27 Sep
|
Larsen u0026 Toubro (Lu0026T)
|
Mumbai
27 Sep
Larsen u0026 Toubro (Lu0026T)
Mumbai
About Organization:
Larsen & Toubro Ltd, commonly known as L&T;, is an Indian multinational conglomerate company, with business interests in engineering, construction, manufacturing, technology, information technology and financial services, headquartered in Mumbai.
The company is counted among world's top five construction companies. The L&T; Group comprises of 93 subsidiaries, 5 associate companies, 27 joint ventures and 35 jointly held operations, operating across basic and heavy engineering, construction, realty, manufacturing of capital goods, information technology, and financial services.
This role is based out of Corporate IT in Headoffice.
Job Location: Powai, Mumbai Working Model: Work from office
Operating Model: 6 days (2nd and 4th Saturdays Off)
Educational Qualifications: B.Tech/B.E./MCA/M.Sc. In Cyber Security Specialization,
Experience: 5-10 years in Security Technologies Operations Management.
Job Profile:
1. Strong hands-on expertise across enterprise security technologies EDR, PIM/PAM, WAF, IDS/IPS, Vulnerability Management, DLP, and cloud security platforms.
2. Experience managing deployment, configuration, integration, health, coverage, and operational effectiveness of security controls against industry best practices, KPIs, and KRIs.
3. Hands-on knowledge of cloud security CNAPP, CSPM, CWPP, DSPM, and KSPM across Azure, AWS, and GCP, including remediation of misconfigurations and workload-hardening findings.
4. Strong understanding of vulnerability management, patch compliance, remediation tracking, and technology-obsolescence risk management.
5. Experience in identity-security risk monitoring, including excessive privileges, dormant and service accounts, MFA gaps, and privileged-access exceptions.
6. Ability to govern enterprise AI security frameworks covering policy, risk assessment, data protection, access control, compliance, and continuous monitoring.
7. Robust analytical, documentation, dashboards, reporting, and stakeholder-management skills,
with knowledge of security frameworks such as NIST, CIS, and ISO 27001.
Job Responsibilities:
1. Oversee and maintain the maturity of security technologies (EDR, PIM/PAM, WAF, IDS/IPS, Vulnerability Management, DLP, and cloud security platforms) against defined industry best practices, KPIs, and KRIs.
2. Manage the deployment, configuration, integration, health, coverage, and operational effectiveness of enterprise security technologies.
3. Drive remediation of vulnerabilities, security misconfigurations, unsupported technologies, and security control gaps.
4. Define and track SecOps KPIs and KRIs covering vulnerability ageing, patch compliance, security-tool coverage, remediation timelines, incidents, and risk exceptions.
5. Prepare cybersecurity dashboards, operational reports, and risk updates for governance and leadership teams.
6. Manage the effectiveness and coverage of cloud security deployments including CNAPP, CSPM, CWPP, DSPM, and KSPM across Azure, AWS, and GCP, and coordinate remediation of cloud misconfigurations, identity-control gaps, network-segmentation issues, encryption gaps, and workloadhardening findings.
7. Manage remediation of findings arising from audits, cybersecurity assessments, penetration tests, cloud reviews, compliance reviews, and operational-risk assessments, ensuring closure with appropriate technical validation and supporting evidence.
8. Conduct periodic security-control validation, attack simulations, and tabletop exercises.
9. Monitor identity-security risks, including excessive privileges, dormant accounts, service accounts, MFA gaps, and privileged-access exceptions.
10. Govern the enterprise AI security framework, including policies, risk assessment, data protection, access controls, compliance, and continuous monitoring.
CERTIFICATIONS Preferred: CCSP, GCIH, GCIA, CRISC, CEH, CompTIA CySA+, or OSCP. Cloud Security: Microsoft Azure Security, AWS Security, or Google Professional Cloud Security Engineer. Equivalent certifications supported by relevant SecOps leadership and hands-on experience may also be considered.
📌 Technology Security Manager (Mumbai)
🏢 Larsen u0026 Toubro (Lu0026T)
📍 Mumbai