Specialist I
4 days ago
5 - 7 Years
1 Opening
Bangalore
Role descriptionRole Proficiency:
With strong knowledge of various applicable compliance standards independently handle internal/external compliance audits and VAPT/Red Teaming assignments. Involve more in the risk assessment and remediations. Effectively communicate with customer to understand the requirements and clearly convey the requirements to team. Handle the assigned tasks with minimal supervision
Outcomes:
Should handle the assigned tasks from the allocated domain with minimal guidance from the leads. (Domain Examples: BCMS Risk assessment incident management HITRUST SOC customer assurance Awareness activities Data Privacy VAPT Red Teaming etc.)
Handle (with minimal guidance from the supervisors) internal/external compliance audits to ensure compliance with ISO 27001/ISO 22301/ISO 27701 requirement as well as process specific requirements.
Responsible for the effective documentation of internal audits (reports) external audit documentation.
Help the team for effective external audit facilitation and the related responsibilities.
Point out the non-conformance areas related to information security with assistance from the supervisor.
Ensure that policies are updated as and when required and eliminate the discrepancies of old policy versions.
Conduct information security awareness training programs for all the employees contractors and approved system users.
Evaluate IT Controls' implementation and perform Risk Assessment.
Carry out technical vulnerability assessments of IT systems and processes to identify potential vulnerabilities. Make recommendations to control any risks identified and ensure that they are implemented.
Collect review and analyse latest technologies and tools.
Analyse user requirements and steps required to perform the VAPT/Red Teaming.
Interact with and communicate detailed technical requirements to the team.
Lead Security Assessment scoping independently based on security standards like OWASP.
Lead Web Application Penetration Testing Network Penetration Testing Mobile Penetration Testing and Code Review independently based on the guidance from leads.
Learn and understand existing and emerging security management practices.
Independently handle the evidence collection from multiple teams as part of any external audits.
Assist in customer assurance activities.
Assist in the process automation activities.
Mentor and Lead A band employees.
Measures of Outcomes:
Number of internal audits and security assessments conducted per year.
Number of external audit facilitation activities.
Number of Threats/Risks/Vulnerabilities reported per year.
Number of NCs in external audits on assigned domains.
Number of areas of responsibility on cross domains.
Performance of ISMS/BCMS/PIMS/QMS in the responsible centre/regions.
Awareness activities conducted and the percentage of adoption in the responsible centre/regions.
Noticeable initiatives taken to improve the process.
Less than two stake holder escalations.
More than three appreciation from the stakeholders/supervisors.
Outputs Expected:
Documentation:
- Policy and Procedure amendments
Awareness training materials
Presentations decks for internal/ external discussions
Audit /Security Assessment reports
Process:
Internal ISMS audits – independently carry out audits
prepare audit reports and ensure timely closure of audit reportsCompliance Audits – Representation in certification audits
conduct preparatory session and evidence collectionRisk Assessment - IT Controls' implementation and assess risks
Infosec activities – training material
conducting sessions
co-ordinate with other teams for trainings conductingCustomer Assurance – independently handle customer assurance requirements and evidence collection
Policy – Identify discrepancies in the policies and addressing it
Vulnerability Assessment and Penetration Testing/Red Teaming Activities
CM activities
Executing other location responsibilities
Monitoring:
- Mentoring and leading A band employees
Training or certifications:
- 2 per year (1 certification and minimum 1 of UST trainings on ISMS domains)
Skill Examples:
Ability to understand prioritize and escalate tasks to resolve issues quickly and make decisions
Able to interpret all scenarios applicable to the business for identifying the potential risks associated with various functions/services.
Proficiency in Network Security Controls' implementation like IAM IPS/IDS E-Mail Security Controls Cloud Security Controls etc.
Proficiency in Technical Vulnerability Assessment and Management.
Strong compliance auditing knowledge.
Detail oriented customer oriented result delivery oriented analytical thinking
Strong Excel and Dashboard skills.
Excellent Presentation and communication skills
Excellent verbal and written communication skills required including the ability to effectively communicate in both highly technical and non-technical environments
A great problem solver with the knack of coaching others to do the same
Good at working in a team and with other teams
Good time management
A desire for continuous learning and skill development.
