Cryptography & Security Specialist

5 days ago


Delhi, India All About Expats Full time
Job DescriptionOur client, a leader in pioneering technology, is dedicated to solving some of humanity’s most complex challenges. In partnership with key industry players, they offer cutting-edge patterning solutions that are integral to the progression of microchip technology. If you're passionate about incorporating security into processes and Information Technology, this might be the perfect opportunity for you.Job MissionAs a Cryptography and Security Specialist, you will join the Application Security team within the Technology Security Competence Center (TSCC), a segment of the Risk & Business Assurance (R&BA) department. Your primary responsibility will be to analyze security systems for potential vulnerabilities that could be exploited. This role involves identifying weaknesses and advising on the application and strengthening of cryptography. You will also be instrumental in identifying and testing new technologies that could be integrated into the organization's framework.Your duties will include conducting comprehensive security assessments, primarily focusing on new and existing applications and IT services. Additionally, you will provide assistance and advice on security-related queries in projects, and contribute to driving security enhancements. This role requires regular interaction with stakeholders at various levels within IT and across different sectors of the organization.This position plays a crucial role in safeguarding the organization’s information, Intellectual Property (IP), and assets, as well as those of their customers and suppliers, within the scope of the proposed solutions. This entails ensuring alignment with the organization's Information Security strategies and compliance with security policies, standards, and guidelines. It may also involve proposing additions and improvements to these standards to enhance overall security.

As a Cryptography and Security Specialist, you will be responsible for:Giving advice on which cryptographic tools/products to use and how to embed these in the environment.

Giving advice on which form of encryption best fits the environment, taking into account different factors, i.e., the classification of the data.

Keeping your knowledge up-to-date, especially in the cryptographic domain.

Setting up and monitoring governance and (co-) setting up processes and monitoring of these processes.

Performing project intake assessments in cooperation with the Project Security Officer.

Assessing applications and systems to be implemented or actual implementations based on assessments of high- and low-level designs, interviews and/or testing.

Assessing existing or new IT services (on premise or cloud) on technical vulnerabilities and weaknesses based on ASML process and tooling.

Translating assessment results into an Information Security Specification (security plan for service).

Communicating observations to the relevant stakeholders, advising on mitigation and following up on actions.

Adding information to the different security registers from Business Impact assessments (BIA’s), IT Security Assessments (ITSA’s), penetration/security tests, vulnerability scans, exceptions and other sources.

Adding information to security finding register, which contains all security assessment findings and risks that are reported within the TSCC, and is used to follow up on security assessment findings.

Improving and maintaining an Application Security Register, manage and follow-up on actions and register application progress.

Keeping track of follow-up actions and deliver management reporting.

Representing, on occasion, the TSCC in IT projects and intake boards where required.

Assessing IT security exception requests on validity and providing advice to the team lead application security and business stakeholder for acceptance or rejection including advice on additional security controls.

Improving procedures to keep the security registers, application registers and assessment processes up to date.

Creation and execution of roadmaps, standards, design patterns and frameworks, specifically on cryptography. Working together with different stakeholders within and outside of ASML e.g., external auditors and Core IT services.

Creation of cryptography KPI’s, assuring right cryptography within ASML is being used.

Advising on strategic future developments in cryptography.

Updating and maintaining security baselines and standards.

Assisting IT Security risk management.

Training and coaching DevOps teams on security aspects, standards and security solutions in CI/CD.

Requirements

Education and experience:Bachelor’s or Master’s degree in mathematics in combination with cybersecurity/information security (or equivalent experience).

Valid industry certifications such as CISSP, CISM and/or CISA are a plus.

CCSP or equivalent is a plus.

Required Experience:Min 6+ years professional experience with a focus on IT applications / information security, risk and compliance.

Strong mathematical/algorithmic understanding of symmetric and asymmetric cryptography, hash functions, digital signatures etc.

Experience and good hands on knowledge of PKI and certificate management in complex large enterprise settings, including Business Analysis.

Experience with tools/products (i.e. Docker) where cryptography is embedded is a plus.

Experience in executing Threat and Vulnerability Analysis (TVA) or IT Security risk assessments on IT services and applications.

Experience with a wide range of SAP applications is a plus (no authorization management).

Experience with Cloud security and 3rd party management.

Experience in collecting information through research and interviews.

Good working knowledge of Office suite applications like Excel, SharePoint and Teams.

Deep Knowledge of current security technologies and governance processes.

IT audit experience is a plus.

In-depth working knowledge of IT Risk / security frameworks and best practices, such as: NIST Cyber, security, framework, ISF Standard of Good Practice for Information Security, NIST SP 800 30 framework, ISO 27001/2 framework.

Knowledge of the Scaled Agile Framework (SAFe) is a plus.

