
Vulnerability Assessment Consultant-2
3 days ago
The Information Security Consultant will support planning, execution, and reporting of operational and system IT internal controls and risk management within the company.
This role will act as a point of contact for Cybersecurity Governance, Risk, and Compliance. The role will work closely with the Technology functional teams and internal business lines in the day-to-day operational delivery of the overall Cybersecurity Compliance program.
Teaming with the Cybersecurity Compliance Manager, the Information Security Consultant will:
- Monitor changes in business processes, information systems, management, and operations, and accordingly maintain an assessment of risk.
- Build and maintain productive relationships with process owners.
- Through effective leadership, ensure audits of control effectiveness and design and other projects are completed in an efficient manner, and within established deadlines.
- Through the effective review of department work, ensure that the assessments of the internal control structure related to processes audited are supported through sufficient and adequately documented evidence.
- Continually evaluate the efficiency and effectiveness of the internal controls and department functions, and identify areas of improvement.
- Assist with internal investigations.
- Promote good practice of Information Security Compliance to staff and associated contractors.
- Provide direct and specific guidance to the department internal control process owners as appropriate for each process owner of the department and the work being performed.
- Perform risk assessments related to controls in scope for work being performed.
Responsibilities
- Maintain awareness of current compliance, audit professional standards and any associated legislation changes, and apply where appropriate to the internal IT controls and audit function.
- Maintain awareness of current issues and significant changes within the business environment and business processes.
- Periodically determine the need for revisions to control processes.
- Demonstrate effective interaction with all levels of management and business partners.
- Review specific control risk assessments to ensure efficiency and effectiveness in addressing key risks associated with the respective auditable entity or entities.
- Review risk questionnaire submissions to identify key risks associated with the respective vendor/service and work with stakeholders to mitigate and advise.
- Ensure that appropriate communication has been made in advance with compliance and internal process & service owners regarding the timing and logistics of each audit and review.
- Anticipate problems and obstacles to the timely and efficient completion of audits and compliance reviews. Recommend solutions to anticipated and incurred problems and obstacles impeding the timely completion of such audit and reviews.
- Through an understanding of internal controls, standards and applicable policies, procedures, and country regulations, review evidence to ensure the assessment of the effectiveness and efficiency of internal controls is adequate and sufficiently supported and documented, and the departmental and professional standards are adequately upheld.
- Ensure issues and exceptions are fully identified and properly defined, and recommendations are adequately formulated to address the root cause of identified issues in a beneficial manner.
- Ensure issues and recommendations are adequately and effectively communicated to owners on a proactive basis during the course of each audit or review.
- Review final process owners responses for adequacy and completeness.
- Ensure appropriate and timely follow-up audit work is performed to properly update the status of outstanding reported issues, and adequate communication is provided to management on a proactive basis.
- Use the firm's various methods of internal communication to direct colleagues and the wider organization to current, new policies and essential compliance information.
Sounds like you To apply you need to be:
Experience & Education
- Experience in evaluating third parties for the presence of fundamental information security controls.
- College diploma or university degree in the field of computer science, information systems, or computer engineering.
- Exposure to any GRC technologies to perform risk management.
- Good understanding of compliance standards/framework like ISO 27001/27002, NIST, SOC1, SSAE16/SOC2, CIS.
- Knowledge of technical domains such as network security, cloud security, application security, and penetration test concepts.
- Experience in conducting risk assessments and applying the concept of inherent and residual risk in order to draw appropriate conclusions and articulate the same to non-technical audiences.
- Minimum of 4 years IT experience; or equivalent combination of education and experience.
- Minimum of 4 years experience contributing to the success of a range of midsize-to-large multi-country initiatives.
- Experience in designing and managing compliance and risk management controls and processes in day-to-day IT operations and projects.
- Experience in undertaking and reporting on internal audits of IT operations, applications, and projects.
- Experience working in the corporate sectors (financial services, telecommunications, or utilities).
- Experience working in the real estate services industry.
Technical Skills & Competencies
- High level of written and oral English communication skills.
- High level of analytical, conceptual, and problem-solving abilities.
- Affable, credible, and can communicate effectively with clients and colleagues.
- Good research skills and the ability to manage details.
- Ability to present ideas in user-friendly language.
