Security Consultant

3 weeks ago


Bengaluru, India Prime Infosoft Full time

Description : Role Proficiency : With strong knowledge of various applicable compliance standards independently handle internal/external compliance audits and VAPT/Red Teaming assignments. Involve more in the risk assessment and remediations. Effectively communicate with customer to understand the requirements and clearly convey the requirements to team. Handle the assigned tasks with minimal supervisionOutcomes : - Should handle the assigned tasks from the allocated domain with minimal guidance from the leads. (Domain Examples : BCMS Risk assessment incident management HITRUST SOC customer assurance Awareness activities Data Privacy VAPT Red Teaming etc.)- Handle (with minimal guidance from the supervisors) internal/external compliance audits to ensure compliance with ISO 27001/ISO 22301/ISO 27701 requirement as well as process specific requirements.- Responsible for the effective documentation of internal audits (reports) external audit documentation.- Help the team for effective external audit facilitation and the related responsibilities.- Point out the non-conformance areas related to information security with assistance from the supervisor.- Ensure that policies are updated as and when required and eliminate the discrepancies of old policy versions.- Conduct information security awareness training programs for all the employees contractors and approved system users.- Evaluate IT Controls implementation and perform Risk Assessment.- Carry out technical vulnerability assessments of IT systems and processes to identify potential vulnerabilities. - Make recommendations to control any risks identified and ensure that they are implemented.- Collect review and analyse latest technologies and tools.- Analyse user requirements and steps required to perform the VAPT/Red Teaming.- Interact with and communicate detailed technical requirements to the team.- Lead Security Assessment scoping independently based on security standards like OWASP.- Lead Web Application Penetration Testing Network Penetration Testing Mobile Penetration Testing and Code Review independently based on the guidance from leads.- Learn and understand existing and emerging security management practices.- Independently handle the evidence collection from multiple teams as part of any external audits.- Assist in customer assurance activities.- Assist in the process automation activities.- Mentor and Lead A band employees.Measures of Outcomes : - Number of internal audits and security assessments conducted per year.- Number of external audit facilitation activities.- Number of Threats/Risks/Vulnerabilities reported per year.- Number of NCs in external audits on assigned domains.- Number of areas of responsibility on cross domains.- Performance of ISMS/BCMS/PIMS/QMS in the responsible centre/regions.- Awareness activities conducted and the percentage of adoption in the responsible centre/regions.- Noticeable initiatives taken to improve the process.- Less than two stake holder escalations.- More than three appreciation from the Expected : Documentation : - Policy and Procedure amendments- Awareness training materials- Presentations decks for internal/ external discussions- Audit /Security Assessment reportsProcess : - Internal ISMS audits independently carry out audits- prepare audit reports and ensure timely closure of audit reports- Compliance Audits Representation in certification audits- conduct preparatory session and evidence collection- Risk Assessment - IT Controls implementation and assess risks- Infosec activities training material- conducting sessions- co-ordinate with other teams for trainings conducting- Customer Assurance independently handle customer assurance requirements and evidence collection- Policy Identify discrepancies in the policies and addressing it- Vulnerability Assessment and Penetration Testing/Red Teaming Activities- CM activities- Executing other location responsibilitiesMonitoring : - Mentoring and leading A band employeesTraining or certifications : - 2 per year (1 certification and minimum 1 of UST trainings on ISMS domains)Skill Examples : - Ability to understand prioritize and escalate tasks to resolve issues quickly and make decisions- Able to interpret all scenarios applicable to the business for identifying the potential risks associated with various functions/services.- Proficiency in Network Security Controls' implementation like IAM IPS/IDS E-Mail Security Controls Cloud Security Controls etc.- Proficiency in Technical Vulnerability Assessment and Management.- Strong compliance auditing knowledge.- Detail oriented customer oriented result delivery oriented analytical thinking- Strong Excel and Dashboard skills.- Excellent Presentation and communication skills- Excellent verbal and written communication skills required including the ability to effectively communicate in both highly technical and non-technical environments- A great problem solver with the knack of coaching others to do the same- Good at working in a team and with other teams- Good time management- A desire for continuous learning and skill development.- Self-motivated and enthusiasticKnowledge Examples : - Should have a strong understanding of concepts of Information Security Business Continuity and Data Privacy VAPT Red Teaming and various compliance standards.- Knowledge on ISO and other Compliance standards efficient to evaluate the security controls.- Knowledge on ISO 22301/27001/9001/27701 Risk Management incident management awareness activities customer assurance etc.- Knowledge on standard SDLC and project management life cycles.- Knowledge on the operations of various functional units like HR REFM IT Finance etc. and units involved in IT Asset lifecycle management.- Expert on security testing standards like OWASP Top 10 SANS 25 etc.- Good at OWASP cheat sheets and other security frameworks.- Expert on Linux commands.- Expert on Scripting Languages like Shell Script Python etc.- Development and Testing knowledge would an added advantage.- Hands on experience in RSA Archer Postman Burp Suite Nessus Nmap Genymotion MobSF Drozer etc.- Good to have Certifications like ISO 27001/22301/9001/27701 Lead Auditor/Implementor CISA CRISC SSCP ECSA (Practical) ECES CHFI OSEE etc. (ref:hirist.tech)



  • Bengaluru, India NMS Consultant Full time

    From 3 to 8 year(s) of experience ₹ Not Disclosed by Recruiter - Bangalore/Bengaluru, Delhi / NCR - Microsoft Security Solutions Architect for the following **Microsoft Security Products (M365 SCI, EMS E5, E5 Security & E5 Compliance, Microsoft Sentinel, Defender for Cloud) **capable of delivering the following part of the job profile for Global...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: [Mumbai, Pune, Bangalore & Delhi (NCR)] Experience Level: 3–9 Years - Employment Type: Full-Time Role Overview: We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: (Mumbai, Pune, Bangalore & Delhi (NCR)) Experience Level: 3–9 Years Employment Type: Full-Time Role Overview: We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: (Mumbai, Pune, Bangalore & Delhi (NCR)) Experience Level: 3–9 Years Employment Type: Full-Time Role Overview: We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: (Mumbai, Pune, Bangalore & Delhi (NCR)) Experience Level: 3–9 Years Employment Type: Full-Time Role Overview: We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    1 week ago


    Bengaluru, Karnataka, India GERALD US, Inc. Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    As a Security Consultant, you will play a key client-facing role, engaging directly with stakeholders across German-speaking markets. You will provide advisory, implementation, and project delivery support to help clients strengthen their security posture, achieve compliance, and align with international standards. Your ability to communicate effectively in...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: [Mumbai, Pune, Bangalore & Delhi (NCR)]Experience Level: 3–9 YearsEmployment Type: Full-TimeRole Overview:We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: [Mumbai, Pune, Bangalore & Delhi (NCR)]Experience Level: 3–9 YearsEmployment Type: Full-TimeRole Overview:We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...

  • Security Consultant

    2 weeks ago


    Bengaluru, India Capgemini Engineering Full time

    Hiring Now: Security Consultant Location: [Mumbai, Pune, Bangalore & Delhi (NCR)]Experience Level: 3–9 YearsEmployment Type: Full-TimeRole Overview:We are looking for experienced Security Consultants with strong expertise in designing and implementing enterprise-grade security solutions. The ideal candidates will have hands-on experience in firewall...


  • Bengaluru, Karnataka, India SR consultant Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Description : - Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex applications, operating systems, wired and wireless networks, and mobile applications/devices - Develop and maintain security testing plans for internal environments and vendors - Automate penetration and other security testing on...