, technology solutions, practice development, architecture, and/or consulting
+ OR Master's Degree in Computer Science, Information Technology, Engineering, Business, or related field AND 10+ years experience in cloud/infrastructure technologies, technology solutions, practice development, architecture, and/or consulting
+ OR equivalent experience
+ 10+ years experience working in a customer/partner facing role (e.g., internal and/or external)
+ 10+ years solution or services sales experience
+ OR Experience selling security solutions to CISO, CDO, CTO and other key C-level stakeholders.
+ OR Industry experience and application of security solutions within Retail Healthcare, Manufacturing, etc. is a plus
+ IR Technical passion with good understanding of cloud security technologies - Threat protection (Endpoint security, E-mail security, Incident Response, etc.), Kill Chain, CNAPP, SIEM, Multi-Cloud Security, Identity and Access management,
+ Experience with competitive Security solutions (e.g. Palo Alto, Cisco, CrowdStrike, etc.) is a plus
#IPS #WSS
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations ( .
Senior Information Security Engineer-PKI, Venafi, Cryptography, Certificate Management
Posted 3 days ago
Job Viewed
Job Description
Be a contributing member of the collaborative team responsible for Optum's Digital Certificate Services. This position will be responsible for ensuring the confidentiality, integrity, and availability of the enterprise certificate lifecycle management platform along with the related core capabilities of ensuring domain validation and certificate operations
including issuance, renewal, and revocation are always available for applications and platforms. Collaborate with other IT teams to drive certificate automation and other certificate management best practices. Provide operational support in the day-to-day tasks involved with providing a centralized, enterprise certificate management platform.
**Primary Responsibilities:**
+ Provide operations support in the day-to-day tasks of managing certificates using Venafi Data Center Protect
+ Engineer and develop tactical and strategic solutions to improve and automate certificate management
+ Engineer and drive forward new initiatives that supports and enhance Certificate Lifecycle Management
+ Provide innovative solutions to automate repetitive operational tasks
+ Analyze, design, develop and deploy integrations to help adopt Venafi products in customer environments
+ Participate as an independent contributor within an agile based team
+ Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so
**Required Qualifications:**
+ 4+ years of PKI, certificate management, or related experience
+ Experience with certificate lifecycle management platforms, with emphasis on Venafi
+ Scripting and automation experience leveraging Powershell, Python, or other scripting languages
+ Understanding of X.509 certificates and general certificate management processes
+ Serve as a subject matter expert regarding certificate management operation for internal teams
+ Ability to participate in on call rotation
**Preferred Qualifications:**
+ Undergraduate degree in applicable area of expertise or equivalent experience
+ CISSP or other security related certification
+ Cloud Infrastructure experience in any of the major CSP's including MS Azure, AWS, or GCP
+ Identity and Access Management experience
_At UnitedHealth Group, our mission is to help people live healthier lives and make the health system work better for everyone. We believe everyone-of every race, gender, sexuality, age, location and income-deserves the opportunity to live their healthiest life. Today, however, there are still far too many barriers to good health which are disproportionately experienced by people of color, historically marginalized groups and those with lower incomes. We are committed to mitigating our impact on the environment and enabling and delivering equitable care that addresses health disparities and improves health outcomes - an enterprise priority reflected in our mission._
#Nic #NJP
Principal Security Specialist

Posted 3 days ago
Job Viewed
Job Description
Job Description:
To drive improvements in the end-to-end product/system lifecycle spanning the whole SDLC and post launch operations, covering major strategic customer-facing products and internally developed colleague-facing applications. To work with security champions to develop a strong security culture and capability and to evolve the security champions program as a whole. To ensure that new product/system releases are secure and that vulnerabilities discovered in live products and systems are quickly and effectively addressed.
***This is a hybrid role - three days per week in our Bangalore office.***
Key Responsibilities:
Responsibilities
1. Working with Security Champions to develop a strong security capability in teams and improving the effectiveness of the overall Security Champion program
2. Driving continual improvement in the secure software development lifecycle and supporting our drive to a modern DevSecOps approach
3. Acts as the main point of contact on security issues for Product Delivery and EAD teams on major strategic groups of products/systems
4. Assessing major strategic groups of Sage products, application or systems to identify security weaknesses and creating improvement plans where required
5. Supporting security compliance as it relates to assigned products
6. Identifies the need for new tools and vendors and leads their evaluation
7. Drives significant improvement in key processes/standards and designs and implements new processes/standards
8. Contributes to performance evaluation and technical mentoring of junior team members
9. Provides technical security leadership for significant projects or workstreams
10. Active contributor to relevant industry bodies, conferences, open-source projects etc.
Skills & experience
1. Significant experience in implementing security in the software development lifecycle
2. Experience in implementing security in public cloud based SaaS applications
3. Proficiency in English - written and verbal
4. Experience of working with geographically dispersed teams
5. Experience working in an agile, DevOps/DevSecOps environment
6. Experience in security operations
7. Experience of formal compliance frameworks (e.g. SOC, ISO27001, PCI or similar)
8. Relevant professional security qualification such a CISSP, CSSLP or similar
9. Relevant degree and >8 years commercial experience
#LI-RS2
Function:
Global Information Security
Country:
India
Office Location:
Bangalore
Work Place type:
Hybrid
Advert
Working at Sage means you're supporting millions of small and medium sized businesses globally with technology to work faster and smarter. We leverage the future of AI, meaning business owners spend less time doing routine tasks, like entering invoices and generating reports, and more time pursuing their ambitions.
