01 Oct
|
Evoke Technologies
|
Hyderabad
01 Oct
Evoke Technologies
Hyderabad
Associate Manager – IT Security
Location: Hyderabad
Experience: 8–12 Years
Education: BE/B.Tech in Computer Science, Information Security, IT, or a related field
About the Role
We are looking for a highly motivated and experienced Associate Manager – IT Security to lead and strengthen our Security Operations (SecOps), Product Security (ProdSec), Vulnerability Management, and Security Compliance initiatives.
The ideal candidate should have strong hands-on experience in Security Operations, SIEM, Threat Detection, Incident Response, Vulnerability Management, Product/Application Security, and Security Compliance. The role will involve leading security initiatives, managing stakeholders, mentoring security teams, and continuously improving the organization's cybersecurity posture.
Key Responsibilities
Security Operations (SecOps)
- Lead day-to-day SOC and Security Operations activities.
- Oversee security monitoring, threat detection, investigation, and incident response.
- Develop and maintain SIEM use cases, correlation rules, and detection mechanisms.
- Monitor and manage security technologies including SIEM, EDR, IDS/IPS, DLP, Email Security, and Cloud Security.
- Drive threat hunting and proactive security investigations.
- Ensure timely incident triage, containment, remediation, and root-cause analysis.
- Develop and improve security processes, playbooks, runbooks, and incident response procedures.
- Coordinate with Infrastructure, Application, Cloud, DevOps, and Business teams during security incidents.
Product & Application Security
- Conduct security reviews of applications, APIs, cloud-native solutions, and products.
- Integrate security controls into the Secure Software Development Lifecycle (SSDLC).
- Perform threat modelling and security architecture assessments.
- Review application/code security findings and drive remediation.
- Manage SAST, DAST, SCA, Container Security, and API Security initiatives.
- Work closely with Development and DevOps teams to implement secure-by-design practices.
- Validate security controls during product releases and enhancements.
- Drive vulnerability remediation and risk reduction initiatives.
Security Compliance & Governance
- Drive compliance with applicable security frameworks, standards, and regulatory requirements.
- Support ISO 27001, SOC 2, PCI-DSS, NIST CSF, CIS Controls, GDPR, HIPAA, and similar compliance programs.
- Coordinate internal and external security audits.
- Conduct security control assessments and compliance reviews.
- Develop and maintain security policies, standards, procedures, and governance documentation.
- Track audit findings, risks, and remediation plans.
- Monitor and report security KPIs, KRIs, and compliance metrics.
- Maintain audit evidence and security documentation.
Vulnerability & Risk Management
- Lead enterprise-wide vulnerability assessment and management activities.
- Prioritize vulnerabilities based on risk, threat intelligence, and business impact.
- Conduct security risk assessments across applications, infrastructure, and cloud environments.
- Track remediation activities with technology and business stakeholders.
- Prepare and present security risk posture updates to leadership.
Leadership & Stakeholder Management
- Mentor and guide security analysts and engineers.
- Manage security vendors and third-party security engagements.
- Collaborate with Development, Cloud, Engineering, Infrastructure, Audit, Risk, and Compliance teams.
- Drive security awareness initiatives and promote a security-first culture.
- Support security roadmap planning and execution.
- Prepare executive-level security reports, dashboards, and presentations.
Key Skills
- Security Operations / SOC
- Threat Detection & Threat Hunting
- SIEM – Splunk or similar platforms
- Incident Response & Security Monitoring
- EDR / XDR
- Vulnerability Management
- Application & Product Security
- Secure SDLC / SSDLC
- Threat Modelling
- SAST / DAST / SCA
- Container Security
- API Security
- Cloud Security
- Security Risk Management
- Security Compliance & Governance
- ISO 27001 / SOC 2 / PCI-DSS / NIST / CIS
- Security Audits
- Security KPIs & KRIs
- Stakeholder & Team Management
Tools & Technologies
Experience with one or more of the following is preferred:
SIEM: Splunk, Microsoft Sentinel, QRadar, or similar
EDR/XDR: CrowdStrike, Defender, SentinelOne, or similar
Application Security: SAST, DAST, SCA, API Security tools
Cloud Security: AWS / Azure / GCP security platforms
Container Security: Kubernetes / Docker security tools
Vulnerability Management: Tenable, Qualys, Rapid7, or similar
What We’re Looking For
- Strong experience in IT Security / Cybersecurity / Security Operations.
- Proven experience leading security initiatives and working with cross-functional teams.
- Strong understanding of threat detection, incident response, vulnerability management, and security monitoring.
- Exposure to Product/Application Security and Secure SDLC.
- Positive understanding of security frameworks, compliance, and risk management.
- Strong analytical, communication, stakeholder management, and leadership skills.
- Ability to work hands-on while also managing security programs and teams.
Education: BE/B.Tech in Computer Science, Information Technology, Cybersecurity, or a related discipline.
📌 Associate Manager – IT Security (Hyderabad)
🏢 Evoke Technologies
📍 Hyderabad