28 Sep
|
A.P. Moller - Maersk
|
Bengaluru
28 Sep
A.P. Moller - Maersk
Bengaluru
Roles and Responsibilities :
- 7+ years of progressive experience in enterprise cyber security with demonstrable in-depth technical expertise across Threat Exposure Management, Vulnerability Management, Defensive and Offensive Security applied to Identity technologies, whilst Application Security, Cloud Security, Data, OT/ICS, and AI/ML Security are beneficial.
- Experience must span large-scale, heterogeneous environments with complex technology stacks.
Certifications such as CISSP, GIAC, Microsoft Identity and Security, IGA, PAM are advantageous, but equivalent hands-on technical capability, advanced analytical proficiency, and a strong record of continuous learning and practical security training are essential.
- Deep understanding of vulnerability classes, exploit vectors, configuration weaknesses, and exposure patterns across Windows, Linux, network devices, cloud services, containers, applications, and OT/ICS systems.
- Solid ability to perform exploitability assessment, correlate vulnerabilities with attacker behaviour (MITRE ATT&CK;), and differentiate real risk from noise or false positives.
- Hands-on experience with VM/CTEM tooling and pipelines, including, but not limited to authenticated scanning, asset discovery methods, CSPM, AppSec (SAST/SCA/DAST/IaC), ASM/EASM platforms, passive/active enumeration and validating high-risk Critically Exposed Assets (CEAs).
- Strong capability to validate data accuracy, match assets, reconcile mismatches, and ensure consistent exposure attribution and ability to analyse trend data, identify anomalies, and provide actionable insights.
- Strong knowledge of AD/Entra ID, Kerberos, NTLM, PKI, certificate chains, CRLs/OCSP, SPNs, federation, MFA, and the ability to identify high-risk identity misconfigurations such as insecure trust relationships,
expired or weak certificates, unconstrained delegation, and stale privileges.
- Skilled in analysing identity attack paths, identifying lateral movement, privilege escalation, token abuse, SPN abuse, mis-issued certificates, and validating high-fidelity identity exposures including certificate-related attack vectors.
- Proficient in cloud and hybrid identity setups (Azure AD/Entra, ADFS, Azure AD Connect) including IAM roles, service principals, OAuth/OIDC flows, certificate-based authentication, SCIM provisioning, and detection of identity drift, sync failures, or insecure connectors.
- Ability to identify cloud and DNS-related exposure paths such as dangling DNS records, orphaned service endpoints, misconfigured identity endpoints, excessive cloud privileges, insecure APIs, and domain-federation weaknesses across CSPs such as, Azure, AWS, and GCP.
- Knowledge of PAM/PAW, JIT/JEA models, IGA (SailPoint, Saviynt), and Zero Trust identity principles, with the ability to spot toxic privilege combinations, entitlement sprawl, and policy drift.
- Ability to correlate identity exposures with adversary TTPs, credential abuse techniques, Golden Ticket/SAML attacks, and map identity weaknesses within wider attack paths across apps, cloud, and infrastructure.
- Knowledge of PAM/PAW, JIT/JEA, IGA platforms (SailPoint, Saviynt), certificate lifecycle governance, and Zero Trust identity principles, with the ability to spot toxic privileges, over-permissioned service accounts, and unmanaged certificate trust chains.
- Ability to correlate identity exposures with adversary TTPs, including certificate forgery (Golden Ticket, Golden SAML, forged smartcard auth), credential theft, dangling DNS exploitation, and map identity weaknesses into broader attack paths across infrastructure, cloud, and applications.
📌 Senior Cyber Analyst-AppSec & AI (Bengaluru)
🏢 A.P. Moller - Maersk
📍 Bengaluru