S

Cyber Security Risk Engineer-2

S&P Global
NewPosted today

LOCATION

Gurugram · Onsite

EXPERIENCE

5+ Years

TYPE

FullTime

SALARY

Negotiable

SKILLS REQUIRED

Cybersecurity Risk ManagementSecurity complianceNIST ControlsSecurity Control Assessment

Job description

Overview

The Cyber Security Risk Engineer will review, assess and report on the maturity of security controls for current and proposed solutions. The role supports security consulting, assessments and measurement, security exceptions management, technology evaluation, and acquisitions and divestitures.

What you'll do

  • Enforce corporate, regulatory and risk management policy configurations.
  • Assist in developing, implementing and maintaining corporate information security standards, technologies, processes and procedures.
  • Review and provide guidance on controls relating to current and future solutions.
  • Ensure the business adheres to minimum requirements and operates within agreed risk appetites for information, data and cyber security and ongoing assurance.
  • Understand areas of concern and provide advice, guidance, recommendations and mitigations with stakeholders.
  • Serve as a subject matter expert for colleagues and line-of-business managers.
  • Improve efficiencies using automation and orchestration solutions to reduce manual work that can be done programmatically.
  • Influence tactical and strategic decisions.
  • Identify process efficiencies through analysis and metrics-driven decision making.
  • Create guidance, security documentation and configuration practices.
  • Ensure systems are protected against threats through deployment of security controls.
  • Ensure guidance and assessments are aligned to regulatory and compliance requirements and local laws.
  • Administer best practices and required configuration standards for compliance and privacy law obligations.
  • Remain current with new security threats and assess systems to ensure they can defend the business.
  • Provide metrics and other management information to leadership to support sound decision making.
  • Perform other duties as assigned.

What you'll need

  • At least 5-7+ years’ experience in cybersecurity, including compliance and risk management, with a system and network security engineering background.
  • Highly technical and analytical expertise, with a proven deep background in technology design, implementation and delivery.
  • Experience aligning to a NIST controls framework.
  • Familiarity with the concepts of security control frameworks.
  • Experience in cloud computing technologies, including software-, infrastructure- and platform-as-a-service, as well as public, private and hybrid environments.
  • Extensive knowledge of traditional security controls and technologies, such as SIEM systems, IDS/IPS, public key infrastructure (PKI), IDAM systems, antivirus and firewalls.
  • Knowledge of newer offerings such as endpoint detection and response (EDR), threat intelligence platforms, security automation and orchestration, deception technologies and application controls.
  • Experience driving measurable improvement in monitoring and response capabilities at scale.
  • Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively.
  • Experience of information security and data protection practices in financial services.
  • Experience working within cyber security and information security teams in an international business of scale and complexity.
  • Bachelor’s degree in computer science, information assurance, MIS or a related field, or equivalent.

Nice to have

  • Experience with Amazon Web Services (AWS) or Microsoft Azure.
  • Experience with one or more of ISO 27001, NIST, Payment Card Industry Data Security Standard (PCI DSS), Health Information Portability and Accountability Act (HIPAA), Health Information Technology for Economic and Clinical Health (HITECH) Act, Sarbanes-Oxley Act (SOX), the General Data Protection Regulation (GDPR), Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2.
  • Working knowledge of Windows, Linux and Unix.
  • Highly trustworthy; leads by example.

Details

  • The location line states Gurugram, Haryana.
  • The role description states Hyderabad as the location.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Cyber Security Risk Engineer-2