Live opening · Posted 1 day ago

Senior Cybersecurity Specialist

BCE Global Tech · Bangalore
Instahyre 7-11 yrs
You are 1 day behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 1 day ago
CompanyBCE Global Tech
LocationBangalore
Experience7-11 yrs
SourceInstahyre
Listed1 day ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
18 min from Instahyre publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
16,807 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

We are seeking a Senior Cybersecurity Specialist with strong hands-on experience in implementing, operating, and maturing security controls across enterprise environments. The role requires deep execution capability across asset management, access control, secure development, endpoint security, security testing, AI governance, supplier risk, employee awareness, monitoring and detection, and incident response, with proven expertise in PII / HSPII protection and PCI-DSS compliance. This position plays a critical role in translating security policies, standards, and frameworks into operational, measurable, and enforceable controls.
The core responsibilities for the job include the following:
Asset and Access Management:
Implement and maintain asset inventory controls (hardware, software, and cloud assets).
Execute Identity and Access Management (IAM) controls, including RBAC, least privilege, MFA, and periodic access reviews.
Support onboarding/offboarding automation and privileged access monitoring.
Secure Development and DevSecOps:
Implement secure SDLC controls aligned with organizational standards.
Integrate security checks into CI/CD pipelines (SAST, DAST, SCA).
Work with engineering teams to remediate code-level security issues.
Ensure secure configuration baselines for applications and APIs.
Endpoint Security:
Deploy and manage endpoint protection controls (EDR/XDR).
Enforce device hardening, disk encryption, patching, and configuration standards.
Monitor endpoint compliance and address control gaps.
Security Testing and Assurance:
Execute the vulnerability management lifecycle, including scanning, validation, prioritization, and remediation tracking.
Coordinate and support penetration testing and security assessments.
Validate closure of findings and maintain evidence for audits.
AI Governance and Emerging Technology Risk:
Implement AI governance controls covering data usage, model risk, access control, logging, and monitoring.
Support AI risk assessments and document compliance with responsible AI principles.
Ensure protection of sensitive data used in AI/ML workloads.
Supplier and Third-Party Risk Management:
Execute supplier security assessments and due diligence.
Track remediation of third-party security findings.
Monitor high-risk vendors for ongoing compliance.
Employee Security Awareness:
Support execution of security awareness and phishing simulation programs.
Embed security training aligned with role-based risks.
Measure effectiveness through metrics and behavior improvement.
Monitoring, Detection, and SOC Support:
Implement and tune security monitoring and detection controls.
Integrate logs into SIEM and ensure alert coverage for critical risks.
Support threat detection use cases and reduce false positives.
Incident Response:
Execute incident detection, containment, eradication, and recovery activities.
Participate in incident response drills and post-incident reviews.
Maintain IR documentation, playbooks, and evidence logs.
Data Protection and Compliance:
Implement controls for PII and Highly Sensitive PII (HSPII) protection, including encryption, access controls, logging, and retention.
Execute and maintain PCI-DSS technical and operational controls.
Support internal and external audits with accurate evidence.
Requirements:
Bachelor's degree in computer science or equivalent.
8+ years of experience in cybersecurity or information security roles.
Proven track record of control implementation, execution, and operationalization.
Experience working with engineering, IT, SOC, risk, and compliance teams.
Relevant certifications (preferred): CISSP, CISM, or CISA, AZ-500 / AWS Security Specialty, CEH / Security+ / GIAC (role dependent).
8+ years of cybersecurity experience.
Strong control implementation background.
Relevant certifications (CISSP, CISM, CISA preferred).
Technical Skills:
Strong experience implementing security controls hands-on, not just defining policy.
Practical knowledge of: IAM, PAM, Endpoint Security (EDR/XDR), Vulnerability Management tools, SIEM / SOC operations, Secure SDLC, and DevSecOps tooling.
Solid understanding of PCI-DSS, PII/HSPII protection, and data security principles.
Familiarity with cloud security controls (AWS/Azure/GCP preferred).
Frameworks and Standards (Implementation Focus): ISO 27001 / ISO 27002 NIST CSF / NIST 800-53 PCI-DSS, Zero Trust concepts, privacy and data protection controls
Key Competencies:
Execution-driven and outcome-focused
Strong stakeholder collaboration
Risk-based decision-making
Clear documentation and evidence management
High ownership during incidents and audits
Asset and Access Management:
Implement and maintain asset inventory controls.
Execute IAM controls, including RBAC, least privilege, MFA, and access reviews.
Secure Development and DevSecOps:
Implement secure SDLC controls and integrate security tooling into CI/CD pipelines.
Work with engineering teams to remediate vulnerabilities.
Endpoint Security:
Deploy and manage EDR/XDR solutions.
Enforce device hardening, encryption, and patching.
Security Testing and Assurance:
Execute vulnerability management and penetration testing activities.
Track remediation and maintain audit evidence.
AI Governance:
Implement AI governance and model risk controls.
Ensure sensitive data protection in AI workflows.
Supplier Risk Management:
Conduct supplier security assessments and track remediation.
Employee Security Awareness:
Support execution of awareness and phishing simulation programs.
Monitoring and Detection:
Implement monitoring controls and tune SIEM alerts.
Incident Response:
Participate in incident handling, drills, and post-incident reviews.
Data Protection and Compliance:
Implement PII/HSPII controls.
Execute PCI-DSS technical and operational requirements.

Experience
7-11 yrs

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App