Our employees are our company's greatest asset - they are our real competitive advantage. We possesse immense power of innovation, immagination and a desire to attract and retain the best; provide them with encouragement, stimulus, and make them feel that they are an integral part of the company's mission.
Purpose
This position will provide security advice, tools, solutioning, etc related to various internal and external developed solutions like Sharepoint, Roshni Baji, 118, etc. The professional will be expected to participate in project planning, designing, capacity projections, hands-on implementation, complex integration work, security assessment, hardening of configurations, trouble shooting, maintaining, upgrading, and defining policy/procedure for all IT-infrastructure in use.
Education (Mandatory)
A bachelor’s degree in Computer Science, Cyber Security, or a related technical field
Certifications like CEH, CC, CCNA shall be preferred
Years of Experience
Experience of at least 1-2 years in field of cybersecurity, out of which 1 year experience in VAPT
Functional Competencies
Building High Performance Teams_AM-DM
Cyber Security Fundamentals_AM-DM
Data Analytics and Reporting_AM-DM
Drives Change_AM-DM
Drives Results_AM-DM
Industry Principles and Concepts_AM-DM
Internal Audit Techniques_AM-DM
Mental Agility_AM-DM
Risk Assessment and Management_AM-DM
SAP Management_AM-DM
Self Awareness_AM-DM
Stakeholder Management_AM-DM
Area of Responsibilities
Security Assessment -
- Security Assessment of company wide projects
- Including organizational wide changes in platforms, software, hardware, or appliance based solutions related to network and communication technologies that are implemented on infrastructure levels
- Review of design and workflow/ Ensure end to end secure workflows
- Performs vulnerability assessments, risk business impact, controls, and suggests treatment strategies
- Threats and vulnerability identification in the project/ requested change
- Ensuring all vulnerabilities/ critical findings should be patched/ fixed before going on production/ Live
- Review and approve requests for changes, Service requests, special service requests considering Governance policies
Threat Management -
- Responsible for handling Vulnerability management & pen-testing of the entire infrastructure including but not limited to vulnerability assessment of servers, networking devices, Databases, software and configuration reviews
- Assist in security upgrades and patch installation for all low to critical Findings
- Hunt for threats from inside and outside KE
- Communicate cyber events to internal and external stakeholders
- Suggests fixation or remediation of detected vulnerabilities to maintain a high-security standard
- Perform tests and uncover network vulnerabilities with security teams
- Assists in OTVA activities
- Tools: Nipper, Metasploit, Netsparker, Nessus professional, Tenable SC and other open source tools for VAPT
Cyber Security Project Execution -
- File Integrity Monitoring Solution
- Deployment of the solution, integration with IT assets, Operational issues, Policy development, Use-cases formation for monitoring, Investigation of Suspicious activities and resolution or remediation of the incident. Troubleshoots issues on daily basis
- 3rd Party VAPT
- Coordination with the vendor for the vulnerability identification in our IT assets, from outside the KE
- Cyber Secyurity Awareness
- Monitor and identify the top human risks to our organization and the behaviors we need to change to mitigate those risks
- Develop, manage, and implement a positive security awareness program, which focuses on changing behaviors both at work and at home. Simulate Phishing and other awareness campaigns
Stakeholder Management -
- Lead the creation and procurement of awareness deliverables and learning content, leveraging various channels for effective delivery, measures the usage of the content and its effectiveness, and develops metrics
- Establish a security awareness network with key stakeholders throughout the organization to understand risks and business objectives including Legal, Governance, ETS, EBS, Generation, Transmission, Distribution
- Owns and manages relationships with security education and awareness related vendors
Area of Responsibility Continued
KE provides equal employment opportunity (EEO) to all persons regardless of age, color, origin, physical or mental disability, race, religion, creed, gender, marital status, status with regard to public assistance or any other characteristic protected by federal, state or local laws.
Women and persons with disabilities are encouraged to apply. Role suitability for PWDs will be assessed in accordance with HSE standards.