Participating in designing and deploying application in customer hosted cloud infrastructure
Responsible for cyber security guidelines implementation for application hosted in Baker cloud infrastructure.
Responsible for assisting customer and deployment team for implementing cybersecurity guidelines implementation for application hosted in Customer cloud.
Defining the framework and processes for Cyber security for application hosted in Baker infrastructure
Defining tools and processes needed for maintaining the security of the applications in consolation with Product Architecture team and Baker IT security team.
Working with Architects, independent researchers, and in-house researchers to identify, rate, report and manage product vulnerabilities and incidents
Engaging in incident response methods lead incident response processes related to product cyber.
Create and track meaningful metrics around product cyber risk and compensating controls for the infra and application.
Creating vulnerability and incident trend analysis to improve infrastructure
Maintaining cyber Bills of Material and conduct proactive vulnerability monitoring and assessment on cyber components
Engaging in application and domain-specific threat modeling and attack surface analysis/reduction
Helping prepare reports at appropriate levels of confidentiality for stakeholders to view
Responding promptly and in detail to customer-sponsored penetration tests and customer queries and issues reported.
Making system/images templates/containers available which are hardened and VAPT tested.
Driving and leading for certifications such ISO 270001 OR SOC
Requirements
Have a bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Math).
Have Cybersecurity certification will be preferred. CEH, CISSP, CISM
Have Experience with cyber security framework (NIST 800-53, ISO 27001, IEC 62443, etc.) implementation and governance
Have 4+ years’ experience in implementing security processes including tools/techniques for Cloud hosted applications.
Have Knowledge of application risk identification and evaluation techniques
Have Experience securing applications within cloud platforms such as AWS, Azure, GCP and alike
Have Experience in deploying security services and other cloud services both manually and using automation tools like Cloud formation, Terraform, python or PowerShell scripting
Have Experience with implementing security tools like SIEM (central platform)
Have Security implementation experience with IIOT based application is preferred
Have Experienced in integrating applications using web services (SOAP/REST)
Been Working experience of various IPS/IDS, WAF, SIEM
Have hands on experience on Network security with devices such as Firewall/Routers
Have Good working experience in data encryption technologies
Have Experience with container technologies is preferred.
Tech Stack
AWS
Azure
Cloud
Cyber Security
Google Cloud Platform
Python
SOAP
Terraform
Benefits
Contemporary work-life balance policies and wellbeing activities
Comprehensive private medical care options
Safety net of life insurance and disability programs