Information Security Expert

6 days ago


Pune Maharashtra, India amdocs Full time

**Job ID**:198944
**Required Travel**: Minimal
**Managerial - No**
**Location**:India
- Pune (Amdocs Site)**

**Who are we?**:
**In one sentence**:
As Information Security Team Lead specializing in DevSecOps, you'll partner with Amdocs development teams to seamlessly integrate security tools into our CI/CD pipeline.
You'll oversee the security tools environment while driving automation initiatives through scripting, test development, and monitoring dashboards.

The role requires staying ahead of emerging security code scan threats and collaborating with teams to implement robust protection measures. You'll guide R&D teams in adopting secure development practices and provide expert security consultation to diverse teams across product development, engineering, and services departments.

**What will your job look like?**:

- Manage a team of DevSecOps security analysts and implementation engineers
- Implement DevSecOps tools in all product dev environments
- Follow up with staff members to ensure completion of security-related tasks
- Manage and maintain Security health check of the integrated automation.
- Provide professional support for the developed automations, responding to incidents to avoid system outages or restore availability to meet SLAs.
- Analyze the implementation needs and provide effort estimation to the users
- Stay abreast of industry best practices (Research new technologies) and contribute ideas for improvements in DevOps practices, delivering innovation through automation.
- Tracks and reports on the test execution in a timely manner with attention given to achieving a high level of quality.
- Liaise with development and infra teams to get the defect resolutions
- Onboard new hires, train and share knowledge, take an active role in technical mentoring and elevating team knowledge.
- Working with external vendors for support, manage the relevant vendor employees and make sure the support is performed as planned
- Maintaining hardware and software deployment and POC planning

**All you need is...**:
**Must-Have**
- 3+ years of experience in leading a team (team of security analysts is preferrable)
- 5+ years of relevant experience in information Security DevSecOps
- Total experience - 6-8 years
- Extensive expertise in Application security and security architecture area.
- Hands on experience in SAST Tools (e.g. Checkmarx), Container Scanning tools (Twistlock, Wiz)
- Expertise in Security code reviews and onboarding process for managing false positives
- 5+ years’ experience in FOSS security issues and security hardening (CIS benchmarks)
- 3+ years’ experience in setting up continuous integration and continuous delivery systems
- 2-3 years’ experience with continuous-integration tools such as Hudson/Jenkins, LiquiBase, Github actions
- Understanding of build process, best practices and tools such as Maven, Jenkins pipeline, groovy
- Knowledge of OWASP top 10 list of vulnerabilities, NIST SP-800-xx, NVD, CVSS scoring etc concepts
- Great Communication skills - (Ability to communicate with a Developer, a Manager or Director level).
- Project Management Skills
- 2-3 years’ basic understanding of Cloud Platforms
- BS in Computer Science, or equivalentWorking in Agile/Scrum team**Nice to have**:

- Familiarity with REST Services, Service Oriented Systems and Micro-services architecture
- Scripting skills in at least one of the following: Python, Django web framework, Perl, Ruby, shell (bash, ksh, csh)
- Knowledge in distributed systems, software and network security preferred.
- Sound Knowledge of TCP/IP protocol Stack, HTTP protocol, encoding standards, encryption technologies and development frameworks.
- 2+years of experience on docker /k8S

**Why you will love this job**:

- You will have the opportunity to work with the industry most advanced technologies and experts in a global company
- You will have opportunities to evolve yourself in the future of all cutting-edge technologies and business trends.
- You will be working with a great team

**Amdocs is an equal opportunity employer. We welcome applicants from all backgrounds and are committed to fostering a diverse and inclusive workforce



  • Pune, India amdocs Full time

    **Job ID**:179893 **Required Travel**: Minimal **Managerial - No** **Location**:India - Pune (Amdocs Site)** **Who are we?**: **In one sentence**: The Information Security Lead develops, maintains, and publishes required information security standards, procedures, and guidelines per domain of responsibility. Responsible for conceiving and executing...


  • Pune, India MSCI Inc Full time

    **Your team responsibilities** **What we will offer you**: - At MSCI, we provide competitive benefits programs in every region in which we do business. While our benefits plans vary in availability in our different locations, we offer a broad range of benefits that are part of the value you receive as a MSCI employee. Wherever you are with us, you will...


  • Pune, India Deutsche Bank Full time

    **Job Title: Associate **- Risk Assessment** **Location: Pune, India **Job Description Summary** Business Services Organization (BSO) supports all divisions with information security relevant areas. BSO is seeking ISO for its Information Security Services team for Risk assessment services. **What we’ll offer you** As part of our flexible scheme, here...


  • Pune, Maharashtra, India Deutsche Bank Full time

    Job Title Information Security Specialist - AVP Location Pune India Role Description We are seeking an accomplished Information Security Specialist Assistant Vice President to lead engineering configuration and assurance activities for Microsoft Purview the enterprise data governance and protection platform In this high-impact role you will design and...


  • Pune, Maharashtra, India Verve Group Full time

    **Who We Are** **Who You Are** We're searching for a driven and reliable information security professional to be the backbone of our Information Security Management System (ISMS). In this crucial role, you'll be the bridge between our business and engineering teams, ensuring the CISO's security vision is translated into practical action. You'll translate...


  • Pune, Maharashtra, India Dataseat Full time

    **Hybrid** - ** Pune**,** **Mahārāshtra**,** **India** **IT Operations**: **Job description**: **Who We Are** Verve Group has created a more efficient and privacy-focused way to buy and monetize advertising. Verve Group is an ecosystem of demand and supply technologies fusing data, media, and technology together to deliver results and growth to both...


  • pune, India Threadneedle Software Full time

    We are seeking a proactive and detail-oriented Information Security Engineer to own and operate our information security program. This is a critical hybrid role responsible for maintaining our security and compliance posture across multiple frameworks (ISO 27001, ISO 27017, SOC 2) while also managing and implementing the technical security controls that...


  • Pune, Maharashtra, India ProcessLOGIX Consulting Pvt Ltd Full time

    **ProcessLOGIX Consulting Pvt Ltd** is hiring “Consultant”. Location: Bibewadi, Pune **Job Description**: - Good understanding of ISO 27001, experience in information Security controls designing, policy documentation, implementing best information security practices, compliance frameworks for Information Security. - Mapping and documenting processes...


  • pune, India Air Liquide Full time

    How will you CONTRIBUTE and GROW?As the AMEI DDS Information Security Officer your role will be to take the lead on Information Security for this scope, by advising teams regarding all forms of cyber risk and helping define plans to address them. As GDDS ISO, on top of standard ISO activities for the AMEI entity, you will act as the main point of contact of...


  • Pune, India MSCI Inc Full time

    **Your Team responsibilities** - MSCIs security operations team is looking to expand its team. Information Security Operator will provide critical management and reporting services on a variety of Information Security platforms for on-prem and on-cloud technologies. This includes: configuration, tool creation (scripts, procedures, and templates), defining...