- Ability to effectively prioritize and execute tasks in a high-pressure environment.
- Team player with experience working in a team-oriented, collaborative environment.
- Quality-focused and highly flexible.
- Thinks ahead and anticipates problems, issues, and solutions.
Certifications
- Certified Information Systems Auditor (CISA).
- Information Technology Infrastructure Library (ITIL) Foundation.
-
Vulnerability Assessment and Penetration Tester
4 weeks ago
Bengaluru, Karnataka, India Securseed Full timeCompany Overview:Securseed InfoSec is a leading cybersecurity firm dedicated to providing cutting-edge solutions to protect our clients' digital assets and sensitive information. We specialize in comprehensive vulnerability assessments, penetration testing, and security consulting services that empower organizations to fortify their defenses against evolving...
-
Vulnerability Assessment and Penetration Tester
4 weeks ago
Bengaluru, Karnataka, India Securseed Full timeCompany Overview:Securseed InfoSec is a leading cybersecurity firm dedicated to providing cutting-edge solutions to protect our clients' digital assets and sensitive information. We specialize in comprehensive vulnerability assessments, penetration testing, and security consulting services that empower organizations to fortify their defenses against evolving...
-
Vulnerability Assessment and Penetration Tester
3 weeks ago
Bengaluru, Karnataka, India Securseed Full timeCompany Overview: Securseed InfoSec is a leading cybersecurity firm dedicated to providing cutting-edge solutions to protect our clients' digital assets and sensitive information. We specialize in comprehensive vulnerability assessments, penetration testing, and security consulting services that empower organizations to fortify their defenses against...
-
Bengaluru, Karnataka, India NTT Ltd. Full time US$ 80,000 - US$ 1,20,000 per yearMake an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive. Your day at NTT DATAThe Senior...
-
Bengaluru, Karnataka, India beBeePenetration Full time ₹ 1,00,00,000 - ₹ 1,50,00,000Vulnerability Assessment and Penetration Testing Leadership RoleThis senior leadership position focuses on guiding the Vulnerability Assessment and Penetration Testing (VAPT) team to deliver high-quality security assessments for applications, networks, cloud environments, and infrastructure across the organization. The ideal candidate will lead end-to-end...
-
Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000Senior Cybersecurity Expert - Penetration Testing and Red TeamingWe are seeking a highly skilled and experienced Senior Cybersecurity Expert to join our team. As a penetration tester and red teamer, you will be responsible for conducting end-to-end vulnerability assessments of web applications, mobile apps, APIs, and network infrastructure.Key...
-
Bengaluru, Karnataka, India beBeeSecurity Full time US$ 10,32,400 - US$ 14,12,200As a Senior Vulnerability Assessment and Penetration Testing (VAPT) and Red Teaming Professional, you will be responsible for identifying and exploiting vulnerabilities in our systems to strengthen our security posture. Your expertise in simulating real-world attacks will help us improve our defenses and stay ahead of emerging threats.Key...
-
Vulnerability Management process
2 days ago
Bengaluru, Karnataka, India Bounteous Full timeWe are seeking a skilled and experienced Vulnerability Management process to join our dynamic team. Location: Bangalore & Pune (Hybrid Model) Experience: 5 - 8 Years NP: Immediate joiners Requirement: Perform Vulnerability assessment & Policy Compliance using leading Vulnerability Scanning solutions like Qualys etc. Perform Vulnerability assessments &...
-
Bengaluru, Karnataka, India beBeeVulnerabilityManagement Full time ₹ 1,00,00,000 - ₹ 2,00,00,000Job TitleAn experienced and skilled Vulnerability Management professional is required to join our team. This individual will be responsible for performing vulnerability assessments, policy compliance, and providing technical advice and support on remediation.">Perform Vulnerability assessment & Policy Compliance using leading Vulnerability Scanning solutions...
-
Vulnerability Assessor
1 day ago
Bengaluru, Karnataka, India beBeeCybersecurity Full time ₹ 20,00,000 - ₹ 25,00,000Job Title: Cybersecurity SpecialistWe are seeking a skilled and detail-oriented cybersecurity professional to join our team. The ideal candidate will have hands-on experience in performing vulnerability assessments and penetration testing across web applications, networks, infrastructure, and mobile platforms.Key Responsibilities:Perform comprehensive...