Our colleagues are the best of the best. It's why we were awarded 2024 Best Places to Work by Glassdoor. Because to achieve extraordinary outcomes, we need extraordinary teams. This means infusing Sage with people who knock down barriers, continuously innovate, and want to experience their potential.
Learn more about working at Sage:sage.com/en-gb/company/careers/working-at-sage/
Watch a video about our culture:youtube.com/watch?v=qIoiCpZH-QE
We celebrate individuality and welcome you to join us if you embrace all backgrounds, identities, beliefs, and ways of working. If you need support applying, reach out
Learn more about DEI at Sage:sage.com/en-gb/company/careers/diversity-equity-and-inclusion/
Equal Employment Opportunity (EEO)
Sage is committed to Equal Employment Opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities.
In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Sage will be based on merit, qualifications, and abilities. Sage does not discriminate in employment opportunities or practices on the basis of race, color, religion, sex, national origin, age, protected disability, veteran status, sexual orientation, gender identity, genetic information, or any other characteristic protected by applicable law.
Sr. Cloud Solution Architect - Security
Posted 3 days ago
Job Viewed
Job Description
In this role you will adapt business models, plans, and solutions to insights. Act as the voice of the customers (VOC)/partners across communities to add and prioritize. Leverages and champions an existing architecture approach to achieve agreed commitments to the customer/partner. Demonstrate and prove solutions capability and value. Apply broad technical knowledge across various architecture solutions to meet requirements and resolve identified constraints. Lead customer/partner projects that implement technical architecture. Identify, escalate, and work to resolve technical blockers and route non-technical issues for removal. Adapt methodology and apply governance to minimize business and technical risks. Generate new ideas for changes and improvements. Develop and expand existing impactful relationships with stakeholders. Respectfully challenge customers/partners when going in the wrong direction and escalate appropriately. Identify Microsoft's strengths over competitive solutions to convince customers of solution. Share ideas, insight, and strategic, technical input with internal teams using a thorough knowledge of specific Microsoft products and their context in the competitive landscape. Participate in external architect community events and share learnings with the internal team. Lead architecture design, resiliency reviews, and technical optimization that result in production deployment application and increase customer usage/Azure Consumed Revenue. The CSA drives delivery execution through preparedness, precision delivery, overall utilization, and high customer satisfaction in a cost-efficient manner.
Microsoft's mission is to empower every person and every organization on the planet to achieve more. As employees we come together with a growth mindset, innovate to empower others and collaborate to realize our shared goals. Each day we build on our values of respect, integrity, and accountability to create a culture of inclusion where everyone can thrive at work and beyond.
**Responsibilities**
We are looking for a highly motivated and passionate Cloud Solution Architect (CSA) to drive customer transformation in our Solutions. You will own the customer engagements, including architecture, implementation, and production.
The ideal candidate will have experience in customer-facing roles and success in leading in-depth technical architecture discussions with CISOs, senior customer executives, Architects, IT Management, and Developers to drive value to our customers and is open to travel to customer site as needed by business.
**Key responsibilities include:**
+ **Understanding Customer/Partner Technical Environment** ( _Insights about Customer/Partner and Industry_ ): Gather customer/partner insights (e.g., feedback around technical preferences, environments, business needs, competitive landscape), and map architecture and digital transformation solutions to customer/partner business outcomes. Adapt business models, plans, and solutions to insights.
+ **Understanding Customer/Partner Technical Environment** ( _Internal Advocacy_ ): Act as the voice of the customer (VOC)/partner by driving new feedback, gaps, blockers, insights, resources, etc. across communities to track, add, and prioritize, using established channels (e.g., UAT/TFT).
+ **Architecture Design and Deployment** ( _Architecture Proposals)_ : Receive and synthesize data about customer/partner business and technical requirements, address them with technical architecture(s), demonstrate and prove those solutions capability and business value through design collaboration sessions with the customer/partner.
+ **Architecture Design and Deployment** ( _Requirements and Constraints_ ): Apply broad technical knowledge across various of architecture solutions to meet business and information technology (IT) requirements and resolve identified technical constraints. Help to shape and enhance customers' requirements.
+ **Architecture Design and Deployment** ( _Resolving Blockers_ ): Identify, escalate, and work to resolve technical blockers (e.g., changing configurations, sample coding) to accelerate architecture implementations and routes non-technical issues for removal by the appropriate party.
+ **Trusted Advisor** ( _Challenger Mindset_ ): Respectfully challenge customers/partners when going in the wrong direction and escalate appropriately.
+ **Trusted Advisor** ( _Competitor Insights/ Differentiated Value Proposition):_ Understand the competitor's architecture solutions and identify Microsoft's strengths over competitive solutions to drive conversations with customers/partners and convince them of solution.
+ **Customer Usage:** Lead architecture design, resiliency reviews, and technical optimization that result in production deployment application and increase customer business value. Drive efforts to ensure that the customer's environment and applications are well-architected.
+ **Customer Satisfaction** - Deliver positive Customer Satisfaction, and become trusted advisors to customers by leveraging solution area expertise to enable defined Customer Success Plan outcomes.
