Specialist Cyber Security Cloud Operations

3 weeks ago


bangalore, India Emirates NBD Full time
Role is based in Dubai UAE (not a remote role)
The Cloud Security specialist role is responsible for effectively detecting, responding to, and mitigating threats targeting EmiratesNBD’s cloud infrastructure and data. They will also act as standby resources for conducting the incident processes to ensure they are well drilled and effective. Maintain acceptable cyber hygiene levels and ensure the goals of the unit are met.
Roles & Responsibilities:
Continuously monitor cloud environments using security tools and services to detect potential intrusion attempts, data exfiltration, lateral movement, and unauthorized access.
Utilize Security Information and Event Management (SIEM) tools to collect and analyze logs from various cloud services, identifying potential security incidents and abnormal patterns.
Develop custom detection rules and queries to identify cloud-specific threats, such as API abuse, unauthorized resource provisioning, and data exfiltration.
Address cloud-specific attack vectors, such as identity and access management (IAM) issues, insecure API configurations, and data exposure due to misconfigured storage services.
Implement container security monitoring solutions to ensure the integrity and security of containerized applications running in cloud environments.
Utilize API security tools to monitor and protect cloud APIs from abuse, unauthorized access, and injection attacks.
Deploy honeytokens and deception technology to lure and detect attackers attempting to exploit fake assets in the cloud.
Deploy machine learning-based anomaly detection to identify unusual user behaviors and potential account compromises within cloud environments.
Implement serverless security monitoring solutions to detect potential threats targeting serverless functions and ensure secure serverless application development.
Continuously review and enhance cloud security monitoring strategies, taking into account the evolving threat landscape and the cloud environment's changes.
Leverage CASB solutions to monitor and control data access and movement between cloud services and users, mitigating insider threats and unauthorized activities.
Conduct regular audits of Identity and Access Management (IAM) configurations, ensuring proper access controls and permissions across cloud resources.
Proactively search for signs of unauthorized activities, persistent threats, and advanced attack techniques within cloud environments using threat hunting methodologies.
Utilize threat intelligence sources and security data to detect cloud-specific threats such as misconfigurations, account compromises, and privilege escalation.
Use both manual and machine assisted techniques to find the Tactics, Techniques and Procedures of advanced adversaries.
Trace attacker paths and detect suspicious patterns of threat actors.
Research innovative methods for making Threat Hunting more efficient and effective.
Utilize digital forensics tools and techniques to perform in-depth analysis of compromised cloud instances, identifying attack vectors and post-incident indicators.
Develop acquisition and processing workflows to acquire and process cloud forensic artefacts.
Employ automated incident triage solutions to quickly assess the severity and impact of security alerts, prioritizing critical incidents for immediate response.
Execute incident response playbooks tailored to different cloud attack scenarios, ensuring the proper sequence of actions during each phase of incident handling.
Swiftly contain and isolate affected cloud resources to prevent further spread of the attack and conduct thorough investigations to identify the root cause of the incident.
Maintain clear and timely communication with stakeholders, providing updates on incident investigations, impact assessments, and recommended countermeasures.
Perform detailed post-incident analysis to understand attack vectors, tactics, techniques, and procedures (TTPs) employed by threat actors, enabling better defense against future attacks.
Help meet SLA’s defined for Incident Management.
Prepare and provide relevant reports for identified incidents.
Ensure the relevant documentation is kept upto date at all times.
Proactively identify gaps and remediate them to keep observations from Auditors and Regulators to a minimum.
Help the CSIRT during security incidents.
Ensure that peers maintain quality.
Coach, guide and mentor peers to ensure quality delivery
Assist security team members in decision making when it comes to security incidents.
Guide peers during conflicts within the team.
Guide the team and self with upto date and highest level of technical acumen.
Suggest new solutions to improve the Security Monitoring posture of the Group.
Conduct PoCs for new technologies which could help uplift the level of Security within the Group.
Run security projects end to end where necessary.
Requirements:
Proficiency in designing and implementing cloud security architectures with a comprehensive understanding of network segmentation, secure gateway configurations, and application security controls.
Expertise in setting up robust cloud monitoring and logging solutions, utilizing tools such as CloudWatch, Azure Monitor, for continuous monitoring of cloud resources. Proficient in creating custom alerts and integrating with incident management platforms for timely response.
Proven ability to implement runtime security measures, utilizing container security solutions like Kubernetes RBAC, Pod Security Policies, and image scanning to ensure the integrity and security of applications during runtime.
Proficiency in integrating security seamlessly into the CI/CD pipeline, leveraging tools like Jenkins, GitLab, and GitHub Actions for automated security testing and vulnerability assessments.
Adept at configuring granular IAM policies, implementing role-based access controls, and integrating Identity Providers (IdPs) to facilitate Single Sign-On (SSO) for heightened access control.
In-depth understanding of cloud compliance frameworks, including GDPR, HIPAA, and PCI-DSS. Proficient in mapping controls, conducting compliance audits, and producing documentation for certifications.
Proven expertise in devising incident response plans, developing Security Operation Center (SOC) playbooks, and utilizing advanced SIEM solutions for real-time threat detection and response.
Knowledge of current adversary techniques, vulnerability disclosures, data breach incidents, and security analysis techniques.
Experience in analyzing, gathering intelligence on, developing, and documenting threat group activities.
Experience in analyzing malware / offensive tools and threat actor tactics, techniques, and procedures to characterize threat actors’ technical methods for accomplishing their objectives or missions.
Demonstrated understanding of remediation and counter measures for challenging information security threats.
Moderate to advanced technical experience in network communication protocols.
Conducting forensic analysis on and data captures from networks / packet capture, hosts (volatile/live memory), electronic media, log data, and network devices in support of intrusion analysis or enterprise level information security operations.
Expert understanding of a company’s business processes, technology and information systems.
Must have knowledge on application and infrastructure security threats and mitigating measures.
Deep knowledge on all aspects of Information Security concepts from broad range of technical and non- technical areas.
Good negotiation skills will be desirable.
Ability to understand regulatory requirements and process efficiency frameworks.
Ability to understand the details of ground level security issues, and its management.
Ability to monitor and enforce improvements when necessary, in line with regulatory requirements or best practices.
Good knowledge of risk management frameworks and how to identify, manage and mitigate risk.
Ability to create and review security policies, standards, procedures and hardening baselines
Strong understanding of the cloud technology stacks for Microsoft Azure, Amazon AWS, Google Cloud Platform and Oracle Cloud.
Strong grasp of SecDevOps practices.
Should be able to conduct Digital Forensics and Malware Assessments.
Multiple operating systems, such as Windows, Linux/Unix, and Mac/OSX.
Scripting (Shell/Python/R/etc.) / Programming in support of data analysis.
Superior written and verbal communication skills in order to effectively communicate security threats and recommendations to technical or non-technical stakeholders.
Good hands on experience with traditional infrastructure technologies that involve perimeter protection, core protection and end-point protection/detection.
Penetration testing experience is desirable. Must be able to understand and mitigate security issues that relate to applications.
Takes responsibility and ownership for the security of projects that are assigned to them
Should have good project management & execution skills with respect to tasks and ensure completion.
Process oriented skills are advantageous.
Experience with technologies/concepts such as OAuth, AI, Blockchain, Robotics, SecDevOps, SAML, OWASP Top 10.

