Security and Compliance Professional

6 months ago


Bengaluru Karnataka, India IBM Full time

Introduction

Your Role and Responsibilities

The Security and Compliance professional should continuously consider the attack vectors and security weaknesses within their service or product offering and provide solutions to remediate those weaknesses. Communicates and articulates to leadership team about the security posture of represented products/services. This overarching responsibility drives the requirement for the Security and Compliance Lead to be proficient in the Required Skills section below.
- Technical: First and foremost, good grasp of computer science and deep technical understanding of Micro-services architecture, SaaS, Cloud Security and Infrastructure.
- Collaborative: Must collaborate with architects, developers, and non-technical stakeholders to drive security solutions.
- Respected: Proven track record as a security professional in the industry. You will be expected to establish trust and respect with the development teams.
- Growth Mindset: The world of security is highly dynamic and IBM is a company that thrives on innovation and maturation, our Security and Compliance professional must possess a growth mindset to keep up with the ever-changing security landscape and seek opportunities to increase their breadth and depth of security topics.

Required Technical and Professional Expertise
- 5+ years of working experience with designing/building SaaS offerings.
- Domain expertise in cloud software and infrastructure technologies.
- Ability to communicate highly technical aspects to Executives, IT staffs, CISO team, auditors, respectively.
- Experience with various scripting languages (Shell, Python, Bash, etc.).
- Familiarity with OWASP Top Ten, NIST, CIS and MITRE ATT&CK
- Demonstrated experience in successful driving and execution of compliance programs for common IT security standards/regulations: SOC1/2/3, ISO27K, HIPAA, PCI, FBA (formerly FFIEC), FedRAMP, GDPR, etc.

Experience with and understanding of
- Access Management - understand the concepts of need to know, least privilege, individual accountability, privilege access monitoring, access revalidation, etc. and ensure your service implements them. Know to avoid the use of shared IDs, excessive privileges, weak passwords, etc.
- Vulnerability Management - be able to regularly scan your systems and remediate any vulnerabilities found within required time frames
- Data Protection - understand the types of data your services deal with and have measures in place to protect that data (e.g. encryption in transit and at rest, locked down file permissions, etc.)
- Logging & Monitoring - ensure there is a process in place to store key logs with data integrity in place to protect those logs and have a process in place to independently monitor those logs for any unusual activity
- Business Continuity - understand what business continuity requirements are necessary in your organization and actively participate in ongoing business continuity planning
- Risk Management - understand where there are gaps in compliance or areas of risk that need to be analyzed and addressed either by remediation activities or formal Risk Evaluations to ensure mitigation, executive awareness, and approval
- Audits - be prepared to support audits by providing evidence or being interviewed as required
- Common Attack Patterns - know what the common attack vectors facing the industry (e.g. CWE 25 or OWASP Top 10), be able to describe an attack, give a generic example of the payload, describe what a successful exploitation/impact looks like, and what best practice remediation is.

Preferred Technical and Professional Expertise
- Certifications / Credentials - CISSP (preferred), CCNP/CCIE (preferred), CCSP, CISA/CRISC/CISM.

Being an IBMer means you’ll be able to learn and develop yourself and your career, you’ll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.

Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.

Are you ready to be an IBMer?



  • Bengaluru, Karnataka, India slice Full time

    About the Role:At slice, we are seeking a highly skilled Cyber Security Compliance Professional to join our team. This is an exciting opportunity for a motivated individual with exceptional interpersonal skills to support the Head of Cyber Security and Compliance in planning and coordinating the implementation of compliance requirements.The ideal candidate...


  • Bengaluru, India MNR Solutions Full time

    We are looking for a skilled Information Security Risk and Compliance professional to join our team in Bangalore or Chennai. The ideal candidate will have a strong background in information security, risk management, and compliance frameworks. This role will focus on identifying, assessing, and mitigating security risks while ensuring adherence to regulatory...

  • IT Compliance Officer

    3 months ago


    Bengaluru, Karnataka, India cycatz Full time

    **Job Description: IT Compliance Officer & Security Awareness Coordinator** **Position**: IT Compliance Officer **Location**: Bangalore **(Work from Office) Department**: IT / Compliance **Type**: Full-time **Experience**: 1 to 3 yrs. **About Cycatz**: Cycatz offers highly reliable and efficient cyber security deliverables to all our valued customers on...

  • Cyber Security Intern

    6 months ago


    Bengaluru, Karnataka, India HKIT Security Solutions Full time

    **Job Title: Cybersecurity Intern** As a Cybersecurity Intern, you will work closely with our cybersecurity team to assist in various tasks related to ensuring the security and integrity of our organization's digital assets. You will gain hands-on experience in identifying and mitigating cyber threats, implementing security measures, and analyzing security...


  • Bengaluru, Karnataka, India Philips Full time

    **Job Title**: IT Security Professional Philips is a global leader in health technology, committed to improving billions of lives worldwide and striving to make the world healthier and more sustainable through innovation. Driven by the vision of a better tomorrow. But it’s not just what we do, it’s who we are. We are 80,000, wonderfully unique...


  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** **Summary** Cloud Lifecycle Management Application Management team is providing central tools and architectures for provisioning and operating various SAP Cloud solutions. One of our main tools is the Service Provider Cockpit (SPC), which is the de-facto standard suite for service operations in SAP’s major cloud units like...