**Qualifications**
**Language Qualification:**
**English Language:** Fluent in reading, writing and speaking with strong presentation skills.
**Technical Expertise:**
At least 12+ years of experience working directly with customers in any of the following: providing technical readiness and training, delivery of support services, on-premises and remote technical support, solution development, account management, technical requirements gathering.
At least 6+ years of deep technical security related experience with any of the following security domain technologies:
**Azure and Cloud Security Engineering**
+ Azure Security Infrastructure, Databases, Networking, Virtual Machines
+ Azure Secrets and Keys
+ Azure Identity
+ Troubleshooting of data logging and audit, security monitoring
+ Azure Governance and Compliance
+ Microsoft Defender for Identity
+ Microsoft Defender for Cloud
+ Microsoft Sentinel
+ Microsoft Client/Server Operating Systems Security, including related services (eg Certificate Authority, authentication/authorization mechanisms, encryption, health attestation)
+ Microsoft Security recommendation experience (eg Securing Privileged Access, Credential Theft Mitigations)
+ Azure Security Services (eg Azure Advanced Threat Protection, Azure Information Protection, Azure Security Center, Azure Log Analytics)
+ Security Threat Landscape experience including advanced attack vectors and tools (eg Pass the Hash, Golden Ticket, ransomware)
**Infrastructure Security experience with competitive cloud security technologies, cloud security platforms, or any of the following:**
+ Active Directory
+ Azure Active Directory, Entra ID
+ Cloud workload protection
+ Threat protection
+ WAF (Web Application Firewall)
+ Stateful firewall. (NG Firewall)
+ Data encryption and protection key services.
+ SIEM, and Cloud Security Analytics
+ Security Orchestration, Automation, and Response (SOAR)
+ Security Operation Center
+ Identity and Access Management
**Microsoft 365 & Security**
+ Microsoft Defender for Office 365
+ Microsoft Defender for Cloud Apps
+ Microsoft Defender for Endpoint
+ Microsoft Purview: Data loss prevention (DLP), Information Protection, Insider Risk Management, Privileged Access Management, Data Security Posture Management (DSPM), Compliance: Records Management, Audit / eDiscovery, Data Life Cycle Management
+ Fundamentals of SharePoint & Exchange
+ Advanced Hunting
+ Simulation Training
+ Threat Analytics
+ Investigations
**Modern Management - Mobility and Security Solutions in any of the following:**
+ Microsoft Intune; Autopilot, Desktop Analytics, Conditional Access, identity governance, Azure Active Directory (AAD), Microsoft Cloud App Security (MCAS); Advanced Threat Analytics; Microsoft Endpoint Configuration Manager.
+ Microsoft Defender XDR
**Endpoint Management Security related technologies:**
+ Microsoft Enterprise Mobility Suite + Security (EMS),
+ Active Directory/Identity
+ Windows Defender Advanced Threat Protection (D-ATP)
+ Office 365 Advanced Threat Protection
+ Other endpoint security solutions and comprehensive threat protection technologies.
**Other Qualifications:**
+ Ability to host CISO workshops and partner with customer Security teams to craft end to end Enterprise Security Strategy & Roadmap.
+ Ability to work independently and collaboratively working in a fast-paced environment where technology and customers' requirements can change regularly
+ Demonstrated aptitude for providing extraordinary customer service, influence, and impact while problem solving and building Customer & Partner relationships.
+ Possess a passion for continuous learning, strong problem-solving skills, critical thinking and good judgement
+ Ability to apply product & technology knowledge to improve Microsoft products and the customer experience
+ Solid understanding of client/server, networking, Network Security and Internet technologies fundamentals.
+ Technical Delivery and Customer facing presentation skills with a high degree of comfort with both large and small audiences
+ Must have the ability to take on internal initiatives to create services opportunities, and work in a fast-paced environment while balancing multiple demands, addressing shifting priorities, and maintaining focus
**Experience Profile:**
+ 12+ years of IT experience, with **minimum 5 years of experience in Infrastructure/Cloud Security** related profile, experience in designing, delivering or managing information security services
**Any of the below certifications**
+ Certification (Any one of the certifications - Minimum)
+ SC-100 Cybersecurity Architect Certification
+ SC-200 Security Operations Analyst Associate
+ SC-300 Identity and Access Administrator Associate
+ SC-400 Information Protection Administrator Associate
+ SC-900 Security, Compliance, and Industry Fundamentals
+ CISA, CISM, ITIL, CISSP, CISM, CCSK, CCSP, CCAK, CIRSC
Knowledge, Skills and Abilities
+ The ability to teach, tailor, and take control of the technical sales process to drive specific customer actions and disrupt conventional thinking.
+ Knowledge of the cloud platform, productivity platform, identity, and multi-geography deployment strategy.
+ The ability to explain and advise on cloud security considerations, capabilities, and tools across software as a service (SaaS), platform as a service (PaaS), and infrastructure as a service (IaaS).
+ The ability to apply ingenuity, inventiveness, and imagination to the inclusive design and construction of a product, service, program, or initiative.
+ The ability to speak and understand English when giving instructions and directions, and when talking with colleagues, managers, and others for work matters.
+ The ability to lead customer conversations on competitive cloud differentiation in compelling customer terms. This includes the ability to lead the analysis, planning, and execution of cloud migration to drive successful transitions to the cloud.