Self-motivated and enthusiastic
Knowledge Examples:
Should have a strong understanding of concepts of Information Security Business Continuity and Data Privacy VAPT Red Teaming and various compliance standards.
Knowledge on ISO and other Compliance standards efficient to evaluate the security controls.
- Knowledge on ISO 22301/27001/9001/27701 Risk Management incident management awareness activities customer assurance etc.
- Knowledge on standard SDLC and project management life cycles.
- Knowledge on the operations of various functional units like HR REFM IT Finance etc. and units involved in IT Asset lifecycle management.
- Expert on security testing standards like OWASP Top 10 SANS 25 etc.
- Good at OWASP cheat sheets and other security frameworks.
- Expert on Linux commands.
- Expert on Scripting Languages like Shell Script Python etc.
- Development and Testing knowledge would an added advantage.
- Hands on experience in RSA Archer Postman Burp Suite Nessus Nmap Genymotion MobSF Drozer etc.
- Good to have Certifications like ISO 27001/22301/9001/27701 Lead Auditor/Implementor CISA CRISC SSCP ECSA (Practical) ECES CHFI OSEE etc.
Additional Comments:
Mandatory Skills:Windows OS, server Skill to Evaluate: Windows OS,Mac Os Developer, server Experience:6 to 8 Years Location:Bengaluru Job Description: Minimum experience of 6 years in engineering & operations of security & compliance of Windows Server OS and Mac OS environment Hands-on experience in analysing, testing and implementing security-related configurations such as OS security policies in Windows servers and Mac devices For Mac devices, hands-on experience in applying compliance policies on individual machines OR via Microsoft Intune's configuration profiles to enforce security settings Hands-on experience in analyzing OS security compliance data for both on-prem and cloud environments Knowledge in Center for Internet Security (CIS) Benchmarks Understanding of common IT issues Understanding of Waterfall and Agile processes and principles Good stakeholder management skills to communicate and support remediation of security issues Good communication and presentation skills Education Qualificaiton:Bachelor Degree Job Title: C&S Infrastructure Security Engineer – Windows server OS and Mac OS Roles & Responsibilities: Understand the existing Sony's secure configuration / hardening standards for Windows server OS and Mac OS Understand the existing security controls Implement and maintain hardening standards for Windows and macOS systems. Apply industry-standard benchmarks (e.g., CIS Benchmarks, NIST 800-53, DISA STIGs) to secure operating systems. Configure system settings, including user accounts, file permissions, services, and network configurations, to minimize attack surfaces Develop automation scripts (e.g., PowerShell for Windows, or Shell scripting for macOS) to streamline hardening tasks. Work with IT administrators and DevOps teams to integrate hardening practices into system deployment workflows. Conduct training sessions on secure configuration practices and hardening standards. Stay updated on emerging threats and vulnerabilities affecting Windows and macOS platforms.Research and evaluate new security controls that are applicable to Windows server OS and Mac OS environments Execute proof of concept for new controls (if required) Build proper documentation for new technologies & remediation steps Engages with other IT teams and stakeholders to ensure a consistent approach for security implementation and provide organizational support across the enterprise Collaborate with team-mates and understand the threats, vulnerabilities and risks to the enterprise Establish and manage non-production and production environments for testing Own the end-to-end technical design, unit testing, and the maintenance of the hosting environment Participate in daily stand-up meetings and project meetings to contribute to achieve project deliverables within required timeframe Project Details: The person in this role is the primary infrastructure security engineer, maintains a strong people network with the stakeholders, is conversant with key assets & their operations and is instrumental in the analysis, research and testing of infrastructure security tools/functions globally.
SkillsWindows,Mac OS,Developer,Server, Powershell / Shellscript
About USTUST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world's best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients' organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.
-
Specialist I
2 weeks ago
Bengaluru, Karnataka, India Philips Full time ₹ 4,00,000 - ₹ 12,00,000 per yearJob TitleSpecialist I - Product SecurityJob DescriptionJob Title: Specialist I - Product SecurityYour Role:Perform Ethical hacking and penetration testing on hardware components, embedded systems, and interfaces (e.g., JTAG, UART, SPI, I2C).Performs Ethical Hacking into products/solutions.Analyze and test wireless communication protocols (Bluetooth Classic,...
