05 Aug
|
HCL Technologies
|
Lucknow
05 Aug
HCL Technologies
Lucknow
Consulting Analyst (DFS)
Experience: Not Available to Not Available years
Location: Lucknow, India
Skills: Vulnerability Management, penetration testing, Red Teaming, network security, application security, cloud security, CVSS, vulnerability scanning tools, Qualys, Nessus, Rapid7, Burp Suite, Metasploit, Nmap, Cobalt Strike, SIEM, ArcSight, Splunk, ISO, PCI-DSS, NIST, CIS, ISO 27001, CEH, OSCP, OSWE, GPEN, GWAPT, CISSP, CISM
Job Summary
This role is responsible for identifying, assessing, and mitigating security vulnerabilities across enterprise environments while also simulating real-world cyberattacks through Red Teaming exercises. The objective is to proactively strengthen the organization’s security posture by combining defensive (VM) and offensive (Red Team) capabilities.
Job Description
Vulnerability Management
Perform regular vulnerability scans across infrastructure, applications, and endpoints
Analyze scan results, prioritize risks based on severity (CVSS), and recommend remediation
Coordinate with IT and application teams for patching and vulnerability closure
Track remediation progress and ensure timely closure within SLA
Red Teaming / Offensive Security
Conduct Red Team exercises to simulate real-world attack scenarios
Perform penetration testing (network, web, cloud, endpoints)
Identify security gaps in detection and response mechanisms
Execute phishing simulations and social engineering assessments (where applicable)
Security Assessment & Risk Analysis
Identify security weaknesses and provide actionable risk mitigation strategies
Perform root cause analysis for critical vulnerabilities
Validate the effectiveness of existing security controls
Tools & Technology Management
Work with vulnerability scanning tools (Qualys, Nessus, Rapid7, etc.)
Use penetration testing tools (Burp Suite, Metasploit, Nmap, Cobalt Strike, etc.)
Support security monitoring tools and SIEM integration (ArcSight, Splunk, etc.)
Reporting & Governance
Prepare detailed vulnerability assessment and Red Team reports
Provide executive summaries with risk ratings and remediation plans
Track metrics such as vulnerability trends, MTTR, and risk exposure
Incident & Detection Validation
Validate SOC detection capabilities through Red Team engagements
Test incident response processes and identify gaps
Work closely with Blue Team for threat detection improvement
Stakeholder Management
Collaborate with application owners, infrastructure teams, and security teams
Present findings to leadership and recommend remediation strategies
Support audits and compliance requirements (ISO, PCI-DSS, etc.)
Automation & Continuous Improvement
Automate vulnerability scanning, reporting, and tracking processes
Enhance Red Team methodologies and attack simulations
Improve overall security posture through continuous assessments
Security Compliance & Standards
Ensure alignment with security frameworks (NIST, CIS, ISO 27001)
Support audit readiness and compliance reporting
Maintain documentation of vulnerabilities and testing activities
Key Responsibilities
Vulnerability Management
Perform regular vulnerability scans across infrastructure, applications, and endpoints
Analyze scan results, prioritize risks based on severity (CVSS), and recommend remediation
Coordinate with IT and application teams for patching and vulnerability closure
Track remediation progress and ensure timely closure within SLA
Red Teaming / Offensive Security
Conduct Red Team exercises to simulate real-world attack scenarios
Perform penetration testing (network, web, cloud, endpoints)
Identify security gaps in detection and response mechanisms
Execute phishing simulations and social engineering assessments (where applicable)
Security Assessment & Risk Analysis
Identify security weaknesses and provide actionable risk mitigation strategies
Perform root cause analysis for critical vulnerabilities
Validate the effectiveness of existing security controls
Tools & Technology Management
Work with vulnerability scanning tools (Qualys, Nessus, Rapid7, etc.)
Use penetration testing tools (Burp Suite, Metasploit, Nmap, Cobalt Strike, etc.)
Support security monitoring tools and SIEM integration (ArcSight, Splunk, etc.)
Reporting & Governance
Prepare detailed vulnerability assessment and Red Team reports
Provide executive summaries with risk ratings and remediation plans
Track metrics such as vulnerability trends, MTTR, and risk exposure
Incident & Detection Validation
Validate SOC detection capabilities through Red Team engagements
Test incident response processes and identify gaps
Work closely with Blue Team for threat detection improvement
Stakeholder Management
Collaborate with application owners, infrastructure teams, and security teams
Present findings to leadership and recommend remediation strategies
Support audits and compliance requirements (ISO, PCI-DSS, etc.)
Automation & Continuous Improvement
Automate vulnerability scanning, reporting, and tracking processes
Enhance Red Team methodologies and attack simulations
Improve overall security posture through continuous assessments
Security Compliance & Standards
Ensure alignment with security frameworks (NIST, CIS, ISO 27001)
Support audit readiness and compliance reporting
Maintain documentation of vulnerabilities and testing activities
Skill Requirements
Solid understanding of Vulnerability Management lifecycle
Hands-on experience in penetration testing & Red Teaming
Knowledge of network, application, and cloud security
Familiarity with CVSS scoring, threat modeling, and risk assessment
Knowledge of security tools (Qualys, Nessus, Burp Suite, Metasploit, etc.)
Good understanding of SIEM, SOC, and detection mechanisms
Other Requirements
CEH, OSCP, OSWE, GPEN, GWAPT
CISSP / CISM (for broader security governance)
Relevant vendor certifications (Qualys, Rapid7, etc.)
📌 Consulting Analyst (DFS) (Lucknow)
🏢 HCL Technologies
📍 Lucknow