  • bangalore, India Kognosdata Full time

    Company Description Kognosdata is a company located in Bengaluru that specializes in creating effective solutions for scientific and engineering software, outsourcing, and e-commerce. We are dedicated to solving problems and providing innovative solutions in these areas. Role Description This is a full-time on-site role for a Cyber Security Specialist. The...


  • bangalore, India Data Security Council of India Full time

    Responsibilities:Account acquisition and Management: Acquire new clients and engage with existing clients for retention.Build proposition, solutions, and service lines for industry sectors, specific problems, and arrange capabilities/ offerings around them.Building a trusted relationship with clients as a Trusted Advisor for Cyber Security from the...


  • bangalore, India Carrier Full time

    About the role : In the role of Operations Manager at Carrier’s Cybersecurity team, you will be responsible for leading the Security Operations team within the Cybersecurity Architecture and Engineering department. Your duties will include supervising the maintenance and management of cybersecurity tools, handling security applications, implementing...


  • bangalore, India Data Security Council of India Full time

    Responsibilities: Account acquisition and Management: Acquire new clients and engage with existing clients for retention. Build proposition, solutions, and service lines for industry sectors, specific problems, and arrange capabilities/ offerings around them. Building a trusted relationship with clients as a Trusted Advisor for Cyber Security from the...


  • bangalore, India Agratas Full time

    Job Description:We are currently seeking an experienced Cyber Defence Head with minimum 14 years of relevant experience to lead our team in ensuring the security and integrity of our organization's systems and data. The ideal candidate will have a strong background in security operations, including data loss prevention, ZT technology, endpoint protection...

  • GM. Cyber Operations

    2 weeks ago


    bangalore, India Vodafone Full time

    What you’ll do Role title: General Manager (Senior Cyber Security Manager) – Cyber Defense Background Vodafone continues to invest in Cyber Security to mitigate its Cyber Risk. _VOIS is the Global Capability Center (GCC) of Vodafone in Egypt, Romania, India, and other locations. It provides various services and capabilities to its...


  • bangalore, India Saaki Argus & Averil Consulting Full time

    Job Description: · Strong expertise in cloud security, DNS, DDoS, IDS/IPS, email security, and email and web advance threat protection. Improving defence by examining email, DNS, and DDoS attack patterns. Monitoring baseline changes for external threat threats detection and automating preventive mitigation. · DMARC and outgoing email enforcement...


