About this role
Function
D&IT
Pay Band
M2
Role
Lead the rigorous validation and enhancement of comprehensive security architectures across complex network, cloud, Application and endpoint environments.
A purpose driven role for you
- Embed and enforce Security by Design principles into High-Level and Low-Level Design (HLD/LLD) reviews and overall enterprise architecture lifecycles.
- Manage the security of LAN, WAN and SD-WAN networks.
- Manage network/perimeter security via Firewall, Switches and other network components.
- Govern the Web Application Firewalls (WAF) and Layer 7 protection controls to safeguard web applications and APIs against OWASP Top 10 vulnerabilities.
- Design and validate core network security controls, including Next-Gen Firewalls (NGFW), IDS/IPS, Zero Trust Network Access (ZTNA), and network micro-segmentation.
- Validate endpoint defense strategies, maintaining robust EDR/XDR platform coverage, OS hardening standards, and patch management pipelines.
- Integrate automated security gates, dependency checks, and vulnerability scanning by cloud security solution (CNAPP Journey).
- Lead the enterprise vulnerability management lifecycle, translating scan results from cloud, application, and network layers into prioritized remediation guidance.
- Audit and enforce strict Identity and Access Management (IAM), Least Privilege, and Privileged
- Access Management (PAM) policies across applications and cloud infrastructure.
- Proven ability to articulate complex application, cloud, and architectural security risks clearly to non-technical business leaders and stakeholders.
- Experience establishing Security Champion programs and mentoring junior analysts and developers on secure coding and architecture validation.
- Lead and execute Proof of Concept (POC) technical evaluations for new and emerging security solutions to validate capabilities against enterprise architectural requirements.
- Manage technical relationships with Original Equipment Manufacturers (OEMs) and vendor service integration partners to ensure optimal technology adoption, support, and SLA adherence.
- Support cybersecurity budget management and capacity planning by building technical business cases for proposed infrastructure investments and optimizing current licensing
- Serve as a senior technical escalation point for high-severity network, and application security incidents, leading containment and root cause analysis.
- Continuously monitor emerging zero-day vulnerabilities, application exploits, and threat actor TTPs to dynamically update defensive configurations.
- Govern the web security cloud proxy & CASB solution
A Day in the life
Lead the rigorous validation and enhancement of comprehensive security architectures across complex network, cloud, Application and endpoint environments.
Academic Qualification & Experience
B. Tech
6-9 Years of experience
Technical Skills/Knowledge
Working experience related to cyber security in Manufacturing & if engineer has a certification with respect to CISSP, CCSP, CSSLP, CISM it would be the added advantage
Behavioural Skills
- Communication
- Team work