+ The ability to make a verbal message understood and to receive/understand messages during in-person or remote (e.g., telephone) interactions.
+ The ability to identify problems and review related information to develop and evaluate options and implement solutions.
Microsoft is an equal opportunity employer. Consistent with applicable law, all qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations ( .
Network Security Architect - Detection & Protection
Posted 3 days ago
Job Viewed
Job Description
Applied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and advanced display in the world. We design, build and service cutting-edge equipment that helps our customers manufacture display and semiconductor chips - the brains of devices we use every day. As the foundation of the global electronics industry, Applied enables the exciting technologies that literally connect our world - like AI and IoT. If you want to push the boundaries of materials science and engineering to create next generation technology, join us to deliver material innovation that changes the world.
**What We Offer**
Location:
Bangalore,IND
You'll benefit from a supportive work culture that encourages you to learn, develop, and grow your career as you take on challenges and drive innovative solutions for our customers. We empower our team to push the boundaries of what is possible-while learning every day in a supportive leading global company. Visit our Careers website to learn more.
At Applied Materials, we care about the health and wellbeing of our employees. We're committed to providing programs and support that encourage personal and professional growth and care for you at work, at home, or wherever you may go. Learn more about our benefits ( .
We are seeking a Network Security Architect to lead the design, deployment, and optimization of advanced network detection and protection capabilities across our enterprise. This individual will play a key role in enabling threat-informed defense strategies and ensuring malicious activity is detected and mitigated before it can cause impact.
This is a hands-on, strategic role-ideal for a seasoned security architect with deep expertise in network-layer defenses, strong architectural thinking, and experience contributing to complex investigations and incident response efforts.
You'll lead efforts to identify where and how we collect network telemetry to support threat detection and architect smart, effective defenses across our hybrid environment. This includes recommending the placement and configuration of technologies such as NDR sensors, SWG, SSE, API gateways, and NGFWs-based on risk, threat modeling, and telemetry value.
You'll also play a key role in supporting threat hunting efforts, particularly at the network layer-leveraging flow analysis and telemetry insights to identify potential gaps or attacker behavior.
**Key Responsibilities**
+ Serve as the network detection strategy lead-identifying where and how we collect network telemetry to support threat detection.
+ Ensure telemetry is strategically collected to support detection, investigation, and threat hunting across cloud and on-prem environments.
+ Architect and optimize network security threat detection technologies, including:
+ NDR and NGFWs
+ SWG and/or SSE
+ API gateways
+ DDoS protection platforms
+ WAF and RASP solutions
+ Serve as the technical lead and escalation point for network detection and protection engineering.
+ Develop and maintain detection logic informed by MITRE ATT&CK and current adversary tactics.
+ Partner with CTI and purple teams to simulate and detect real-world attack techniques and validate the effectiveness of the network detection and protection toolset.
+ Collaborate with the SOC to optimize telemetry from network and enterprise services for threat detection (e.g., SIEM, NDR, proxy/firewall logging).
+ Support Tier 3 incident response, especially for network-centric attacks or evasive techniques.
+ Conduct assessments, audits, and configuration reviews of network security platforms.
+ Lead or guide cross-functional security projects aimed at enhancing enterprise detection maturity.
**Required Qualifications**
+ Bachelor's degree in Cybersecurity or a related field.
+ 7+ years of experience in security engineering with strong expertise in network detection and protection.
+ At least one of the following (or similar) certifications: CCNA, PCNSA, GCIA, GCTI, OSCP, Security+, CISSP
+ Proven experience architecting secure network defenses for large, complex organizations.
+ Strong understanding of MITRE ATT&CK, adversary behaviors, and detection engineering principles.
+ Experience tuning and optimizing SIEM, NDR, NGFWs, or security analytics platforms.
+ Hand-on experience with NDR, NGFWs, SWG/SSE, Netflow & packet analysis, threat hunting, and log correlation techniques (L3-L7).
+ Familiarity with DDoS protection platforms (e.g., Azure, AWS, or Google native services).
+ Demonstrated ability to lead technical investigations and collaborate across disciplines.
**Preferred Qualifications**
+ At least two of the following (or similar) certifications: CCNA, PCNSA, GCIA, GCTI, OSCP, Security+, CISSP
+ Experience with WAF, API Gateways, and DDos protection platforms
+ Familiarity with NIST CSF and CIS Controls.
+ Experience working in or supporting security for manufacturing or industrial organization
**Additional Information**
**Time Type:**
Full time
**Employee Type:**
Assignee / Regular
**Travel:**
Yes, 10% of the Time
**Relocation Eligible:**
Yes
Applied Materials is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, national origin, citizenship, ancestry, religion, creed, sex, sexual orientation, gender identity, age, disability, veteran or military status, or any other basis prohibited by law.
Senior Information Security Engineer - VAPT, Thick client application

Posted 4 days ago
Job Viewed
Job Description
Serving thousands of enterprise customers around the world including 45% of Fortune 500 companies, Zscaler (NASDAQ: ZS) was founded in 2007 with a mission to make the cloud a safe place to do business and a more enjoyable experience for enterprise users. As the operator of the world's largest security cloud, Zscaler accelerates digital transformation so enterprises can be more agile, efficient, resilient, and secure. The pioneering, AI-powered Zscaler Zero Trust Exchange platform, which is found in our SASE and SSE offerings, protects thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Named a Best Workplace in Technology by Fortune and others, Zscaler fosters an inclusive and supportive culture that is home to some of the brightest minds in the industry. If you thrive in an environment that is fast-paced and collaborative, and you are passionate about building and innovating for the greater good, come make your next move with Zscaler.
