Mode - Hybrid (3 days WFO)
Job Type - Full time (3 months payroll - Little Big Connections)
Role - Infrastructure Secu rity Office
Location - Pune
Key Responsibilities
- Monitor and follow security KPIs, including vulnerability scores and CSPM alerts; drive and track corrective actions.
- Oversee cybersecurity for SLS Infrastructure projects, including configuration hardening, remediation of security alerts, and integration of security controls into project lifecycles.
- Organize and manage audits and risk assessments performed by external cybersecurity firms; coordinate remediation plans and ensure timely closure of findings.
- Conduct annual security reviews covering password policies, backups, access rights, disaster recovery plans (DRP), and other foundational controls.
- Review technical documentation (HLD, LLD, SOP, DRP, ) and support fulfilment of ISO 27001 obligations and evidence requirements.
- Review and approve network flow openings and security change requests submitted to the Infrastructure Cyber Security team.
- Prepare and maintain security reporting on a weekly and monthly cadence for stakeholders, highlighting trends, risks, and remediation status.
Collaboration & Customer Engagement
- Coordinate with other Infrastructure support teams (Level 2-4), standardise processes, tools, and governance, ensuring seamless collaboration and fostering knowledge sharing and best practices.
- Collaborate regularly with the Infrastructure Operations Manager and Service Delivery Managers to ensure alignment on service priorities, capacity planning, and customer requirements.
- Build and maintain strong relationships within global SLS Infrastructure teams to ensure Infrastructure services meet evolving business and team needs.
- Actively contributing on the ISO 27001 certification and its roadmap.
- Cost optimization and capacity planning in collaboration with our FinOps team.
- Participate on our backup and disaster recovery strategy.
PROFILE Academic Background & Experience
- Bachelor s or Master s degree in Computer Science, Engineering, or related fields.
- Minimum 7 years of professional experience in cybersecurity roles after graduation.
Behavioural Capabilities
- Autonomy: Be a problem solver.
- Builder: Ability to grow and document expertise on the product itself and to capitalize knowledge of the business needs through any user interaction. A Bouygues group company
- Value driven: Ability to identify and prioritize opportunities to extract value from product features and data beyond its initial scope.
- Team player: Ability and willingness to cooperate with other product owners and analysts inside or outside the team in order to combine offers, share expertise and identify even more value opportunities.
- Rigorous and detail oriented with strong organizational skills.
- Curious and proactive, eager to investigate root causes and emerging threats.
- Collaborative and communicative, able to drive cross-functional initiatives and explain technical risk to non-technical stakeholders.
Skills
- Fluent English speaking and writing at minimum C1 level
- Strong analytical and problem-solving skills
- Knowledge of security architecture principles and components, including cloud platforms, networking, devices management, server management, identity and access management, and more.
Cloud Security
- Strong technical and security knowledge of at least one cloud provider (AWS or Azure). Knowledge of both AWS and Azure is highly desirable.
- Experience with Cloud Landing Zones, cloud security posture management (CSPM), and cloud-native security controls.
Systems And Network Security
- Solid systems and security fundamentals (OS hardening, IAM, backup/DRP concepts, logging and monitoring).
- Practical experience with network security technologies: SD-WAN, NAC, IPAM, ZTNA/SASE, and firewall rule management.
- Knowledge on TUFIN Network Orchestration tool is a nice to have
Governance, Compliance, And Measurement
- Proven ability to manage external audits and risk assessments, translate findings into remediation plans, and track closure.
- Familiarity with ISO 27001 requirements and documentation practices.
- Experience defining, tracking, and reporting security KPIs and operational metrics.