  • bangalore, India Agratas Full time

    Job Description: We are currently seeking an experienced Cyber Defence Head with minimum 14 years of relevant experience to lead our team in ensuring the security and integrity of our organization's systems and data. The ideal candidate will have a strong background in security operations, including data loss prevention, ZT technology, endpoint protection...

  • Cyber Security

    1 month ago


    bangalore, India Necurity Solution Full time

    Necurity Solution is a leading company in the Computer & Network Security industry, specializing in providing comprehensive security solutions to businesses worldwide. We are currently seeking a highly skilled and motivated individual to join our team as a Cyber Security professional. As a Cyber Security expert, you will play a crucial role in protecting our...


  • Bangalore, India CME India Technology And Support Services Pvt Ltd Full time

    Job Description : Manager will help to manage, create, implement, and subsequently mature and support Cyber Defense solutions for CME's Network and Systems, with a focus on Cloud computing and Automation, within Cyber Defense Engineering - Global Information Security. This position will be responsible for the management of a team of : - Cyber...


  • bangalore, India Mindsprint Full time

    Position: Sr Engineer /Lead Engineer - Cyber SecurityLocation: Chennai/BangaloreSummary:We're seeking a seasoned Senior Cyber Security Engineer with 6-8 years of experience to fortify our team. Your role involves ensuring the security of cloud infrastructure and applications through meticulous assessment and implementation of robust security measures.Key...


  • Bangalore/Chennai, India WEN Full time

    Job Description : - Defines, publishes and maintains processes for Security Governances, Risk and Compliance (GRC) for public cloud (AWS and Azure)- Define cyber controls for public cloud platform, whilst adhering to a centralized methodology- Updating and documenting security controls as an accountable part of the public cloud expertise team (e.g.: code...


  • bangalore, India Mindsprint Full time

    Position: Sr Engineer /Lead Engineer - Cyber Security Location: Chennai/Bangalore Summary: We're seeking a seasoned Senior Cyber Security Engineer with 6-8 years of experience to fortify our team. Your role involves ensuring the security of cloud infrastructure and applications through meticulous assessment and implementation of robust security measures....

  • Program Manager

    1 month ago


    Bangalore, India Infosys Limited Full time

    Responsibilities In the role of Program Manager, you will be responsible for Managing and Assuring Cyber Security risk remediation for Infosys clients by collaborating with multiple teams, driving and executing security remediation and improvement workstreams. • Define, govern, and execute security remediation actions through programmatic & structured...


  • Bangalore/Chennai, Tamil Nadu, India INSIGHT GLOBAL SOLUTIONS Full time

    Must Have Requirements:.- 5-7+ years of information technology experience including security and compliance.- 3+ years cyber security experience.- 2 years of Splunk experience.- Fluent with Wireshark.- Experience analyzing cloud traffic and logs. Day-to-Day: This position is responsible for security alert monitoring and remediation for all security products...


  • Bangalore/Chennai, India INSIGHT GLOBAL SOLUTIONS Full time

    Must Have Requirements:.- 5-7+ years of information technology experience including security and compliance.- 3+ years cyber security experience.- 2 years of Splunk experience.- Fluent with Wireshark.- Experience analyzing cloud traffic and logs. Day-to-Day: This position is responsible for security alert monitoring and remediation for all security products...


  • Bangalore Metropolitan Area, India SELLIGENCE SOLUTIONS PRIVATE LIMITED Full time

    Key Duties & ResponsibilitiesDevelop and Implement Security Policies: The cyber security manager is responsible for formulating and implementing comprehensive security policies and procedures that align with the organization’s goals and regulatory requirements. This includes creating incident response plans, conducting risk assessments, and ensuring...


  • Bangalore,Hyderabad, India MY Search Full time

    Our client is a Global multinational technology company that is focused on engineering, manufacturing, data analytics, networks and operations. They are looking for Autosar Cyber Security Software Specialist to be based at Hyderabad with the following :- Total 4 to 8 years of experience with 4+ years in developing security features in embedded software for...

  • Cyber/Cloud Security

    1 month ago


    Bangalore/Chennai, India WEN Full time

    Role : Cyber Security Consultant - Lead CSRO (Only Female : The Cyber/Cloud Security and Risk Officer (CSRO) aims to contribute to the steering of strategy in terms of public cloud security, technical standards, processes, tools and risk management.Experience : 10 yrs + - Defines, publishes and maintains processes for Security Governances, Risk and...


  • bangalore, India Ceragon Full time

    Job Description Ceragon is looking to hire a cyber security engineer with an analytical mind and a detailed understanding of cybersecurity methodologies, practices and systems. Cyber security engineer is expected to have rigorous attention to details, outstanding problem-solving skills, work comfortably under pressure, and deliver on tight...