Information Technology Security Manager (Thane)
Information Technology Security Manager (Thane)
-
Thane, India
-
Posted: yesterday
-
Save
Description
Position: EVM (Enterprise Vulnerability Management) Lead Key Skills & Experience: Candidates with 15+ years of experience: 1. Demonstrable experience with Vulnerability management for on prem as well as cloud infra, application security and penetration testing 2. Should have familiarity with a variety of development and testing tools, including: BurpSuite, Kali, Nessus, Tenable, Qualys, Appsec testing tools, DevSecOps tools etc 3. Able to explain all vulnerabilities and weaknesses in the OWASP Top 10, WASC TCv2, and CWE 25 to any audience, and discuss effective defensive techniques 4. Familiarity with industry standards and regulations including PCI-DSS, IT Act, Cert-In regulations, and ISO-27001 is desired. 5. Strong analytical & problem-solving skills with ability to translate ideas into practical implementation 6. Ability to manage stakeholder relationships including team members, vendors and partners 7. Excellent communication skills with ability to present and communicate effectively with both technical and non-technical audience Job Description: 1. MSSP Governance & SLA Management 2. Performance Oversight: Monitor and hold the MSSP accountable for Vulnerability Management KPIs, success rate for P1/P2 incident resolution and the timely delivery of monthly remediation status reports. 3. RACI Coordination: Act as the point of contact (Accountable/Consulted) for all vulnerability scanning, re-validation, and remediation plan development. 4. Continuous Improvement: Review quarterly service improvement plans to reduce the "Mean Time to Identify Vulnerabilities" and improve "Asset Coverage" across the enterprise. 5. Platform engineering 6. Infrastructure Ownership: Accountable for the installation, configuration, and lifecycle management (patching, upgrades, and capacity planning) of the hardware and software required for VM, AppSec, and Security Assurance programs. 7. Vulnerability Management Engineering: Ensure the Tenable console and on-premises scanners maintain >99.9% availability. 8. Vulnerability Management Platform updates: Synchronize platforms with OEM databases to keep vulnerability libraries and compliance frameworks (ISO, NIST, PCI-DSS, CIS) current. 9. AppSec Tooling: Oversee the deployment and integration of Static (SAST), Dynamic (DAST), and Software Composition Analysis (SCA) tools to provide 100% coverage of ASL’s application landscape, including containerized workloads and IaC security. 10. Assurance Tooling: Manage and optimize automated testing tools and scripts used for Firewall Assurance (e.g., AlgoSec), Network Assurance, and AD security baselining. 11. Security Integration: Lead the technical integration of EVM platforms with the ITSM (ManageEngine), PAM (CyberArk), SIEM (QRadar), and GRC tools to automate remediation workflows. 12. Vulnerability Management Lifecycle 13. Scanning Operations: Oversee continuous tool-based scanning for all IPs / URLs and internal / external VAPT cycles. 14. Cloud & Hybrid Security: Lead security assessments for Cloud Platforms, including Cloud Armor, GKE clusters, and microservices. 15. Remediation Advocacy: Work with internal IT and Application teams to prioritize and fix critical vulnerabilities, ensuring that recent releases are rolled out without P0/P1 flaws. 16. Application Security & DevSecOps 17. Secure SDLC: Maintain and enforce secure coding policies, standards, and checkpoints within the Software Development Life Cycle (SDLC). 18. AppSec Testing: Oversee SAST, DAST, and Software Composition Analysis (SCA) for homegrown applications (e.g., MeraASL, ASLLink) and critical business applications like SAP. 19. Compliance: Map all findings to industry standards such as OWASP Top 10, CWE, and CIS Benchmarks. 20. Security Assurance & Hardening 21. Standardization: Develop and maintain Minimum Baseline Security Standards (MBSS) for all IT assets, including Linux/Windows servers, network devices, and SaaS products like Google Workspace. 22. Access Reviews: Monitor the effectiveness of Privilege Identity Management (CyberArk) and conduct monthly Segregation of Duties (SOD) reviews. Apply on Kit Job: kitjob.in/job/4n9d2x
Highlights
-
Company nameDMart - Avenue Supermarts
-
Job positionInformation Technology Security Manager (Thane)
Safety Tips
Be careful: if it seems too good to be true, it most likely is.
More info about this ad
Information Technology Security Manager (Thane) has been posted in the Ambernath Information Technology category on Locanto.
Right now, this is the only ad posted in this category in Ambernath.
Interested in more? Widen your search to view ads in nearby areas of Ambernath. This includes Information Technology in Dombivali, Ulhāsnagar and Badlapur. There are more ads within a 15 km radius for this category. If you want to view those ads, click here.