Ugrás a tartalomra
egy személy és egy személy, aki székeken ül, és egy laptopot néz

Technology, Digital and Data

Senior Cybersecurity Analyst (Cybersecurity Advisor)

Hely Bangalore, Karnātaka, India
Közzététel dátuma
Jelentkezés vége:
Szerződés típusa Full time
Feladat típusa Regular
Igénylési azonosító R0000390120

Leírás

Career Area:

Technology, Digital and Data

Job Description:

Your Work Shapes the World at Caterpillar Inc.

When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here – we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.

About Caterpillar

Caterpillar Inc. is the world’s leading manufacturer of construction and mining equipment, off-highway diesel and natural gas engines, industrial gas turbines and diesel-electric locomotives.

For nearly 100 years, we’ve been helping customers build a better, more sustainable world and are committed and contributing to a reduced-carbon future. Our innovative products and services, backed by our global dealer network, provide exceptional value that helps customers succeed.

Your Impact Shapes the World at Caterpillar Inc

When you join Caterpillar, you're joining a global team who cares not just about the work we do – but also about each other. We are the makers, problem solvers and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here – we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.

Job Summary

We are seeking an Senior Cybersecurity Analyst (Cybersecurity Advisor) to join our AP Cybersecurity - CAT IT Division to serve as a trusted advisor to business and technology stakeholders. This role is responsible for driving regional cybersecurity governance, risk management, security assessments, compliance programs, and security advisory services across the organization. The successful candidate will help ensure that cybersecurity risks are effectively identified, communicated, and managed while enabling business innovation in a secure and compliant manner.

The preference for this role is to be based out of Bangalore – Caterpillar PSN

This position requires candidate to work a 5-day -a -week schedule.

Shift Timing : 01:00-10:00PM IST

Position Summary

The OpenVMS Systems Administrator is responsible for the administration, maintenance, monitoring, and support of mission-critical OpenVMS environments supporting warehouse automation, parts distribution, and manufacturing applications across multiple global locations. This role provides operational support for both physical OpenVMS Integrity servers and emulated OpenVMS environments hosted on Vere Technologies virtual servers, ensuring high availability, system performance, security, and business continuity for critical enterprise applications.

Security Advisory & Risk Management

  • Serve as a trusted cybersecurity advisor to business leaders, project teams, and technology stakeholders.
  • Provide expert guidance on cybersecurity objectives and compliance with corporate security policies, industry standards, and regulatory requirements.
  • Communicate complex cybersecurity risks, vulnerabilities, and recommendations in a clear and actionable manner to both technical and non-technical audiences.
  • Support business decision-making by balancing security requirements with operational and business objectives.

Security Governance & Compliance

  • Conduct security assessments, compliance reviews, and risk evaluations to ensure adherence to established security frameworks and standards.
  • Evaluate the effectiveness of cybersecurity controls and recommend enhancements where necessary.
  • Produce high-quality security assessment reports and communicate findings to stakeholders in a timely manner.
  • Support internal and external audit activities and regulatory compliance initiatives.

Security Architecture & Solution Review

  • Review and advise on the security architecture of new applications, infrastructure projects, cloud solutions, and outsourced services.
  • Evaluate purchased products, internally developed solutions, and third-party services through established cybersecurity processes, including:
    • Software Asset Management (SAM)
    • Secure Configuration Baselines (SCB)
    • Third-Party Cyber Risk Assessment (TPCRA)
    • Secure Development and Security Review Processes
  • Recommend security controls and best practices aligned with enterprise security standards.

Vulnerability & Risk Remediation Management

  • Coordinate and support vulnerability assessments, risk assessments, and control reviews.
  • Partner with risk owners to develop and track remediation plans and ensure risks are managed according to the Risk Treatment Plan (RTP) process.
  • Monitor remediation progress and provide regular reporting to management.

Incident Response & Security Operations Support

  • Support Cybersecurity Incident Response Team (CSIRT) activities when required.
  • Coordinate cybersecurity incident investigation and response efforts within assigned business areas.
  • Ensure timely communication and escalation of security incidents and emerging risks.

Security Awareness & Education

  • Support the organization's Cybersecurity Awareness Program.
  • Deliver security awareness activities, phishing simulation campaigns, and targeted security communications.
  • Develop and present cybersecurity messages aligned with enterprise security directives.
  • Promote a strong security culture across the organization.

Continuous Improvement

  • Stay current with evolving cybersecurity threats, technologies, regulations, and industry best practices.
  • Research emerging security standards, frameworks, and technologies, and assess their applicability within the organization.
  • Contribute to the continuous improvement of cybersecurity processes, policies, and controls.

Other

  • Travel may be required based on business needs.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, Information Technology, Engineering, or a related field.
  • Minimum 5+ years of experience in cybersecurity, information security, IT risk management, security consulting, or related areas.
  • Strong knowledge of at least two or more of the following cybersecurity domains:
    • Information Security Governance
    • Risk Management and Compliance
    • Identity and Access Management (IAM)
    • Cryptography and Data Protection
    • Network and Communication Security
    • Secure Software Development Lifecycle (SSDLC)
    • Cloud Security
    • Security Architecture
    • Business Continuity and Disaster Recovery
    • Security Operations and Incident Response
    • Regulatory and Legal Compliance
  • Demonstrated ability to perform security assessments, risk evaluations, and security consulting engagements.
  • Strong communication, stakeholder management, and presentation skills.
  • Ability to influence business and technical stakeholders at multiple organizational levels.

