Assoc. Dir. DDIT ISC VulnSvcs role

1 day ago


Hyderabad Office, India Novartis Full time ₹ 20,00,000 - ₹ 25,00,000 per year

Band

Level 5

Job Description Summary

The role is part of DDIT ISC Security Operations in Vulnerability Services team. The person will focus on reducing risk exposure from security vulnerabilities through design, implementation and operations of VulnSvcs products that implement the VulnSvcs processes. Plays an active role in analyzing vulnerabilities for reduction and management.
Objective of this role is to implement VulnSvcs processes through technology engineering, operations and ensuring effective use for wide array of stakeholders and users. Actively engage and work with VM team to analyze vulnerabilities posture and reduction. Role requires experience with vulnerability management/remediation solutions setup, end user focused product mgmt. and operations through strong collaboration with cross functional teams. Acumen with vulnerabilities/configuration issues, remediation/mitigation analysis, risk assessment, influencing stakeholders for timely mgmt., and operating security service is key.
-Oversees security operations service line, technology governance and external/internal interfaces in accordance with service operations and management processes.


 

Job Description

Major accountabilities:

  • As a lead, own the design, implementation, roadmap, and operational oversight for VulnSvcs products to centralize and or operate the related processes:
  • Ownership of VulnSvcs business requirements, translating to technical solution requirements, working with cross functional teams to manage implementation.
  • Proactively monitor and govern engineering and support operations of the VulnSvcs solutions such as ServiceNow (SecOps module, custom modules), exposure mgmt. independently and aligned external/internal individuals.
  • Identify problem areas and drive identification of root causes as well as sufficient prevention of recurrences.
  • Lead product vendor/CSM connects to address Novartis requirements/issues.
  • Plan, influence and deliver VulnSvcs products roadmap and maturity.
  • Stay up to date with latest product features, perform POCs, finalize implementation requirements, ensure planned production.
  • Develop and maintain documentation of related process and best practices.
  • Provide security awareness and training to teams on VulnSvcs solutions and Mgmt.
  • Implement security policies, procedures, and standards to ensure the confidentiality, integrity, and availability of solutions from technical vulnerabilities.
  • Identify potential improvement areas for vulnerability remediation and shared learned lessons with application/development teams.
  • Monitor and prioritize security vulnerabilities through risk analysis to understand potential impact and translate vulnerability severity as security risk.
  • Flexibly support emergency response for 0-day vulnerability remediation.
  • Collaborate with various stakeholders from security operations, architecture, cyber, platform and application teams to achieve goals.
  • Defines remediation activities for security assessment gaps as they pertain to IT Security Management

Key performance indicators:

  • Stable, compliant, secure, and cost-effective operations measured by Availability, Performance, Capacity, Security Metrics -Responsiveness and Recovery Speed of critical incidents/issues in business -Learning Agility, ability to evaluate and launch new services and capabilities -Productivity gains and defect reduction through continuous improvement -Automation led Security Operations Services -Integration of Applications and Infrastructure into Centralized Security Platforms
  • Adequacy and maturity of VulnSvcs technology and processes.
  • Technical expertise proven in identifying, reviewing, and improving risk posture.
  • Ensure Application/project satisfied with the risk, security, and remediation advisory.
  • Reducing the number of vulnerabilities by adapting remediation wherever possible
  • Cross skill collaboration and feedback from the various stake holders

Minimum Requirements:
Work Experience:

  • 10+ years of overall working experience in information security preferably in Vulnerability Management, Security Patching and Security Operations domain.
  • At least 5+ years of relevant experience in security domain dealing majorly with vulnerability analysis, remediations, and assessments.
  • Experience with centralizing threat vulnerability management process & technologies.
  • Experience of sourcing complex IT services, product management and working closely with vendors for effective use of capabilities.
  • Demonstrated leadership skills through experience in middle management and/or engagement with large security/development program stakeholders.
  • Risk.
  • Accountability.
  • Strong cross functional leadership.
  • Relationship Management.
  • Strategy Development.
  • Operations Management and Execution.
  • Collaborating across boundaries.
  • Project Management.
  • Interactions with senior management.
  • People Leadership.