-
Specialist I
2 weeks ago
Bengaluru, Karnataka, India Philips Full time ₹ 6,00,000 - ₹ 18,00,000 per yearJob TitleSpecialist I - Product SecurityJob DescriptionJob Title: Specialist I - Product SecurityYour Role: • Perform Ethical hacking and penetration testing on hardware components, embedded systems, and interfaces (e.g., JTAG, UART, SPI, I2C). • Performs Ethical Hacking into products/solutions.• Analyze and test wireless communication...
-
Client Services Support Specialist I
22 hours ago
Bengaluru, Karnataka, India ATS Global Full time ₹ 4,00,000 - ₹ 8,00,000 per yearHiring Client Services Support Specialist (I/II) with 13 years of inbound American voice experience. Must have excellent communication, active listening, typing, and MS Office skills. Night shift, work from office. Great perks & benefitsOffice cab/shuttleHealth insuranceFood allowanceAnnual bonus
-
TMF Specialist I
4 days ago
Bengaluru, Karnataka, India Allucent Full time ₹ 40,00,000 - ₹ 80,00,000 per yearAt Allucent, we are dedicated to helping small-medium biopharmaceutical companies efficiently navigate the complex world of clinical trials to bring life-changing therapies to patients in need across the globe.We are looking for a TMF Specialist to join our A-team. The TMF Specialist I coordinates the indexing of documents within the Trial Master File at...
-
Site Services Specialist I
1 week ago
Bengaluru, Karnataka, India ICON plc Full time ₹ 5,00,000 - ₹ 12,00,000 per yearSite Services Specialist I - India, Bangalore - Hybrid, Office-BasedICON plc is a world-leading healthcare intelligence and clinical research organization. We're proud to foster an inclusive environment driving innovation and excellence, and we welcome you to join us on our mission to shape the future of clinical developmentWe are currently seeking a Site...
-
Content Specialist I
1 week ago
Bengaluru, Karnataka, India Mouser Electronics Full time ₹ 2,00,000 - ₹ 4,00,000 per yearGreeting From TTITitle: Content Specialist ILocation: India (Bangalore)This role would be supporting TTI (Mouser's Parent Company). The Content Specialist will support the eBusiness and x teams within the Supplier Marketing and Product Management department. Assists with the companys online content strategy, communication outreach, and other related...
-
Digital Production Specialist I
6 days ago
Bengaluru, Karnataka, India Kaplan Full time ₹ 40,00,000 - ₹ 80,00,000 per yearJob Title Digital Production Specialist I (Hybrid)Job DescriptionFor more than 80 years, Kaplan has been a trailblazer in education and professional advancement. We are a global company at the intersection of education and technology, focused on collaboration, innovation, and creativity to deliver a best in class educational experience and make Kaplan a...
-
Specialist I, Procurement
4 days ago
Bengaluru, Karnataka, India NextGen Federal Systems Full time ₹ 4,00,000 - ₹ 12,00,000 per yearJob Description:The Specialist I, Procurement, is responsible for supporting the organization's purchasing activities by managing the procurement process from requisition to receipt. This role ensures timely processing of the purchase of goods and services.Process purchase requests, prepare purchase orders, and ensure timely processing of goods and services...
-
Support Specialist I, Customer Support
7 days ago
Bengaluru, Karnataka, India Vimeo Full time ₹ 9,00,000 - ₹ 12,00,000 per yearAt Vimeo, we seek passionate individuals ready to elevate customer experiences. As a Support Specialist I, you will be the frontline liaison, ensuring that our customers receive timely and empathetic support.What you'll do:Efficiently handle a variety of customer queries, prioritizing quick resolutions at the first touchpoint. Rotate through our 24x7 shifts...
-
Support Specialist I, Customer Support
7 days ago
Bengaluru, Karnataka, India Vimeo Full time ₹ 5,00,000 - ₹ 12,00,000 per yearAt Vimeo, we seek passionate individuals ready to elevate customer experiences. As a Support Specialist I, you will be the frontline liaison, ensuring that our customers receive timely and empathetic support.What you'll do:Efficiently handle a variety of customer queries, prioritizing quick resolutions at the first touchpoint.Rotate through our 24x7 shifts...