Required Skills:Working at the cutting edge of tech, you’ll always have new challenges and new problems to solve – and working together is the only way to do that.

You won’t work in a silo. Instead, you’ll be part of a creative, dynamic work environment where you’ll collaborate with supportive colleagues.

There is always space for creative and unique points of view. You’ll have the flexibility and trust to choose how best to tackle tasks and solve problems.

Competencies:To thrive in this job, you’ll need the following skills:

Able to operate independently/with minimal supervision, self-starter.

Ability to interact with all levels including users, engineers, executives and senior managers.

Analytical, precise, tenacious, autonomous.

Knowledge of IT-security, Information Security and Architecture methodology.

Ability to overcome organizational resistance.

Excellent organizational skills and the ability to prioritize multiple tasks and assignments.

Able to manage large amounts of new information quickly; grasp the deep technical characteristics of new environments; draft clear and concise visualizations of complex processes and environments, stand your ground in a flexible / changing environment.

Enclose a personal motivation from the candidate for this position.

Even if you don't perfectly align with the current position, we encourage you to apply.We have several vacancies open and your application keeps you in consideration for this role and other relevant openings in the future.RequirementsA Bachelor's or Master's degree. Minimum of 5 years of experience in full-stack Java software engineering, including Java 11 and Spring. Experience with distributed software architectures and cloud-based hosting (preferably Azure). Back-end development proficiency with some front-end (web) development exposure. Knowledge of Continuous Integration, Build, and Deployment practices, tools, and trends. Comprehensive understanding of Java development methods, IT architectures, and common development tools. Skill in writing SQL database queries. Experience in the financial sector is preferable. Familiarity with tools like Azure DevOps and Splunk monitoring. A flexible, proactive approach with a strong analytical mindset and result orientation. Excellent oral and written communication skills in English.

  • Delhi, India Mindwise Solutions Private Limited Full time

    IS Architect Cryptography Infrastructure Network Information Security Architect - Cryptography, Infrastructure and Network a. Qualifications i. BE/ B.Tech/ M.Tech/ MSc/ MCA qualification or equivalent ii. Certified expert on one of the following - LA ISO 27001 IT risk management/ Information security certificate such as CISA, CISSP, GIAC are highly...


  • Delhi, Delhi, India Awign Expert Full time

    Job DescriptionAbout Awign Expert:Awign Expert is an Enterprise focused platform that helps businesses Hire, Assess and Manage high skilled resources for Gig Based Projects. We provide our Experts a gateway to work for and build a freelance/consulting career with large scale Enterprises. We are a newly launched business division of Awign, which is one of the...


  • delhi, India L A Technologies Pvt Ltd Full time

    Company DescriptionL.A Technologies is a specialized group of IT professionals based in Mumbai Metropolitan Region. We provide top-notch services in Networking, Securities, Wireless, and Server platforms for Internet and business applications. Our team includes certified professionals in Cisco, Microsoft, Certified Auditors, and Linux, as well as a network...


  • Delhi, Delhi, India Agensi Pekerjaan BTC Sdn Bhd Full time

    Job DescriptionOpen Position: IT Security Cloud Specialist (MNC Company)An MNC Company is currently looking for IT Security Cloud Specialist to join the team and based in the Kuala Lumpur office.Key responsibilities include:Responsible to manage and deploy IT security solutions in the cloud (AWS, Azure & Google Cloud)Build the integrations and solutioning...


  • Delhi, Delhi, India Agensi Pekerjaan BTC Sdn Bhd Full time

    Job DescriptionOpen Position: IT Cyber Security Specialist (IT MNC Company)An IT MNC Company is looking for IT Cyber Security Specialist to join the team and be based in the Kuala Lumpur officeKey responsibilities include:Perform vulnerability assessment, application and network penetration testing, digital forensic and system security testingDesign and...


  • Delhi, Delhi, India Work Visa USA Jobs (move2usajobs LLC) Full time

    Job DescriptionAn excellent opportunity awaits Information Security Specialists who are ready to take their careers to the next level in the United States. This role is designed for cybersecurity professionals who are passionate about protecting digital assets, ensuring data privacy, and mitigating cyber threats in a dynamic and challenging environment....


  • Delhi, India LeadSquared Full time

    Key Responsibilities:Application security assessmentsSecure Code ReviewCloud security assessmentsVulnerability managementSecurity Training and AwarenessAutomation and engineeringRequirements3 to 5 years' experience in Product Security, desirable to have 1+ years of software development experience.Experience in testing several complex web applications by...


  • Delhi, India Agensi Pekerjaan BTC Sdn Bhd Full time

    Job DescriptionOpen Position:IT Security Specialist (Regional)An IT MNC Services Organisation is looking for IT Security Specialist to join the team and be based in the Selangor office.Key responsibilities include:Strong experience in managing IT Security Operations and Design within IT Application, Cloud, Network, IT Infrastructure and etcGood experience...


