10 Oct
|
Wolters Kluwer (India) Private Limited - GBS
|
India
10 Oct
Wolters Kluwer (India) Private Limited - GBS
India
About the Role:
As a Senior IT Security Analyst, you will engage in advanced cybersecurity tasks with a high level of autonomy. Your contributions will be crucial for maintaining a secure IT environment and anticipating potential threats. You'll exercise thorough security measures and guide less experienced team members.
Key Responsibilities
- Support vulnerability management activities across cloud, infrastructure, containers, Kubernetes, and application environments.
- Review and analyze findings from security tools such as CSPM, vulnerability scanners, container security tools, and application security platforms.
- Work with infrastructure, cloud, application, and Dev Ops teams to drive remediation of identified security issues.
- Support cloud security posture management across AWS, Azure, or GCP environments.
- Manage EDR and XDR platforms: Deploy, configure, and optimize security tools to monitor endpoints, integrate cross-layered telemetry (cloud, network, and email), and eliminate security silos.
- Detect and respond to threats: Analyze advanced multi-vector alerts, hunt for hidden attackers, and orchestrate automated playbooks to rapidly isolate compromised systems and minimize response times.
- Review cloud misconfigurations, exposed resources, identity risks, network security gaps, and compliance issues.
- Assist in container and Kubernetes security reviews, including image vulnerabilities, runtime exposure, cluster configuration, and workload security.
- Support vulnerability prioritization based on severity, exploitability, exposure, asset criticality, and business impact.
- Help maintain dashboards, reports, trackers, and metrics for vulnerability remediation and security posture.
- Contribute to automation of repetitive security tasks, reporting, data enrichment, and remediation workflows.
- Support basic application security and shift-left activities, including SAST, DAST, SCA, dependency risks, and secure development awareness.
- Assist with basic forensic analysis, incident triage, log review, and evidence collection when required.
- Contribute to emerging AI security initiatives, including understanding risks around AI agents, connectors, cloud-hosted AI workloads, data exposure, and infrastructure security.
- Coordinate with multiple stakeholders to track remediation progress, exceptions, risk acceptance, and closure.
Required Skills and Experience
- 5–6 years of experience in cybersecurity, vulnerability management, cloud security, infrastructure security, or related domains.
- Good understanding of cloud security concepts across AWS, Azure, or GCP.
- Hands-on or working knowledge of CSPM tools such as Orca, Wiz, Prisma Cloud, Defender for Cloud, Lacework, or similar.
- Understanding of vulnerability management processes, including detection, prioritization, remediation tracking, SLA monitoring, and reporting.
- Familiarity with vulnerability scanners such as Rapid7, Qualys, Tenable, or similar.
- Good understanding of infrastructure security, including servers, operating systems, patching, network exposure, identity, and access controls.
- Basic understanding of containers and Kubernetes security, including container images, registries, clusters, namespaces, workloads, secrets, and runtime risks.
- Basic understanding of application security and shift-left practices, including SAST, DAST, SCA, CI/CD security, and secure coding concepts.
- Understanding of AI security concepts such as AI agents, connectors, data access, prompt injection, excessive permissions, and secure integration with enterprise tools.
- Ability to analyze security findings and translate them into clear remediation actions.
- Experience working with dashboards, Excel, Power BI, Service Now, Jira, or similar reporting and tracking tools.
- Basic scripting or automation experience using Python, Power Shell, Bash, KQL, SQL, or APIs.
- Strong communication skills with the ability to work with cloud, infrastructure, application, Dev Ops, and leadership teams.
Valuable to Have
- Exposure to Kubernetes security tools, container scanning, runtime security, or CNAPP platforms.
- Experience with Service Now Vulnerability Response, Jira, Power BI, Snowflake, or similar enterprise reporting platforms.
- Familiarity with MITRE ATT&CK;, MITRE ATLAS, OWASP Top 10, OWASP LLM Top 10, CIS Benchmarks, NIST, or cloud security frameworks.
- Understanding of forensic basics such as log analysis, endpoint artifacts, timeline review, and incident evidence handling.
- Experience with automation of vulnerability reporting, data cleanup, ticket enrichment, or remediation workflows.
- Exposure to AI security, GenAI governance, MCP/connectors, agentic workflows, or AI infrastructure security.
Our Interview Practices
📌 Senior IT Security Analyst (India)
🏢 Wolters Kluwer (India) Private Limited - GBS
📍 India