Preferred Certifications

One or more of the following certifications are highly preferred:

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)

Additional certifications such as CCSP, Azure Security Engineer, AWS Security Specialty, or relevant cloud security certifications are a plus.

Skill Descriptors
Communicating Complex Concepts: Knowledge of effective presentation tools and techniques to ensure clear understanding; ability to use summarization and simplification techniques to explain complex technical concepts in simple, clear language appropriate to the audience.
Level Working Knowledge:
• Uses comparisons to familiar ideas when introducing a technical or novel feature.
• Separates fundamental concepts from supporting details in explaining a product or service.
• Explains products and services with little or no use of technical jargon or advanced vocabulary.
• Emphasizes the most important facts or features of a product or service.
• Perceives lack of audience comprehension; further simplifies explanation when needed.

Consulting: Knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply consulting knowledge appropriately.
Level Basic Understanding:
• Explains the roles and responsibilities of a consultant.
• Lists the typical phases of a consulting assignment or project.
• Presents a professional image, especially when dealing with customers.
• Describes the consulting process and relationship with clients.

Cybersecurity Standards and Policies: Knowledge of developing cybersecurity policies, standards and procedures; ability to develop and communicate policies, standards and procedures that guide interactions with customers.
Level Working Knowledge:
• Follows efficient and effective auditing and compliance reporting.
• Provides feedback for improvement of procedures and policies.
• Assists in the development and implementation of specific cybersecurity policies and procedures.
• Participates in the development of organizational cybersecurity policies and standards.
• Generates status reports for senior management to ensure the implementation of cybersecurity standards and policies.

Cybersecurity Risk Management: Knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.
Level Working Knowledge:
• Responds to cyber security incidents following established security protocols.
• Applies the methods and processes used in tracking and prioritizing vulnerabilities in organizational cyber environment.
• Assesses the value of organizational assets.
• Analyzes and documents cyber security threats specific to your organization.
• Produces and interprets common cyber risk assessment and management reports.

Information Security Management: Knowledge of the processes, tools and techniques of information security management; ability to deploy and monitor information security systems, while detecting, controlling and preventing violations of IT security.
Level Working Knowledge:
• Follows procedures for the handling of computer security incidents and vulnerabilities.
• Participates in monitoring, back-up, recovery and archival activities.
• Assists in dealing with key issues and requirements for appropriately securing information.
• Analyzes data security and integrity considerations relevant to one's own function.
• Implements published information security management practices and guidelines.

Information Security Technologies: Knowledge of technologies and technology-based solutions dealing with information security issues; ability to protect information security across the organization using encryption technologies and appropriate security software.
Level Working Knowledge:
• Collects and documents information about new information security tools.
• Explains computer forensics, authentication mechanisms and digital certificates.
• Installs, upgrades or maintains firewall technology or anti-virus software.
• Participates in evaluating information security features against business requirements.
• Utilizes a specific hardware or software security technology to control risks.

Information Technology (IT) Security Policies: Knowledge of IT security policies, standards, and procedures; ability to utilize a variety of administrative skill sets and technical knowledge to ensure cyber security compliance.
Level Working Knowledge:
• Performs information gathering and research on key elements of IT security policies.
• Assists senior colleagues in identifying and analyzing critical issues in IT security policies.
• Executes IT security policies and standards within a specific region in organization.
• Conducts performance reviews on implementation of IT security policies.
• Generates status reports for senior management to ensure the implementation of IT security policies.

System and Technology Integration: Knowledge of the features and facilities of systems; ability to integrate and communicate among applications, databases and technology platforms.
Level Extensive Experience:
• Designs and develops applications or technology interfaces and bridges.
• Documents existing best practices for system or technology integration processes.
• Identifies and quantifies risks of proposed alternatives to a system or technology integration initiative.
• Delivers training on major issues, interfaces, considerations and potential pitfalls and risks.
• Discusses with line areas on data, technology and application integration issues.
• Advises others in how to integrate projects across multiple technologies.

What you will get:

  • Work Life Harmony
  • Earned and medical leave.
  • Relocation assistance

Holistic Development

  • Personal and professional development through Caterpillar ‘s employee resource groups across the globe
  • Career developments opportunities with global prospects

Health and Wellness

  • Medical coverage -Medical, life and personal accident coverage
  • Employee mental wellness assistance program

Financial Wellness

  • Employee investment plan
  • Pay for performance -Annual incentive Bonus plan.

Additional Information:

Caterpillar is not currently hiring individuals for this position who now or in the future require sponsorship for employment visa status; however, as a global company, Caterpillar offers many job opportunities outside of the U.S. which can be found through our employment website at www.caterpillar.com/careers

Caterpillar is an Equal Opportunity Employer (EEO)

EEO/AA Employer. All qualified individuals, including minorities, females, veterans and individuals with disabilities - are encouraged to apply.

This position requires working onsite five days a week.

Visa Sponsorship is not available for this position.

Posting Dates:

Caterpillar is an Equal Opportunity Employer. Qualified applicants of any age are encouraged to apply

Not ready to apply? Join our Talent Community.

FOGJUNK MUNKÁHOZ

ÉRTESÜLJÖN A LEGFRISSEBB ÁLLÁSAJÁNLATOKRÓL ÉS A CATERPILLAR-HÍREKRŐL.

CSATLAKOZZON A TEHETSÉGKÖZÖSSÉGHEZ
mosolygó emberek kollázsa