  • Delhi, India Gritstone Technologies Full time

    Information Security Specialist GRIT-JR0000247Job SummaryWe are looking to hire a cyber security engineer or Specialist with an analytical mind and a detailed understanding of cybersecurity methodologies. Cyber security engineers are expected to have meticulous attention to detail, outstanding problem-solving skills, work comfortably under pressure, and...

  • Security Specialist

    1 week ago


    Delhi, India CryptoMize Full time

    ResponsibilitiesEND -->Our PrinciplesThese are some of the principles that we strongly believe in, preach and actually follow as well.CommitmentsWe clearly commit what we can do, by when can we do it and how we would do it, And then we do it.ConfidentialityWe are extremely paranoid about protecting the confidentiality of what we do, for whom and how we do...

  • Security Specialist

    2 weeks ago


    Delhi, Delhi, India CryptoMize Full time

    ResponsibilitiesEND >Our PrinciplesThese are some of the principles that we strongly believe in, preach and actually follow as well.CommitmentsWe clearly commit what we can do, by when can we do it and how we would do it, And then we do it.ConfidentialityWe are extremely paranoid about protecting the confidentiality of what we do, for whom and how we do...


  • Delhi, Delhi, India Quest Diagnostics Full time

    Title: IT Security Sr.Specialist II Third Party Risk ManagementLocation: HyderabadShift Timings: 1.00 PM to 10.00 PM ISTHybrid Model: 3 Days Onsite & 2 Days RemoteQuest Diagnostics Third-Party Vendor Risk Management Program performs the critical function of assessing the risks of new and existing vendors. The IT Security Sr. Specialist II will be responsible...


  • Delhi, India Secure Network Solutions India Private Limited Full time

    Company DescriptionSecure Network Solutions India Private Limited (SNS) is a leading cybersecurity company. With over 23+ years of experience, SNS focuses solely on providing information and network security solutions.As an ISO 27001 Certified Company and winner of several awards, our mission is to be one of India's best security solution and support...

  • Cyber Security Trainer

    2 months ago


    Delhi, India Futurense Technologies Full time

    Job Title: Cyber Security TrainerLocation: Kanakapura, BangaloreJob Type: Full-timeJob Description:We are seeking a dynamic and experienced Cyber Security Trainer to join our team at our Kanakapura, Bangalore location. The ideal candidate will have a strong background in cybersecurity, a passion for teaching, and the ability to inspire and mentor B.Tech CSE...


  • Delhi, Delhi, India Promaynov Advisory Services Pvt. Ltd Full time

    Location: Whitefield, BengaluruNo of years' experience required:3 to 6 yearsJob Role:Perform application threat modelling based on STRIDE/DREAD model, use C4 data model architecture to identify the trust boundaries and security gaps to create application risk profile and remediation recommendations.Advise Product Owners to manage their security risks...


  • Delhi, India WorldQuant Full time

    WorldQuant develops and deploys systematic financial strategies across a broad range of asset classes and global markets. We seek to produce high-quality predictive signals (alphas) through our proprietary research platform to employ financial strategies focused on market inefficiencies. Our teams work collaboratively to drive the production of alphas and...


  • Delhi, Delhi, India VE3 Full time

    Job DescriptionJob Title:Cyber Security Specialist (Cyber Resilience Programme)- Active SC ClearedLocation:UKReporting To:Programme Lead, Cyber Resilience ProgrammePosition Type:Full-timeExperience Level: 5+ years.About the Company:We leverage our strong capabilities to build powerful solutions that make a real difference for our clients. We offer a full...


  • delhi, India YASH Technologies Full time

    Experience: 7 to 10 yearsNotice Period: immediate/15 days/ 30 daysLocation: Pune7 - 10 years industry experience in network security environmentsStrong experience in engineering and deploying enterprise cloud infrastructure security solutions with a good understanding of cross platform technologiesGood knowledge and understanding of Cryptography, Identity...

  • Cloud Security

    4 weeks ago


    delhi, India SID Global Solutions Full time

    Position: L2, L3Mode of work: On-siteExperience: 5-14 yrsLocation: Mumbai(Navi Mumbai)Looking for candidate who can join the project within 25 days.Mandatory to have any one of the certification(CISSP/ CISM/CCSP/ CEH ) along with VMWare VCAP Certification.Provide hands-on security expertise in the design, maintenance, analysis, assessment, development,...


  • Delhi, Delhi, India Infoblox Full time

    It's an exciting time to be at Infoblox. Named a Top 25 Cyber Security Company by The Software Report and one of Inc. magazine's Best Workplaces for 2020, Infoblox is the leader in cloud-first networking and security services. Our solutions empower organizations to take full advantage of the cloud to deliver network experiences that are inherently simple,...