  • Bengaluru, Karnataka, India Zanskar Securities Pvt Ltd Full time

    Zanskar Securities is a leading algorithmic brokerage firm based in Bangalore, specializing in cutting-edge trading technologies. Our mission is to innovate the financial markets through advanced quantitative models and financial engineering. We are a team of quants, engineers, and infrastructure experts dedicated to delivering high-performance trading...

  • Security Officer

    1 month ago


    Kalyan Nagar, Bengaluru, Karnataka, India Black Belt Security Group Full time

    **Job Title**: Security Training Officer **Department**: Security **Reports To**: Head of Security / Security Manager **Job Summary**: The Security Training Officer is responsible for developing, implementing, and overseeing comprehensive training programs for the security team. This position ensures that all security personnel are thoroughly trained and...


  • Bengaluru, Karnataka, India Manipal Hospitals (MHEPL) Full time

    About the RoleAt Manipal Hospitals (MHEPL), we are seeking an experienced IT Security Compliance Manager to join our team in Bangalore, India. This role is responsible for ensuring the organization's information systems and technologies meet the highest security standards.Key Responsibilities:Risk assessment: Identify vulnerabilities in our information...

  • Security Officer

    2 weeks ago


    Bengaluru, Karnataka, India Dicovery facility and security services Full time

    The Security Officer ensures the safety and security of people, property, and assets within their assigned area. This role involves monitoring premises, responding to incidents, enforcing safety policies, and providing excellent customer service to staff and visitors. **Job Types**: Full-time, Permanent Pay: ₹15,000.00 - ₹20,000.00 per...


  • Bengaluru Rural, India Saaki Argus & Averil Consulting Full time

    At Saaki Argus & Averil Consulting, we are seeking a talented Data Security Professional to join our team.This role plays a pivotal part in safeguarding our organization's sensitive data and ensuring robust security measures are in place to protect against cyber threats and breaches.The Data Security Professional will work closely with our IT teams,...


  • Bengaluru, Karnataka, India IBM Full time

    Introduction At IBM, work is more than a job - it's a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better, but to attempt things you've never thought possible. Are you ready to lead in this new era of technology and solve some of the world's most...


  • Bengaluru, Karnataka, India Muthoot Fincorp Ltd. Full time

    Job SummaryMuthoot Fincorp Ltd. is seeking an experienced Cloud Security Professional to join its team. As a key member of the Information Security team, you will be responsible for ensuring the security and compliance of our cloud-based infrastructure.About the RoleThis is a Pan India Individual Contribution role, requiring continuous communication with...


  • Bengaluru, Karnataka, India Locus.sh Full time

    **Who are we?** - Locus.sh is a leading-edge technology company dedicated to solving the most challenging problems in logistics and supply chain. Our ambition? To revolutionize the supply chain realm through cutting-edge technology, enabling smarter, automated decision-making. From dispatch management and carrier orchestration to route optimization and...

  • Security Field Officer

    3 months ago


    Bengaluru, Karnataka, India VULTURE SECURITY AND FACILITY SERVICES Full time

    We required immediately Security Field Officer Experience : 2 to 6 years Location : Peenya Industrial Area Salary : 25000 to 30000 Vehicle : Two wheeler is must Schedule: - Day shift Supplemental Pay: - Commission pay - Performance bonus **Education**: - Higher Secondary(12th Pass) (preferred) **Experience**: - total work: 5 years (preferred) -...

  • Security Guard

    6 months ago


    Kengeri, Bengaluru, Karnataka, India Maxipower security and allied services Full time

    Urgent Requirement security Supervisor and security guard **Salary**: ₹14,000.00 - ₹19,000.00 per month Schedule: - Rotational shift **Education**: - Secondary(10th Pass) (preferred) **Experience**: - total work: 1 year (preferred) - Security: 1 year (preferred) **Language**: - English (preferred) - Hindi (preferred) Ability to Commute: -...


  • Bengaluru, India Siemens Technology and Services Private Limited Full time

    Dear Aspirant! We empower ourpeople to stay resilient and relevant in a constantly changing world. We’relooking for people who are always searching for creative ways to grow andlearn. People who want to make a real impact, now and in the future. Does thatsound like you? Then it seems like you’d make a great addition to our vibrantinternational team. ...


  • Bengaluru, Karnataka, India SAP Full time

    **We help the world run better** At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Bengaluru, India Siemens Technology and Services Private Limited Full time

    Dear Aspirant! We empower ourpeople to stay resilient and relevant in a constantly changing world. We’relooking for people who are always searching for creative ways to grow andlearn. People who want to make a real impact, now and in the future. Does thatsound like you? Then it seems like you’d make a great addition to our vibrantinternational team. ...


  • Bengaluru, Karnataka, India Manipal Hospitals (MHEPL) Full time

    About Manipal Hospitals (MHEPL)We are a pioneer in healthcare, serving over 5 million patients annually. Our integrated network spans across 17 cities with 33 hospitals and 9,500 beds.Join our team as an IT Security Compliance Specialist to ensure the security of our information systems and technologies. Your role will involve risk assessment, security...