This job posting is no longer active.
Location: Bangalore, KA, India
Date Posted: Sep 28, 2020
This position will be accountable for contributing to the identification, analysis and resolution of needs and problems in a discipline for which the incumbent is beginning to build a reputation as a subject matter expert in Cybersecurity.
This position performs complex analysis work, identifies and resolves problems. Incumbents may work directly with different Business Partners, suppliers, internal customers and/or other teams. This requires the ability to communicate technical information in a concise and accurate manner.
This position is a non-supervisory role that reports directly to the AP regional Cybersecurity manager.
Provide consultation on cybersecurity objectives and compliance with relevant security standards, policies, and procedures. Serve as trusted advisor to effectively communicate complex security risks in a manner that is easily understood and actionable. Enable the business to leverage enterprise-wide security solutions. Advise on processes and methodologies required when evaluating purchased product, new internal solutions, or outsourcing IT systems by various of security tools and processes, such as Software Asset management (SAM) process, Secure configuration baseline (SCB) and Third-Party Risk Assessment (TPRA), etc.
Test and evaluate information security controls and techniques to ensure they are efficiently and effectively implemented. Conduct Information Security Compliance Assessments according to the process and issue quality reports on time. Help risk owners through the remediation process by following the cybersecurity Risk Treatment Plan (RTP) process.
Support Computer Security Incident Response Team (CSIRT) when necessary. Communicate in a timely fashion to update the CSIRT team. Coordinate incident response needs within area of responsibility in the event of an enterprise CSIRT incident or investigation.
Support the Caterpillar’s Information Security Awareness program. Ensure Cybersecurity Awareness material is included in orientation for new staff, or third-party professionals, where applicable by law. Identify the need for customized awareness or phishing result messages specific to business areas. Develop and present messages in alignment with Information Security directives.
Travel may be required based on business need.
Bachelor’s or equivalent degree with at least 5 years work experience on Computer Science, Information Security, IT infrastructure.
Good understanding of the Cybersecurity knowledge in at least 1-2 security domains, such as:
Law & Regulation
Information security management
Cryptography and Encryption
Access Control management
Software Development Life Cycle Management
Business Continuity and Disaster Recovery
Obtain one of the following certifications within eighteen months and maintain in good standing: Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Controls (CRISC). CISSP preferred.