Our Engineering team built the world's largest cloud security platform from the ground up, and we keep building. With more than 100 patents and big plans for enhancing services and increasing our global footprint, the team has made us and our multitenant architecture today's cloud security leader, with more than 15 million users in 185 countries. Bring your vision and passion to our team of cloud architects, software engineers, security experts, and more who are enabling organizations worldwide to harness speed and agility with a cloud-first strategy.
We're looking for an experienced Senior Information Security Engineer to join our Cyber and Data Security team. Reporting to Sr. Manager, Security Research, You'll be responsible for:
+ Working on Security Automation and conduct pen testing on Zscaler Applications and infrastructure
+ Helping the team prioritize vulnerabilities for engineering and operations team
+ Reviewing security bulletins and related news, stay apprised of current threats and trends
**What We're Looking for (Minimum Qualifications)**
+ Proficient in manual security assessments for web apps, thick client application, and APIs using top tools
+ 3+ years of experience, CVE publication, CTF participation, red teaming, and exploit development preferred
+ Skilled in thick client pen testing across Windows, Mac, Linux, Android, and iOS
+ Experienced in security architecture reviews for networks, thick clients, and web apps
+ Strong foundation in security, cryptography, Unix systems, and networking
**What Will Make You Stand Out (Preferred Qualifications)**
+ Experience with product security controls and processes, including vulnerability disclosure and management
+ Experience working for a security product and solutions provider
#LI-Hybrid
#LI-PM5
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
+ Various health plans
+ Time off plans for vacation and sick time
+ Parental leave options
+ Retirement options
+ Education reimbursement
+ In-office perks, and more!
Learn more about Zscaler's Future of Work strategy, hybrid working model, and benefits here ( .
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. _See more information by clicking on the_ Know Your Rights: Workplace Discrimination is Illegal ( _link._
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Senior Consultant - Security

Posted 4 days ago
Job Viewed
Job Description
WSP is one of the world's leading professional services consulting firms. We are dedicated to our local communities and propelled by international brainpower. We are technical experts and strategic advisors including engineers, technicians, scientists, architects, planners, surveyors and environmental specialists, as well as other design, program and construction management professionals. We design lasting solutions in the Transportation & Infrastructure, Property & Buildings, Earth & Environment, Power & Energy, Resources and Industry sectors, as well as offering strategic advisory services. Our talented people around the globe engineer projects that will help societies grow for lifetimes to come.
With approximately **4,000 talented people** across 3 locations (Noida, Bengaluru & Mumbai offices) in India and more than **73,000 globally** , in 550 **offices across 40 countries** , we engineer projects that will help societies grow for lifetimes to come.
At "WSP" we draw on the diverse skills and capabilities of our employees globally to compete for the most exciting and complex projects across the world and bring the same level of expertise to our local communities. We are proud to be an international collective of innovative thinkers who work on the most complex problems. Unified under one strong brand, we use our local expertise, international reach and global scale to prepare our cities and environments for the future, connect communities and help societies thrive in built and natural ecosystems. True to our guiding principles, our business is built on four cornerstones: **Our People, Our Clients, Our Operational Excellence and Our Expertise.**
** are**
+ Passionate people doing purposeful and sustainable work that helps shape our communities and the future.
+ A collaborative team that thrives on challenges and unconventional thinking.
+ A network of experts channeling our curiosity into creating solutions for complex issues.
**_Inspired by diversity, driven by inclusion, we work with passion and purpose._**
**Working with Us**
At WSP, you can access our global scale, contribute to landmark projects and connect with the brightest minds in your field to do the best work of your life. You can embrace your curiosity in a culture that celebrates new ideas and diverse perspectives. You can experience a world of opportunity and the chance to shape a career as unique as you.
**Our Hybrid Working Module**
With us, you can operate in a flexible, agile, yet structured work environment and follow a Hybrid Work Model.
+ Maximize collaboration.
+ Maintain product quality and cultural integrity.
+ Balance community, collaboration, opportunity, productivity, and efficiency.
**Health, Safety and Wellbeing**
Our people are our greatest asset, and we prioritize a safe work environment. Health, safety, and wellbeing are integral to our culture, with each of us accountable for fostering a safe workplace through our "Making Health and Safety Personal" initiative. Our Zero Harm Vision drives us to reduce risks through innovative solutions, earning recognition for our global health and safety practices with the prestigious RoSPA Health and Safety Awards for six consecutive years.
**Inclusivity and Diversity**
WSP India is dedicated to fostering a sustainable and inclusive work environment where our greatest strength - Our People -feel valued, respected, and supported. We ensure an unbiased approach in hiring, promotion, and performance evaluation, regardless of age, gender identity, race, religion, sexual orientation, marital status, physical ability, education, social status, or cultural background.
**Imagine a better future for you and a better future for us all.**
Join our close-knit community of over 73,300 talented global professionals dedicated to making a positive impact. Together, we can make a difference in communities both near and far.
