Security Tech Lead
Company
IBM
Location
IN Bangalore
Type
Full Time
Job Description
At IBM work is more than a job β itβs a calling: To build. To design. To code. To consult. To think along with clients and sell. To make markets. To invent. To collaborate. Not just to do something better but to attempt things youβve never thought possible. Are you ready to lead in this new era of technology and solve some of the worldβs most challenging problems? If so lets talk.
Your Role and Responsibilities
The IBM Sustainability Software team is looking for a technical talented innovative and enthusiastic Security and Compliance Tech Lead to lead and drive compliance security awareness training applying best practices for secured development. Security is something that every development team needs to incorporate into every phase of their product development life cycle and the Security and Compliance Focal is expected to ensure security is built into the design planning implementation and execution of our products.
The Security and Compliance Tech Lead should continuously consider the attack vectors and security weaknesses within the product offering and provide solutions to remediate those weaknesses. Should be Technical with understanding of Micro-services architecture SaaS Cloud Security and Infrastructure; Must collaborate with all stakeholders to drive security solutions; Must possess a growth mindset to keep up with the changing security landscape.
Required Technical and Professional Expertise
- Overall experience 8+ yrs with 5+ yrs of working experience with designing/building SaaS offerings and 3+ yrs as a security technical lead
- Domain expertise in cloud software and infrastructure technologies.
- Very good understanding in penetration testing methodologies and exploits (web apps containers APIs databases operating systems cloud technologies etc).
- Ability to communicate highly technical aspects to Executives IT staffs CISO team auditors.
- Experience with various scripting languages (Shell Python Bash etc.).
- Familiarity with OWASP Top Ten NIST CIS and MITRE ATT&CK
- Demonstrated experience in successful driving & execution of compliance programs for common IT security stds/regulations.
- Access Management β understand the concepts of need to know least privilege individual accountability privilege access monitoring access revalidation etc.
- Vulnerability Management β be able to regularly scan your systems and remediate any vulnerabilities found within required time frames
- Data Protection β understand the types of data your services deal with and have measures in place to protect that data (e.g. encryption file permissions etc.)
- Configuration Management β understand how to securely harden a system or application upon deployment.
Preferred Technical and Professional Expertise
- Certifications / Credentials β CISSP (preferred) CCNP/CCIE (preferred) CCSP CISA/CRISC/CISM.
- Common Attack Patterns β know what the common attack vectors facing the industry (e.g. CWE 25 or OWASP Top 10) be able to describe an attack with an example describe what a successful exploitation/impact looks like and what best practice remediation is.
Date Posted
10/14/2024
Views
0
Similar Jobs
Market Development Specialist - Spectrum
Views in the last 30 days - 0
Spectrum is seeking an outgoing professional for a financially rewarding job as a Market Development Specialist The role involves acquiring new custom...
View DetailsMajor Account Manager - Arista Channels
Views in the last 30 days - 0
Arista Networks is a leading company in datadriven clienttocloud networking known for its innovation in cloud computing AI and softwaredefined network...
View DetailsProject Coordinator - Behind the Design
Views in the last 30 days - 0
Behind the Design is seeking a solutiondriven Project Coordinator for a thriving interior design business The role involves project managing orders ac...
View DetailsVice President of Cybersecurity (Remote in US) - Resultant
Views in the last 30 days - 0
Resultant is a modern consulting firm that takes a unique approach to problemsolving working closely with clients to understand their needs and delive...
View DetailsHR Recruiter - Milestone Business Solutions Inc.
Views in the last 30 days - 0
Milestone is seeking an experienced HR Recruiter for a fully remote position within EST or CST time zones The ideal candidate should have at least 3 y...
View DetailsGrowth Manager - Awesome Motive
Views in the last 30 days - 0
Awesome Motive the company behind popular web apps and business tools like All in One SEO OptinMonster MonsterInsights and WPForms is seeking a datadr...
View Details