Upload Button Icon Add office photos
filter salaries All Filters

16 Black Duck Software Jobs

Infrastructure & Vulnerability Management Engineer, Sr Staff

7-9 years

Bangalore / Bengaluru

1 vacancy

Infrastructure & Vulnerability Management Engineer, Sr Staff

Black Duck Software

posted 3mon ago

Job Description

The Black Duck Cybersecurity team is seeking a passionate, experienced, and collaborative practitioner to be a key member of our security operations team.
The Sr Staff Infrastructure & Vulnerability Management Engineer is responsible for identifying, assessing, and mitigating security vulnerabilities in IT infrastructure, networks, endpoints, and cloud systems using a variety of security tooling at their disposal. The position works collaboratively with security engineers and other IT and security professionals to implement security measures and evaluate the performance of those measures to ensure compliance with policies, regulations, and contracts. They monitor threats, trends, and attack patterns, and partner with security operations center analysts and business stakeholders to provide input for the creation of relevant, actionable security content representations.
Key Responsibilities
  • Conduct vulnerability assessments and penetration testing to identify security weaknesses in networks and network nodes, including cloud-based assets
  • Develop, implement, and maintain a vulnerability management program to prevent, identify, and mitigate security risks; manage tooling designed to discover, protect, and defend assets
  • Identify and prioritize vulnerabilities based on severity and potential impact to business revenue
  • Collaborate with other IT and security professionals to implement security measures and ensure compliance with security policies, regulations and contracts
  • Monitor and track vulnerabilities and provide actional remediation recommendations to asset owners
  • Conduct risk assessments to identify potential security threats and vulnerabilities
  • Guide research, mentor junior staff, and keep current on the latest emerging threats, attack patterns, and adversaries
  • Partner with stakeholders to drive improvements in technology adoption and security governance
  • Works collaboratively on threat intelligence-gathering activities and conducting hypothesis-driven threat-hunting activities
  • Collaborate with cross-functional teams to provide threat intelligence insights and recommendations
Qualifications
  • Strong written and verbal communication skills; ability to establish and maintain strong working relationships with team members and other functional groups
  • Possesses knowledge of a variety of threats, malicious actor personas, attack patterns, exploits, and common vulnerabilities
  • Understands the MITRE ATT&CK Frameworks, Cyber Kill Chain, and Diamond Model concepts
  • Demonstrates an understanding of current and emerging security threats
  • Prior experience with threat-hunting activities
  • Prior experience as an incident responder, security operations analyst, or security engineer
  • Understanding of common attack patterns and Indicators of Compromise (IoCs) across Windows, MacOS, and Linux-based operating systems
  • Experience creating scripts using Python or similar languages
  • Experience with developing and refining network signatures to enhance detection capabilities and improve the identification of evolving cyber threats and vulnerabilities
  • Experience in drafting technical reports summarizing forensic findings a plus
  • Familiarity with intrusion detection system (IDS) alerts a plus
  • Familiar with security tooling such as Qualys, Tenable, Rapid7, Metasploit, Nmap,
  • Splunk, LogRhythm, CrowdStrike Falcon, and M365 E5 security stack
  • Must be familiar with the operation of firewalls, intrusion detection systems, and antivirus software.
  • Experience with advanced digital forensics tools and methodologies to investigate security breaches, including malware analysis, network intrusion detection a plus
  • Experience in conducting digital forensics investigations by analyzing data from network data acquisition kits and other artifacts to identify indicators of compromise a plus
  • 7+ years in an incident response role or working in or with a security operations center
  • 5+ years of experience in evaluating, deploying, and managing endpoint, network, and cloud security tooling
  • Bachelor s degree in information security, computer science, or a related field or equivalent combination of education, training, and experience
  • Holds or is willing to obtain job-related security certifications

Employment Type: Full Time, Permanent

Read full job description

What people at Black Duck Software are saying

What Black Duck Software employees are saying about work life

based on 4 employees
100%
100%
75%
Flexible timing
Monday to Friday
No travel
View more insights

Black Duck Software Benefits

Free Transport
Child care
Gymnasium
Cafeteria
Work From Home
Free Food +6 more
View more benefits

Compare Black Duck Software with

Accenture

3.9
Compare

Capgemini

3.7
Compare

HCLTech

3.5
Compare

Teleperformance

3.9
Compare

Concentrix Corporation

3.8
Compare

Amazon

4.1
Compare

Mphasis

3.4
Compare

Amazon Development Centre India

4.1
Compare

FIS

3.9
Compare

Coforge

3.3
Compare

Nagarro

4.0
Compare

Optum

4.0
Compare

Persistent Systems

3.5
Compare

Dell

4.0
Compare

Indian Oil Corporation

4.4
Compare

S&P Global

4.2
Compare

I Process Services

3.9
Compare

Quest Global

3.6
Compare

AGS Health

4.0
Compare

Sterlite Technologies

3.8
Compare

Similar Jobs for you

Management at KPMG India

Bangalore / Bengaluru

5-8 Yrs

₹ 7-10 LPA

Management at KPMG India

Noida

5-8 Yrs

₹ 7-10 LPA

Engineering Manager at AVNET India Pvt Ltd

New Delhi, Hyderabad / Secunderabad + 3

3-7 Yrs

₹ 5-9 LPA

Management at Capgemini Technology Services India Limited

Chennai

5-10 Yrs

₹ 7-12 LPA

Management Head at Virtusa Consulting Services Pvt Ltd

Bangalore / Bengaluru

8-13 Yrs

₹ 19-24 LPA

Security Engineer at Kong

Bangalore / Bengaluru

3-7 Yrs

₹ 5-9 LPA

Professional at Capgemini Technology Services India Limited

Bangalore / Bengaluru

4-8 Yrs

₹ 6-10 LPA

Application Security Engineer at LIVE CONNECTIONS

7-15 Yrs

₹ 10-35 LPA

Software Engineer at Black Duck Software

Bangalore / Bengaluru

4-7 Yrs

₹ 6-9 LPA

Senior Information Security Engineer at Corner Tree Consulting P Ltd

8-10 Yrs

₹ 15-32 LPA

Infrastructure & Vulnerability Management Engineer, Sr Staff

7-9 Yrs

Bangalore / Bengaluru

3mon ago·via naukri.com

Technical Recruiter

1-4 Yrs

Bangalore / Bengaluru

20hr ago·via naukri.com

NetSuite Developer

3-7 Yrs

Bangalore / Bengaluru

15d ago·via naukri.com

Accounts Payable Accountant

1-3 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Senior Accountant

4-7 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Analyst, Expense Reports India

1-2 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Data Governance Specialist

4-7 Yrs

Bangalore / Bengaluru

1mon ago·via naukri.com

Senior Staff DevOps Engineer

4-8 Yrs

Bangalore / Bengaluru

2mon ago·via naukri.com

Cybersecurity Engineering, Staff Engineer

5-8 Yrs

Bangalore / Bengaluru

2mon ago·via naukri.com

Staff, Software Engineer

2-6 Yrs

Bangalore / Bengaluru

2mon ago·via naukri.com
write
Share an Interview