**With us, you can.**
**Apply today.**
**NOTICE TO THIRD PARTY AGENCIES:**
_WSP does not accept unsolicited resumes from recruiters, employment agencies, or other staffing services. Unsolicited resumes include any resume or hiring document sent to WSP in the absence of a signed Service Agreement where WSP has expressly requested recruitment/staffing services specific to the position at hand. Any unsolicited resumes, including those submitted to hiring managers or other business leaders, will become the property of WSP and WSP will have the right to hire that candidate without reservation - no fee or other compensation will be owed or paid to the recruiter, employment agency, or other staffing service._
+ Good knowledge of various manufacturer specific Video Surveillance bandwidth and storage calculators.
+ Good knowledge of IT and networking to a level that supports Physical Security System installations.
+ Good understanding of architectural building plans, layouts and elevations (including cable, containment and connection schematics).
+ Good understanding of power, cooling and containment systems that support Physical Security Equipment.
+ Good Understanding of Hostile Vehicle Mitigation Solutions.
+ Experience within an electronic security systems design and engineering environment.
+ Candidate must have good industry knowledge and experience of Physical Security project installations or be prepared to engage in specific training to achieve a satisfactory level of knowledge.
+ AutoCAD/3D Revit Skills
+ Proficiency in reading and interpreting floor plans and technical drawings and specifications
+ Strong communication skills at all levels
+ High level of IT literacy - Microsoft Office Suite and Adobe Acrobat essential
+ Excellent communication and organisation skills
+ Ability to work under pressure
+ Diligent approach to quality management
+ Experience working on multiple concurrent projects
+ An approach to work that considers how prioritising tasks can impact or enable others
+ Proactively sharing information within a team
+ Desire to work in extremely collaborative and team-based environment
+ Experience working with and collaborating using online project and resource management tools
+ Rigorous attention to detail, both within your own work and when conducting peer reviews
+ Understanding of design and construction process
+ Experience working on High volume and high-speed
+ Having an understanding of the UK and European Standards/regulations applicable to the discipline and how to demonstrate this in project execution.
+ Have working understanding of latest software packages to allow the allocation / direction of work on projects.
+ Visio
+ Bluebeam
+ AutoCAD
+ AutoCAD Revit MEP
+ Bentley MicroStation
+ JVSG
+ Development of detailed designs, reports, specifications, budgets, and equipment schedules in line with RIBA Stages.
+ Identify the electronic security services that the customer requires to be deployed, e.g. Video Surveillance/Access Control/Intruder Detection.
+ Define and detail how each technology will be used, who will be the main users, the expected number of users or specific user groups and any other specific requirements that will drive the configuration of each systems design.
+ Surveillance camera coverage requirements - Confirm where each camera will be placed within the project boundaries identifying field of view and lens focal length.
+ Identify security technology spatial requirements, power constraints and cable routing requirements or restrictions within the project boundary for each system type or requirement.
+ Layout drawings showing cable routing and equipment locations.
+ Recommendations and design guideline development.
+ Develop a budget/BoQ for the cost of hardware components, implementation of the system, and support/maintenance.
+ Assist in the development and drafting of Technical Specifications and drawings for all Physical Security projects.
+ Ensure total awareness of Project deliverables.
+ Ensure that technical skills are kept up to-date and continually improved with each project via 'on the job' training and exposure to vendor developments and systems.
+ Prioritise and work to tight deadlines with accuracy and tenacity.
+ Ownership of the design throughout the project.
+ Ensuring applicable industry, technical, regional, and regulatory standards applied to designs.
+ Preparation of design documentation and technical specifications.
Be The First To Know
About the latest Information security Jobs in Bengaluru !
Cybersecurity Engineer (2)

Posted 4 days ago
Job Viewed
Job Description
**Who will you be working with?**
Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.
**How will you make a difference?**
Join Enterprise Information Security, where Wabtec is looking for an individual to become a pivotal force in designing and implementing cutting-edge security requirements and controls for our IT projects and systems. As a **Cybersecurity Engineer** , you'll report directly to the Senior Manager of Security Operations, ensuring the security and integrity of Wabtec enterprise environments. Your role will involve providing technical security guidance to cross-functional teams, enabling the creation and delivery of secure IT solutions and shared services. Use your expertise to analyze existing application services and infrastructure designs, suggesting remediations to reduce enterprise risk. You'll also serve as a security expert for new projects, collaborating closely with teams across the company to ensure robust security controls are implemented and maintained. Join us and lead the charge in cybersecurity excellence!
