Role Summary:
The scope of this position focuses on the Cybersecurity Oversight, Delivery, Analysis and Incident Management. Additional activities include supporting Strategic and Technical Initiatives, performing Operational Risk Assessments, Managing Risk Acceptance Activities, developing Annual Risk Posture and Remediation Recommendation Report, and Completion Verification Reviews of Security Projects and Initiatives. Candidates should have ability to infuse Innovation and Creativity into Tactical Activity with a focus on exceptional customer service.
Key Success Drivers including Accountabilities and Responsibilities:
- Coordinate daily with various IT teams to ensure security best practices are implemented across all systems.
- Communicate effectively with business units on security matters, supporting awareness and compliance.
- Collaborate with audit teams and provide regular security reports and insights to management.
- Ensure strict adherence to internal security policies, standards, and procedures.
- Perform real-time security monitoring, log analysis, and investigation of alerts using SIEM tools.
- Review and assess work completed by security service providers; ensure closure of reported findings.
- Respond to and support security incidents, including identification, containment, eradication, and recovery.
- Participate in Agile workflows to enhance security controls and drive operational improvements.
- Maintain and fine-tune tools and technologies used for antimalware, drive encryption, and web security.
- Develop security metrics and reports for ongoing risk assessments and operational visibility.
- Document processes, incident playbooks, and SOPs for various security controls and procedures.
- Manage security-related service requests and incidents through ITSM tools.
- Provide mentorship and oversight to junior team members; assist in team coordination and planning.
- Apply “Secured by Design” principles in the evaluation and implementation of new IT solutions.
- Support data protection strategies and compliance initiatives (e.g., GDPR, ISO 27001).
Functional/Technical Competencies:
- Strong understanding of core IT security domains: endpoint protection, threat detection, DLP, encryption, and access control.
- Experience with security technologies including:
- SIEM (e.g., Splunk, Microsoft Sentinel)
- Anti-malware tools
- Drive encryption solutions (e.g., BitLocker)
- Web filtering and proxy solutions
- Familiarity with frameworks such as NIST, ISO 27001, or CIS Controls.
- Ability to assess vendor deliverables and ensure third-party compliance with security requirements.
- Proficiency in incident management and root cause analysis.
- Strong knowledge of IT infrastructure (servers, networks, endpoints).
- Excellent documentation, reporting, and presentation skills.
- Strong problem-solving and decision-making skills under pressure.
Educational Qualifications
Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Experience:
7 years of experience in IT security or infrastructure support, with at least 2 years in a senior or lead capacity. Proven track record of handling security operations and incident response. Experience in people management or mentoring junior engineers is a plus.
Certifictaions:
- CompTIA Security+
- Certified Information Systems Security Skilled (CISSP)
- Certified Ethical Hacker (CEH)
📌 Senior Support Engineer ( Security Analyst) (Gurugram)
🏢 GMG
📍 Gurugram