PSIRT Analyst – Product Cybersecurity (India)

PSIRT Analyst – Product Cybersecurity (India)

08 Oct
|
Match Point Solutions
|
India

08 Oct

Match Point Solutions

India

Match Point Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise.

We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!

Job Title: PSIRT Analyst Product Cybersecurity
Location: Bengaluru
Employment Type: Full-time

PSIRT Analyst Product Cybersecurity to join its Product Security Incident Response Team (PSIRT). The role will be responsible for supporting the identification, assessment, triage, and coordination of cybersecurity vulnerabilities and security incidents affecting Wabtec's global product portfolio.

The candidate will work closely with Product Security, Enterprise Information Security, Engineering, Product Development, and other global stakeholders to evaluate vulnerabilities, determine product applicability and risk, coordinate response activities, and support timely communication and remediation.

This position requires a strong understanding of vulnerability management, cybersecurity incident response, threat intelligence, and vulnerability assessment frameworks such as CVE, CWE, and CVSS.

Key Responsibilities

- Monitor and manage PSIRT intake channels, including vulnerability reporting mailboxes, reporting portals, security tools, and dashboards.
- Review, classify, acknowledge, and track reported vulnerabilities and security events in accordance with defined SLAs.
- Perform initial vulnerability validation, applicability assessment, and impact analysis for Wabtec products.
- Analyze vulnerabilities using CVE, CWE, and CVSS methodologies.
- Assess vulnerability severity, exploitability, potential impact, and business/product risk.
- Register and maintain accurate vulnerability records, evidence, status, and required metadata in vulnerability management tools.
- Escalate vulnerabilities and security incidents in accordance with established escalation procedures.
- Coordinate with Product Security, Engineering, Enterprise Information Security, and other stakeholders during vulnerability investigations and response activities.




- Participate in security war rooms and emergency response activities when required.
- Support the development, review, and distribution of security advisories and vulnerability notifications.
- Monitor relevant threat intelligence sources, including CISA KEV, CISA advisories, vendor security notifications, and other trusted sources.
- Conduct threat analysis based on vulnerability characteristics, exploitability, affected products, and available threat intelligence.
- Support the vulnerability disclosure process, including coordination with internal and external stakeholders.
- Participate in a documented on-call rotation to support continuous coverage for product security incidents and vulnerability response.
- Provide regular status updates to management and coordinate escalations during ongoing security incidents.
- Support regulatory and compliance readiness activities, including requirements associated with the European Union Cyber Resilience Act (EU CRA).
- Participate in tabletop exercises, preparedness activities, lessons learned, and after-action reviews.
- Prepare reports and presentations communicating cybersecurity risks, vulnerability status, incident progress, and response activities to technical and business leadership.
- Maintain appropriate documentation to support audit, compliance, and governance requirements.

Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related technical discipline.
- 3 5 years of relevant cybersecurity experience.
- Hands-on experience in Vulnerability Management, Vulnerability Assessment, Incident Response, Product Security, or PSIRT.
- Solid understanding of the vulnerability management lifecycle, including:
- Vulnerability identification
- Validation
- Risk assessment
- Prioritization
- Escalation
- Remediation tracking
- Closure

- Good working knowledge of:

- CVE Common Vulnerabilities and Exposures
- CWE Common Weakness Enumeration
- CVSS Common Vulnerability Scoring System

- Experience performing vulnerability triage and determining vulnerability applicability and impact.
- Familiarity with threat intelligence and vulnerability intelligence sources.
- Knowledge of CISA KEV, CISA advisories,



and vendor security notifications.
- Understanding of cybersecurity incident response processes and escalation procedures.
- Strong analytical, problem-solving, documentation, and communication skills.
- Excellent written and verbal communication skills in English.
- Ability to work independently with minimal supervision and collaborate effectively with global teams.
- Ability to manage multiple priorities and stakeholders in a fast-paced environment.

Preferred Qualifications
- Previous experience working in PSIRT or Product Cybersecurity.
- Experience with industrial cybersecurity, OT security, IoT security, embedded systems, or connected products.
- Experience in railway, transportation, automotive, industrial automation, manufacturing, or other product-based industries.
- Knowledge of cybersecurity frameworks and standards such as:
- NIST
- IEC 62443
- ISO 27001 / ISO 27005

- Experience with vulnerability management or security incident management tools.
- Experience supporting security advisories and vulnerability disclosure programs.
- Knowledge of regulatory requirements related to product cybersecurity, particularly the EU Cyber Resilience Act.
- Scripting or automation experience using Python, Power Shell, Bash, or similar technologies.
- Relevant cybersecurity certifications such as Security+, CySA+, GCIH, or equivalent.

Key Skills

Must Have:

- Vulnerability Management
- Vulnerability Assessment & Triage
- CVE / CWE / CVSS
- Threat Intelligence
- Incident Response
- Security Incident Coordination
- Risk Assessment
- Vulnerability Disclosure

Good to Have:

- PSIRT
- Product Cybersecurity
- Industrial / OT Cybersecurity
- IoT / Embedded Security
- NIST / IEC 62443
- EU Cyber Resilience Act
- Python / Power Shell / Bash
- Security Certifications

Match Point Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise.

We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!

📌 PSIRT Analyst – Product Cybersecurity (India)
🏢 Match Point Solutions
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: psirt analyst – product cybersecurity (india) / india