**What do we want to know about you?**
_You must have:_
+ Bachelor's degree in computer science or information technology or at least 5 years of full-time experience in cybersecurity
+ Experience with email security best practices and exchange online controls
+ Experience with Python, PowerShell, or related scripting/coding languages to automate enterprise security workflows
+ Experience with creating and managing hardened secure baseline configurations
+ Experience with hands on implementation and analysis of security configuration policies in an enterprise IT context
+ Strong background in Microsoft environments
+ Strong background with Microsoft Office and M365
+ Strong background with Microsoft Active Directory
+ Experience with Microsoft Defender products and operations
+ Experience with Microsoft Intune
+ Experience with security frameworks such as NIST, ISO, and CIS and decomposing them to granular security requirements and configurations
+ Strong analytical and problem-solving skills
+ Excellent communication and interpersonal skills
+ Must be willing to work weekends/off-shift hours, as needed during incidents
_We would love it if you had:_
+ Ability to work unsupervised
+ Strategic and creative thinking to analyze issues that may arise, and create solutions
+ Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most recommendation to leadership
+ An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative, and actionable manner
+ Proven ability to remain task driven and keep leadership updated on project status
+ Ability to respond positively to feedback, and implement changes in process and procedures as needed
+ Familiarity with Tanium and Microsoft Defender for O365
+ Understanding of network security, application security, and cloud security
+ CISSP, Microsoft or CompTIA security certification
+ Ability to work in a fast-paced environment
**What will your typical day look like?**
+ Design and implement enterprise-wide security controls and policies to protect against cyber threats in a hybrid and multi-cloud environment
+ Provide operational support to business consumers of security controls and services. Tune security stacks based on business requirements
+ Provide security guidance through baseline configurations and controls based on security frameworks and best practices for enterprise core security services including:
+ Workstation and server endpoint management
+ Microsoft Office and M365
+ Privileged Identity Management and identity governance
+ Browser security
+ Data Loss Prevention solutions
+ Develop and report operational health metrics for security services
+ Collaborate with IT, application, GRC and security operations teams to ensure that security controls are implemented effectively
+ Function as a security SME for enterprise ecosystems
+ Develop and maintain documentation on security policies, standards, and procedures
+ Use configuration management tools to ensure proper configuration of systems and applications
+ Stay up to date with the latest security technologies and industry trends
+ Other duties as assigned
**What about the physical demands of the job? (Usual office job examples)**
+ Regularly remaining in a stationary position, often standing or sitting for prolonged periods
+ Regularly communicating with others to exchange information
+ Regularly required to attend meetings in person and virtually using video and audio computer equipment
+ Regularly repeating motions that may include the wrists, hands and/or fingers, such as typing
+ Occasionally moving about to accomplish tasks or moving from one worksite to another
+ Occasionally light work that includes moving objects up to 20 pounds
You may also be asked to perform other duties outside of your function or trade, for which adequate training will be provided if necessary.
**_Work Environment: (Usual office job)_**
+ Hybrid work schedule (both on-site and remote)
+ The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise
**Relocation assistance availability confirmed here.**
**Who are we?**
Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.
Wabtec is focused on performance that drives progress and unlocks our customers' potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more! Commitment to Embrace Diversity:**
Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.
To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world's brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.
We believe in hiring talented people of varied backgrounds, experiences, and styles. People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.
Lead Cybersecurity Engineer - Vulnerability Management

Posted 4 days ago
Job Viewed
Job Description
It's not just about your career or job title. It's about who you are and the impact you will make on the world. Because whether it's for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you're in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.
**Who are we?**
Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.
Wabtec is focused on performance that drives progress and unlocks our customers' potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website ( to learn more!
**Who will you be working with?**
Join Enterprise Information Security (EIS) to drive cybersecurity excellence leveraging intelligence, strategic partnerships, and analysis. Collaborate daily with GRC, Architecture, Operations, and key Information Technology stakeholders to advance our information security capabilities.
**How will you make a difference?**
As a member of Enterprise Information Security, Wabtec is looking for an individual to run a Vulnerability Management program. The **Lead Cybersecurity Engineer** role reports directly into Enterprise Security Services (ESS) and is responsible for vulnerability response. Use your expertise to identify improvement areas and influence cybersecurity hygiene across all IT functions. Join us and lead the charge in cybersecurity excellence!
**What do we want to know about you?**
_You must have:_
+ Bachelor's degree in computer engineering or STEM major (Science, Technology, Engineering, or Math) and/or a minimum of six years of vulnerability management experience
+ 6+ years of experience overseeing the identification, assessment, and remediation of security vulnerabilities across IT infrastructure
+ Experience with the development of technical documentation
+ Thorough understanding of standards such as NVD, CVE, CPE, CWE, CVSS, CESS, EPSS
+ Effective project management and communications skills with ability to work on a Global team
+ Must be willing to work weekends/off-shift hours, as needed during incidents.
_We would love it if you had:_
+ Excellent communication skills with the ability to manage joint response and remediation efforts and constructively influence peers and leadership
+ Proficiencies in collaborating with Architecture, Product Security and IT stakeholders to refine vulnerability management lifecycle between Enterprise and Product
+ Ability to react quickly, decisively, and deliberately in high stress situations
+ Hands-on experience with popular vulnerability management solutions such as Tenable and ServiceNow-VR
+ Preferred -Tanium Comply, WIZ, ArmorCode, and Black Duck
**What will your typical day look like?**
+ Conduct regular vulnerability assessments using tools such as Tenable and ServiceNow-Vulnerability Response
+ Leverage experience to analyze and prioritize vulnerabilities based on risk and impact with the ability to work independently and receive minimal guidance
+ Develop and implement remediation plans in collaboration with IT and application teams, collaborate with various departments, ensuring systems are secure and compliant with industry standards
+ Continuously monitor the security landscape and provide detailed reports on vulnerability status, trends, remediation progress
+ Assist in the response to security incidents, providing expertise in vulnerability exploitation and mitigation
**What about the physical demands of the job? (Usual office job examples)**
+ Regularly remaining in a stationary position, often standing or sitting for prolonged periods
+ Regularly communicating with others to exchange information
+ Regularly required to attend meetings in person and virtually using video and audio computer equipment
+ Regularly repeating motions that may include the wrists, hands and/or fingers, such as typing
+ Occasionally moving about to accomplish tasks or moving from one worksite to another
+ Occasionally light work that includes moving objects up to 20 pounds
You may also be asked to perform other duties outside of your function or trade, for which adequate training will be provided if necessary.