Skills:

  • SNOW SecOps and related vulnerability products integration.
  • Strong knowledge of security vulnerabilities in software and infrastructure, OWASP, SAMM, security frameworks, application architecture principles, security risk analysis and relevant domain areas.
  • Acumen in designing and guiding implementation of vulnerability management solution workflows, integration design of vuln detection tools, hands-on testing and ideation of related product features, product security operations.
  • Persuasive communication skills to effectively convey to both technical and non-technical stakeholders, and the ability to collaborate with cross-functional teams.
  • Strong problem-solving skills and the ability to work independently.
  • Strong understanding of metrics, KPI/KRI, SLAs, and dashboards for vulnerability management and providing executive reporting.
  • Escalation.
  • Information Security Audit.
  • Information Security Risk Management.
  • Quality Management.
  • Root Cause Analysis (Rca).
  • Sec Ops (Security Operations).
  • Vendor Management.

Languages :

  • English.

Skills Desired

Escalation, Information Security Audit, Information Security Risk Management, Quality Management, Root Cause Analysis (RCA), Sec Ops (Security Operations), Vendor Management

  • Hyderabad, Telangana, India Novartis Full time

    **Summary**: The role is part of Security Operations in Vulnerability Services team. The person will focus on reducing risk exposure from security vulnerabilities with major focus on solution design, architecture, and VulnSvcs products management. **About the Role**: Job Title : Assoc. Dir. DDIT ISC VulnSvcs - Location : Hyderabad - The role is part of...


  • Hyderabad, Telangana, India Novartis Full time

    394896BR **Assoc. Dir. DDIT Dev. TD RA**: India **About the role** Role Title: Assoc. Dir. DDIT Dev. TD RA Location: Hyderabad Role Purpose: - Senior Specialist for project delivery and/or operations in the given RA Publishing - Partner with Business Stakeholders and DDIT Strategic Business Partners for demand analysis, solution proposal/evaluation and...


  • Hyderabad, India Sandoz Full time

    Job Description Role: Assoc. Dir. DDIT Dev. GCO Tech. Design (Technical Business Analyst) Senior Expert for delivering projects and/or running operations in the specific business sub-function. Collaborate with Business Stakeholders and DDIT Strategic Business Partners for analyzing demand, proposing/assessing solutions and executing projects Lead the...


  • Hyderabad, India Novartis Full time

    387990BR **Assoc. Dir. DDIT IES ISM Change Mgt**: India **About the role** Location : #L1 Hybrid - Maintain a central source of information about the operational systems in scope and coordinate, control and monitor all changes to the environment to ensure operational stability. - A central cross tower role that operationally controls and drives Change...


  • Hyderabad, Telangana, India Novartis Full time

    **Summary**: Role Purpose: - Contribute to the development of architectural standards, and the direction and design of architecture for a business or technical domain. - Contribute to efforts to elaborate and communicate the architecture of the given domain and/or develop architectural solutions for projects and programs. **About the Role**: - Role Title:...


  • Hyderabad, Telangana, India Novartis Full time

    **Summary**: The role is part of DDIT ISC Security Operations in Vulnerability Services team. The person will focus on reducing risk exposure from security vulnerabilities with major focus on high risk, theme based and 0-day vulnerabilities emergency response and remediation. Flexibility with work schedule is critical. Analyze ongoing security...


  • Hyderabad, Telangana, India Novartis Full time

    394205BR **Assoc. Dir. DDIT Dev. BA US&DUs**: India **About the role** Role Title: Assoc. Dir. DDIT Dev. BA (US&DUs) Location: Hyderabad Role Purpose: This role will provide the Business Analysis needed to drive technology roadmap for S&G focusing and enabling decision making in the function that directly drives success of Novartis through more effective...


  • Hyderabad District, Telangana, India Novartis Full time

    Location : #L1 Hybrid 371713BR Our Information Security and Compliance (ISC) team provide a critical service to the Novartis Community, protecting information assets and ensuring compliance with internal and external ISC requirements. This team is looking for an “Associate Director, Country Information Security and Compliance” to join the team! Your...


  • Hyderabad, Telangana, India Novartis Full time

    395124BR **Assoc. Dir. DDIT IES Reliability Engg**: India **About the role** Location : #L1 Hybrid Your responsibilities include but not limited to: - NMMi / NOM administration and dashboard creations in production, create alerts in Splunk - Understanding of full stack monitoring and integration various data sources to create a fullview - Participate in...


  • Hyderabad, Telangana, India Novartis Full time ₹ 45,00,000 - ₹ 90,00,000 per year

    Job Description SummaryAs Assoc. Dir. DDIT DEV RA TD you will create the detailed IT solution/service design, based on functional specifications to meet quality and performance requirements and technical constraints. Responsible for detailed design, development, and delivery of system solutions for Regulatory Affairs (RA). You will engage with global...