08 Oct
|
Diebold Nixdorf
|
Hyderabad
08 Oct
Diebold Nixdorf
Hyderabad
Description
Supports the full cycle of vulnerability management from discovery/asset identification through risk assessment, remediation, verification, and reporting. Works with Information Security, Information Technology, engineering, and other technical and product/operational stakeholders to ensure understanding of and commitment to relevant vulnerability standards and practices. Proactively monitors system, network, and other changes to ensure their inclusion in vulnerability assessment/remediation activity.
Responsibilities
- Performs Cybersecurity and compliance assessments on new and existing systems, processes and technologies.
- Conducts system scans, access and firewall reviews, and audit research.
- Transforms, analyzes, prioritizes, and distributes findings to stakeholders.
- Coordinates, tracks, and escalates remediation and mitigation efforts with application and infrastructure owners.
- Participates in emergency and crisis management exercises/response.
- Helps with the proactive planning and design of procedural and technical measures to protect against current and future threats.
- Creates comprehensive assessment reports defining existing vulnerabilities, average time to remediation, compensating controls, work in progress and a roadmap for vulnerability remediation.
Qualifications
Required Qualifications
- Diploma or equivalent work experience required.
- Minimum of 5-7 years of relevant experience or equivalent combination of education and experience in Vulnerability Management.
- Good business English skills (Written and spoken).
- Excellent business English and communication skills (Written and spoken).
- Ability to influence behavior and outcomes via tactful, yet assertive, communication with colleagues.
- Administrative and/or integration knowledge of scanning and ticketing systems such as Tenable and ServiceNow.
- Working competence with Office, especially Outlook and Excel, including formulas.
Preferred Qualifications
- Good knowledge of Threat Intelligence collection, dissemination, analysis and delivery.
- Good knowledge of multiple security and privacy concepts such as: OSINT, HUMINT, SOCMINT, NIST, PCI, GDPR.
- GCIA, GHIH, CEH, or CISSP Certification.
- Positive knowledge of ISO 9001 Quality management system.
- Good knowledge of ISO 20000 information technology service management (ITSM) system.
- Good knowledge of other security frameworks such as COBIT, PCI DSS, NIST and SSAE16 is advantage.
- Good knowledge of Security Regulations (SOX, PCI, GLBA) is an advantage.
- Good knowledge of ISO 31000:2009 Risk Management.
- Knowledge of Windows OS, Linux OS and/or general application patching, configuration, or upgrade.
- DOD ACAS, HBSS training
📌 Senior Vulnerability Management Specialist (Hyderabad)
🏢 Diebold Nixdorf
📍 Hyderabad