03 Sep
|
Multi Commodity Exchange Clearing
|
Mumbai
03 Sep
Multi Commodity Exchange Clearing
Mumbai
Key Responsibilities:
- - Vulnerability &
- Patch Lifecycle
: Lead end-to-end patching, risk-based prioritization, and remediation across servers, endpoints, web and mobile applications, networks, DC/DR and lower environments and APIs.
- - Strategic Planning: Develop the enterprise-wide vulnerability and patch management framework, aligning it with business goals and regulatory standards like ISO 27001, NIST, and PCI DSS.
- - Operational Execution:
1. - Scanning: Direct regular authenticated and unauthenticated scans using tools like Qualys, Tenable, or Rapid7.
2. - Patching: Execute standard and emergency (out-of-band) patch deployments using automation platforms such as SCCM/MECM, Intune, or Tanium.
- - Remediation Validation: Perform post-patching verification scans and manual re-testing to confirm that vulnerabilities are successfully closed and no recent issues (regressions) were introduced.
- - Change &
- Risk Management
: Manage patch testing in non-production environments and coordinate maintenance windows with system owners to minimize downtime.
- - Reporting &
- Governance
: Maintain real-time dashboards to track Patch Compliance Rate and Mean Time to Remediate (MTTR), providing executive summaries to senior leadership.
- - Team Leadership: Lead, mentor, and guide a team of security analysts, conducting knowledge sharing sessions to stay ahead of emerging threats.
- - Stakeholder Liaison: Act as the primary point of contact for senior management and CTO, translating technical findings into actionable business risk reports.
Additional Requirements:
- - Windows Server, Linux (RHEL/CentOS), VMWare, Nutanix, OCP
- - Understanding of exploit techniques (e.g., lateral movement, privilege escalation) to better prioritize critical patches.
- - Understanding of SAST/DAST, manual exploitation, and configuration reviews.
- - Preferred credentials include- OSCP, CEH, or GPEN.
- - Management: CISSP, CISM, or CRISC.
Soft Skills:
- - Communication: Ability to explain complex vulnerabilities to non-technical business leaders.
- - Analytical Thinking: Strong problem-solving skills for identifying root causes of security failures.
- - Vendor Management: Experience managing SLAs and deliverables for external security testing firm.
Key Performance Indicators (KPIs):
- - Patching SLA Compliance: Percentage of critical vulnerabilities patched within the organizations defined timeline (e.g., 48 hours for critical threats).
- - Patching &
- Scan Coverage
: Proportion of corporate assets (including across servers, endpoints, web and mobile applications, networks, DC/DR and lower environments and APIs) actively monitored and patched for vulnerabilities.
- - Remediation Efficacy: Percentage of vulnerabilities that reappear in subsequent scans after being marked as "fixed".
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Manager - VAPT Patching (Mumbai)
🏢 Multi Commodity Exchange Clearing
📍 Mumbai