A leading HR solutions firm is looking for an Information Security Specialist in Mumbai, India. This role involves ensuring compliance with security policies and managing incident responses. The ideal candidate should have a relevant bachelor's degree and certifications like CISSP or CISM. Responsibilities include conducting risk assessments, monitoring networks for suspicious activities, and training employees on security best practices.
Qualifications
Hands-on experience in Security solutions, including End Point and Network Security.
Knowledge of securing operating systems like Windows and Linux.
Experience with secure coding practices and application vulnerability assessments.
Responsibilities
Oversee compliance with security policies and procedures.
Conduct regular risk assessments and manage incident responses.
Monitor networks and applications for suspicious activity.
Skills
End Point Security
Data Security
Network Security
System Security
Application Security
Encryption
Security Monitoring
Education
Bachelor's degree in computer science, Information Security, Cybersecurity
Certifications (CISSP, CISM, CEH)
Tools
SIEM
Job description
Responsibilities
Technology Compliance: Regular review of Tools and Technology to ensure that Security Compliances and Hardening with respect to hardware and software are in place and effective.
Policy and Procedure Compliance: Organization’s internal policy and procedure documents must be reviewed, updated time to time and shall be published to respective stakeholders and ensure adherence to the same.
Oversee 24/7 SOC operations, ensuring effective governance via reporting and dashboards.
All actionable arising from compliance report must be tracked until closure with respective stakeholders.
Creating and maintaining a technology compliance report.
Support team in evaluating the IT threat landscape, devising cyber security policy and controls to reduce risk, leading auditing, and compliance initiatives.
Support developing cyber resiliency so that the organization can rapidly recover from hacking, security incidents, or infringements.
Understanding of the various Legal and Regulatory Requirements and implementation of the guide lines to ensure that the organization complies to these guidelines on an ongoing basis.
Periodic review of the information security policies, configuration, documents and keeping them updated and relevant to the environment.
Contributing to a variety of security policy domains associated with compliance, governance, risk management, incident management and additional domains.
This job role is responsible for overall supporting the activities of Information Security and reporting the risks and closure of the audit comments in a timely manner.
This job role requires providing weekly/monthly reports on the updates /closure of the audit points. Other related projects being undertaken and the overall progress dashboards to CISO and Top Management.
Security Policy Development: Create, implement, and update security policies, standards, and procedures to ensure the protection of the organization's information assets.
Risk Assessment and Management: Identify potential security risks, conduct regular risk assessments, and develop strategies to mitigate these risks.
Incident Response: Develop and implement an incident response plan, and respond quickly to security breaches, incidents, and threats to minimize impact and recover data.
Security Monitoring: Continuously monitor networks, systems, and applications for suspicious activities or security breaches using various security tools and technologies.
Access Control: Manage and enforce access control policies to ensure that only authorized users have access to sensitive information and systems.
Conduct regular security training sessions for employees to raise awareness about security best practices and potential threats.
Vulnerability Management: Identify and address vulnerabilities in the organization's systems and applications through regular security scans, patch management, and updates.
Data Protection: Implement measures to protect sensitive data from unauthorized access, disclosure, alteration, and destruction. Use encryption, data masking, and secure data storage practices.
Security Architecture and Design: Design and implement secure network architectures, systems, and applications to protect the organization's information assets.
Reporting: Provide regular reports on security status, incidents, and compliance to senior management and other stakeholders.
Collaboration and Communication: Working closely with other IT and security teams to ensure a coordinated approach to cybersecurity.
Reporting: Providing regular reports on security incidents, threats, and overall security posture to management and other stakeholders.
Ensure that the organization complies with relevant regulatory requirements, industry standards, and internal policies. Prepare for and assist with security audits.
Knowledge of securing cloud environments (e.g., AWS, Azure, Google Cloud).
Understanding of cloud security best practices and tools.
Understanding of regulatory requirements (SEBI, RBI, CERT-IN, NCIIPC) and industry standards like GDPR, HIPAA, PCI DSS, and ISO 27001.
Requirements
Preferred Skills:
Technical Skills:
Hands‑on experience in Security solutions: End Point Security (PIM, EDR/XDR, FIM, NAC, IRM etc...), Data Security (DAM, DLP, Data Classification etc...) and Network Security (Secure Web Gateway, WAF, Firewall, IPS/IDS, LB etc...)
Network Security: Understanding of firewalls, VPNs, IDS/IPS, and other network security technologies.
System Security: Knowledge of securing operating systems (Windows, Linux, macOS) and ensuring regular updates and patch management.
Application Security: Familiarity with secure coding practices, application vulnerability assessments, and penetration testing.
Encryption: Proficiency in encryption methods and tools for data protection.
Security Monitoring: Experience with SIEM (Security Information and Event Management) tools and other monitoring systems.
Certifications and Education:
Education: A bachelor’s degree in computer science, Information Security, Cybersecurity, or related field.
Certifications such as CISSP, CISM, CEH, CompTIA Security+, CISA, ISO27001, ISO22301, CISSP would be an added advantage.
Analytical and Problem‑Solving Skills:
Critical Thinking: Ability to assess situations and make informed decisions quickly and efficiently.
Attention to Detail: Meticulous attention to detail in analysing data and identifying anomalies.
Risk Assessment: Understanding of risk assessment methodologies to prioritize and address potential threats.
Communication Skills:
Report Writing: Capability to document incidents, create detailed reports, and communicate findings clearly.
Collaboration: Effective communication and collaboration with team members and other departments.
Training and Awareness: Ability to conduct training sessions and promote cyber security awareness within the organization.
Soft Skills:
Adaptability: Ability to adapt to new threats and technologies in the ever‑evolving cyber security landscape.
Stress Management: Maintaining composure and effectiveness under pressure during security incidents.
Continuous Learning: Willingness to stay updated with the latest trends, threats, and best practices in cybersecurity.