**_Work Environment: (Usual office job)_**
+ Hybrid work schedule (both on-site and remote)
+ The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise
**Our Commitment to Embrace Diversity:**
Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.
To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world's brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.
We believe in hiring talented people of varied backgrounds, experiences, and styles. People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.
**Who are we?**
Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.
Wabtec is focused on performance that drives progress and unlocks our customers' potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more! Commitment to Embrace Diversity:**
Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.
To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world's brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.
We believe in hiring talented people of varied backgrounds, experiences, and styles. People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.
Senior Cybersecurity Engineer

Posted 4 days ago
Job Viewed
Job Description
It's not just about your career or job title. It's about who you are and the impact you will make on the world. Because whether it's for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you're in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.
**Who are we?**
Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.
Wabtec is focused on performance that drives progress and unlocks our customers' potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more!
_Summary:_
The Senior Cybersecurity Engineer is responsible for ongoing cybersecurity assessments of Wabtec products to determine whether they comply with applicable Wabtec cybersecurity standards and technical controls. They will advise product managers and engineering teams, create awareness of cybersecurity standards and technical controls, and recommend best practices for satisfying these standards and controls for all Wabtec products offered or made available to customers. They will work closely with others to define and maintain technical controls to address applicable regulations, industry standards, Wabtec policy, and product requirements.
**_Experience & Qualifications:_**
+ Bachelor's degree in Computer Science, Software Engineering, Cybersecurity, or related field.
+ Minimum of 6 years of experience with design, development, and/or testing of embedded industrial products and/or web systems.
+ Minimum of 4 years of experience in hands-on cybersecurity engineering.
+ Experience with cybersecurity standards, such as IEC 62443, NIST 800-53, or ISO 27001/2.
+ Extensive hands-on experience with cybersecurity assessment tools and methods.
+ Experience in cryptography, PKI, secure boot, and key management.
+ Demonstrated ability to effectively manage multiple tasks, working with various stakeholders in a global organization.
+ Understanding of software development cycles, project development lifecycle.
+ Demonstrated ability and commitment in understanding industry trends to bring forth best practices.
+ Demonstrated commitment to process improvement.
+ Experience in the rail, mining, or automotive sectors preferred.
+ Fluent in English, with ability to communicate through verbal and written means of communication.
**_Responsibilities:_**
This position requires extensive knowledge and experience with cybersecurity controls pertaining to mainly embedded and web systems. Responsibilities will include the following:
+ Conduct ongoing cybersecurity reviews of Wabtec products and determine whether Cybersecurity Authorization to Operate (CATO) should be granted based on compliance with Wabtec policies, standards, and technical controls.
+ Support engineering teams responsible for conducting threat and risk assessments to identify product threat surfaces and attack vectors.
+ Interpret technical cybersecurity concepts and their business implications. Be able to clearly explain these concepts to management and other engineers.
+ Drive and support an authoritative technical consultation process on product cybersecurity across Wabtec's embedded electronics and non-IT networked product portfolio including connected vehicle security, secure implementation of real-time operating systems, ongoing security support for heavy industrial systems and web services.
+ Recommend and consult on the design of software controls, hardening measures, and other risk mitigations to minimize attack surface and support cost-effective field maintainability of security controls.
+ Support engineering teams responsible for conducting root cause and corrective actions related to cybersecurity weaknesses.
+ Create and present training on cybersecurity to different stakeholder (management / leader / engineer)
+ Help to define and document security-related procedures
+ Select, document, and share best practices for product cybersecurity applicable to the Wabtec product portfolio.
+ Deliver effective project management and technical communications.
+ Support product teams by engaging with customers to identify product security requirements, provide security guidance, and perform technical analysis.
+ Serve as product cybersecurity point of contact for the assigned Wabtec group regarding activities assessment and vulnerability management.
You may also be asked to perform other duties outside of your function or trade, for which adequate training will be provided if necessary.
**Our Commitment to Embrace Diversity:**
Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.
To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world's brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.
We believe in hiring talented people of varied backgrounds, experiences, and styles. People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.
**Who are we?**
Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems.
Wabtec is focused on performance that drives progress and unlocks our customers' potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more! Commitment to Embrace Diversity:**
Wabtec is a global company that invests not just in our products, but also our people by embracing diversity and inclusion. We care about our relationships with our employees and take pride in celebrating the variety of experiences, expertise, and backgrounds that bring us together. At Wabtec, we aspire to create a place where we all belong and where diversity is welcomed and appreciated.
To fulfill that commitment, we rely on a culture of leadership, diversity, and inclusion. We aim to employ the world's brightest minds to help us create a limitless source of ideas and opportunities. We have created a space where everyone is given the opportunity to contribute based on their individual experiences and perspectives and recognize that these differences and diverse perspectives make us better.
We believe in hiring talented people of varied backgrounds, experiences, and styles. People like you! Wabtec Corporation is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, or protected Veteran status. If you have a disability or special need that requires accommodation, please let us know.