02 Oct
|
Bloom Engineering
|
Bengaluru
02 Oct
Bloom Engineering
Bengaluru
Job Summary
Join Enterprise Information Security (EIS) to help strengthen and mature Wabtec's cybersecurity risk management capabilities. Collaborate closely with infrastructure, cloud, application, operations, architecture, compliance and business teams to identify, prioritize and reduce cybersecurity risk across the enterprise. As a subject matter expert, you will work across global technology environments to ensure vulnerabilities, threats and control gaps are effectively managed and remediated.
As a Staff Cybersecurity Engineer within Enterprise Information Security, you will help advance Wabtec s vulnerability management program by leading engineering, operational execution, and governance support across on-premises, cloud, and MA environments. You will oversee vulnerability discovery, prioritization, remediation, and reporting while partnering with technology teams to reduce risk and strengthen the company s security posture. You will also support broader cybersecurity efforts across cloud security, security operations, and threat management to improve enterprise visibility, resilience, and operational effectiveness.
What do we want to know about you
- Bachelor s degree in computer science, Information Technology, Cybersecurity or a related field, or a minimum of 5 years of full-time cybersecurity experience.
- Demonstrated expertise leading enterprise vulnerability management programs across servers, endpoints, cloud platforms, applications and network infrastructure.
- Extensive experience with vulnerability assessment technologies, remediation workflows, risk prioritization methodologies and security exposure management practices.
- Strong understanding of vulnerability scoring frameworks, threat intelligence, exploitability analysis and risk-based remediation approaches.
- Experience developing metrics, reporting and executive-level dashboards to communicate security risk and remediation progress.
- Hands-on experience securing public cloud platforms such as AWS and Azure.
- Experience supporting Security Operations functions including threat detection, incident response, threat hunting or security monitoring activities.
- Knowledge of enterprise operating systems, networking, system administration and infrastructure technologies.
- Experience partnering with technical and business stakeholders to drive remediation efforts across globally distributed environments.
- Robust project execution,
communication and stakeholder management skills.
- Experience managing workstreams and maintaining operational transparency through IT Service Management platforms.
- Must be willing to work weekends or off-shift hours, as needed during cybersecurity incidents.
We would love it if you had
- Experience implementing Exposure Management or Attack Surface Management programs.
- Experience integrating vulnerability management processes with Security Operations and Incident Response functions.
- Knowledge of container, Kubernetes and cloud-native security technologies.
- Experience automating vulnerability management workflows using scripting or API integrations.
- Security certifications such as CISSP, GSEC, GCIH, Security+ or equivalent.
- Proven ability to work independently with strong time management skills.
- Strong communication and influencing skills.
- Commitment to continuous learning and adaptation within an evolving cybersecurity landscape.
What will your typical day look like
- Lead the enterprise vulnerability management program, ensuring effective identification, assessment, prioritization and remediation of vulnerabilities across global technology environments.
- Manage vulnerability scanning platforms, assessment processes and reporting capabilities to maintain enterprise-wide visibility of security exposures.
- Develop and continuously improve risk-based vulnerability prioritization methodologies using threat intelligence, exploitability data and business context.
- Partner with infrastructure, cloud, application and business teams to drive timely remediation of identified vulnerabilities and security control weaknesses.
- Monitor remediation performance, establish service-level targets and report risk reduction progress to leadership and stakeholders.
- Conduct vulnerability trend analysis to identify systemic issues and recommend strategic improvements.
- Support cloud security initiatives by assessing cloud environments for misconfigurations, vulnerabilities and compliance risks.
- Collaborate with Security Operations teams to investigate critical vulnerabilities, active threats and emerging security risks impacting the enterprise.
- Support threat management activities by evaluating threat intelligence and determining exposure to newly disclosed vulnerabilities and security advisories.
- Assist in vulnerability validation, remediation verification and exception management processes.
- Lead and participate in cybersecurity projects involving security tools, platforms and process improvements.
- Develop and maintain vulnerability management standards, procedures, operational runbooks and technical documentation.
- Provide Tier 3 escalation support for vulnerability management and related cybersecurity technologies.
- Support audit, compliance and regulatory activities by providing evidence, metrics and technical expertise.
- Evaluate new security technologies and industry best practices to continuously improve enterprise cybersecurity maturity.
- Participate and be available to support cybersecurity incidents, emergency activities and planned maintenance during weekends or off-hours as required.
What about the physical demands of the job
- Regularly remaining in a stationary position, often standing, or sitting for prolonged periods
- Regularly communicating with others to exchange information
- Regularly required to attend meetings in person and virtually using video and audio computer equipment
- Regularly repeating motions that may include the wrists, hands, and/or fingers, such as typing
- Occasionally moving about to accomplish tasks or moving from one worksite to another
- Occasionally light work that includes moving objects up to twenty pounds
Work Environment
- Hybrid work schedule (both on-site and remote)
- The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, they may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Staff Security Engineer (Bengaluru)
🏢 Bloom Engineering
📍 Bengaluru