Wabtec→
Staff Security Engineer at Wabtec in Bengaluru
ExperiencedOn-siteFull-timeBengaluru
Skills
ArchitectureAzureCloud SecurityAutomatingComplianceInformation SecurityCybersecurityCissp
Job Description
Job Summary
Its not just about your career or job titleIts about who you are and the impact you will make on the world. Because whether its for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, youre in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.
Responsibilities - Lead the enterprise vulnerability management program, ensuring effective identification, assessment, prioritization and remediation of vulnerabilities across global technology environments.
- Manage vulnerability scanning platforms, assessment processes and reporting capabilities to maintain enterprise-wide visibility of security exposures.
- Develop and continuously improve risk-based vulnerability prioritization methodologies using threat intelligence, exploitability data and business context.
- Partner with infrastructure, cloud, application and business teams to drive timely remediation of identified vulnerabilities and security control weaknesses.
- Monitor remediation performance, establish service-level targets and report risk reduction progress to leadership and stakeholders.
- Conduct vulnerability trend analysis to identify systemic issues and recommend strategic improvements.
- Support cloud security initiatives by assessing cloud environments for misconfigurations, vulnerabilities and compliance risks.
- Collaborate with Security Operations teams to investigate critical vulnerabilities, active threats and emerging security risks impacting the enterprise.
- Support threat management activities by evaluating threat intelligence and determining exposure to newly disclosed vulnerabilities and security advisories.
- Assist in vulnerability validation, remediation verification and exception management processes.
- Lead and participate in cybersecurity projects involving security tools, platforms and process improvements.
- Develop and maintain vulnerability management standards, procedures, operational runbooks and technical documentation.
- Provide Tier 3 escalation support for vulnerability management and related cybersecurity technologies.
- Support audit, compliance and regulatory activities by providing evidence, metrics and technical expertise.
- Evaluate new security technologies and industry best practices to continuously improve enterprise cybersecurity maturity.
- Participate and be available to support cybersecurity incidents, emergency activities and planned maintenance during weekends or off-hours as required.
- Bachelors degree in computer science, Information Technology, Cybersecurity or a related field, or a minimum of 5 years of full-time cybersecurity experience.
- Demonstrated expertise leading enterprise vulnerability management programs across servers, endpoints, cloud platforms, applications and network infrastructure.
- Extensive experience with vulnerability assessment technologies, remediation workflows, risk prioritization methodologies and security exposure management practices.
- Strong understanding of vulnerability scoring frameworks, threat intelligence, exploitability analysis and risk-based remediation approaches.
- Experience developing metrics, reporting and executive-level dashboards to communicate security risk and remediation progress.
- Hands-on experience securing public cloud platforms such as AWS and Azure.
- Experience supporting Security Operations functions including threat detection, incident response, threat hunting or security monitoring activities.
- Knowledge of enterprise operating systems, networking, system administration and infrastructure technologies.
- Experience partnering with technical and business stakeholders to drive remediation efforts across globally distributed environments.
- Strong project execution, communication and stakeholder management skills.
- Experience managing workstreams and maintaining operational transparency through IT Service Management platforms.
- Must be willing to work weekends or off-shift hours, as needed during cybersecurity incidents.
- Experience implementing Exposure Management or Attack Surface Management programs.
- Experience integrating vulnerability management processes with Security Operations and Incident Response functions.
- Knowledge of container, Kubernetes and cloud-native security technologies.
- Experience automating vulnerability management workflows using scripting or API integrations.
- Security certifications such as CISSP, GSEC, GCIH, Security+ or equivalent.
- Proven ability to work independently with strong time management skills.
- Strong communication and influencing skills.
- Commitment to continuous learning and adaptation within an evolving cybersecurity landscape.
- Regularly remaining in a stationary position, often standing, or sitting for prolonged periods
- Regularly communicating with others to exchange information
- Regularly required to attend meetings in person and virtually using video and audio computer equipment
- Regularly repeating motions that may include the wrists, hands, and/or fingers, such as typing
- Occasionally moving about to accomplish tasks or moving from one worksite to another
- Occasionally light work that includes moving objects up to twenty pounds
You may also be asked to perform other duties outside of your function or trade, for which adequate training will be provided if necessary.
Work Environment - Hybrid work schedule (both on-site and remote)
- The employee will normally work in a temperature-controlled office environment, with frequent exposure to electronic office equipment. During visits to areas of operations, they may be exposed to extreme cold or hot weather conditions. Is occasionally exposed to fumes or airborne particles, toxic or caustic chemicals, and loud noise