Security Consultant
KIN51515 Mumbai (KIN51515) We Work, India
Kyndryl
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day.Who We Are
At Kyndryl, we design, build, manage and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward – always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our employees, our customers and our communities.
The Role
Job Description: The Security Architect/Consultant Engineer will be responsible for designing, implementing, migration and managing advanced security solutions, with primary skills on firewall devices ( check Point, Palo alto, FortiGate, cisco). And secondary skills either on WAF ( F5 ASM , Imperva, Akamai etc) or NAC ( Cisco ISE, Forescout , Aruba etc ) This role involves handling implementation , operations and execute design consulting type assignment
Collaboration will be your forte, as you work closely with clients to understand their unique security requirements and assess their current security posture. Armed with this knowledge, you'll provide expert guidance and recommendations on the best security practices, risk management strategies, and robust security policies that will fortify their defenses.
You won't stop at providing advice; you'll roll up your sleeves and get hands-on. Designing and implementing security controls, policies, and procedures will be your playground. You'll work alongside cross-functional teams to deploy state-of-the-art technologies, including firewalls, intrusion detection/prevention systems, access controls, and encryption technologies, ensuring a comprehensive security framework.
The thrill of uncovering vulnerabilities and risks is what motivates you. Armed with your extensive knowledge, you'll conduct thorough security assessments, leaving no stone unturned in identifying potential security breaches. Your findings will serve as the foundation for meticulous security audits and reviews, ensuring adherence to policies and procedures. Your reports and findings will be the catalyst for management decisions and actions.
In the fast-paced world of cybersecurity, staying ahead of the game is crucial. That's why you'll continuously immerse yourself in the latest security threats, technologies, and best practices. Your recommendations will drive enhancements to the organization's security posture, ensuring it remains at the cutting edge of defense.
Your influence won't be limited to systems alone. You'll lend your expertise to the design and review of IT infrastructure, systems, and applications, ensuring they are secure by design from inception.
Not only will you make an impact within our organization, but you'll also collaborate with customers and vendors on security assessments, audits, and due diligence activities. Your knowledge and experience will be instrumental in shaping secure collaborations and partnerships.
Our consultants are restless for innovation. They are at the edge of technology, changing the way our customers implement business solutions – so, if you’re a problem-solver, an innovative thinker, and a self-starter with a passion high impact assignments which align technology to business outcomes, then we want to hear from you! Apply today to join our team that has a host of exciting projects and customers waiting for you to work with them to solve complex transformation puzzles through technology.
Your Future at Kyndryl
As a Security Consultant at Kyndryl you will join the Kyndryl Consultant Profession, working with other Kyndryl Consultants, Architects, Project Managers, and cross-functional Technical Subject Matter Experts – presenting unlimited opportunities with unmatched support through our investment in your learning, training, and career growth
Who You Are
You’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.
Primary Domain Skills Area 1 any 2 firewalls as L3/ SME level ( Check Point, Palo Alto, FortiGate, Cisco) : Checkpoint Skills and Palo Alto Skills are preferred . Checkpoint Skills are Mandatory .
Secondary Domain Skills Area 2: WAF/NAC ( F5 ASM , Radware WAF , Imperva WAF and or Akami WAF ) and ( Cisco ISE , Forescout NAC , Aruba Clear Pass
F5 ASM and Imperva WAF skills are Preferred with F5 ASM /WAF skills being mandatory .
Required Skills and Experience
Firewall Configuration/ Management:
- Candidates should have at least -12+ years of experience working in Security Domain ( SOC, Implementation and or Consultancy of Security Solutions
- Design, configure, and maintain firewall policies and rules, Natting.
- Configuring and Managing User defined categories, Whitelisted / Blacklisted URLs.
- Configure the Firewall policy for UTA feature to scan AV, IPS, Sandboxing encryption / decryption and know to allow exception from UTM scanning.
- Configure the Application policy bases on default available list or know to create custom application.
- Hands-on expert experience on NGFW firewall Checkpoint Cisco, Fortinet and Palto Alto to do failover, HA config, upgrade and L3 level of troubleshooting to packet capture.
- Monitor firewall performance and security, ensuring optimal operation.
- Performs security hardware and software maintenance to upgrade / downgrade devices.
- In depth knowledge and skills of working independently on Firewall management tools like FMC, Panorama, Forti Manager, Analyzer, Algosec.
- Configure the Context /Vdom/VSX base firewall and work with virtual firewalls.
WAF Configuration & Management
- Design, configure, and maintain WAF Traffic inspection and Filtering rules and policies
- Configuring and Managing Whitelisted / Blacklisted URLs.
- Configuration of Traffic Protection against various attacks ( SQL injection , XSS , Zero day attacks
- Deep knowledge on Rate limiting and Bot Management policies .
- Deep Knowledge of HTTS Protocol & SSL/TLS
- Monitor WAF security logs and alerts to detect and respond to threats.
- Perform regular security assessments and vulnerability testing on web applications.
- Conduct incident response and forensic analysis in the event of a security breach.
- Knowledge of OWASP Top Ten
- Hands-on experience with one or more WAF platforms (e.g., Imperva, AWS WAF, F5, Azure WAF).
- Hands-on experience of upgrading WAF ( hardware based WAF)
NAC Configuration & Management
- Design, configure, and maintain NAC of various OEM ( Cisco or Forescout or Aruba . )
- Create authentication ,authorization and posture policy for user
- Create device authentication, authorization policy and shell profiles
- Good knowledge of TACACS/Radius protocols
- Expert knowledge of Design and architecture .
- Deep Knowledge of integration of NAC with other network and other infrastructure components ( ie Switches , wireless controller , firewalls, AD , LDAP )
- Familarity with direcetory services like AD and LADAP
- Troubleshooting knowledge of NAC ( Cisco ISE, Forsecout etc)
Firewall and WAF or NAC Migration and Implementation:
- Plan and execute firewall and WAF migrations from different OEM or Same OEM to different hardware, ensuring minimal disruption to network services.
- Implement new firewall solutions, including Planning to execution with next-generation features.
- Test and validate firewall configurations with industry best practise before deployment.
- Hands on experience of execution of firewall & WAF Migration projects/assignment in BFSI and other industry verticals
Design and Consulting:
- Provide expert consulting services on network security design and architecture.
- Develop secure network designs tailored to client needs, ensuring compliance with regulatory requirements.
- Collaborate with clients to understand their security requirements and provide customized solutions.
- Create and maintain detailed network documentation, Network Diagrams and procedures.
- Conduct regular security assessments and audits to identify and mitigate vulnerabilities.
- Provide the training session to colleague and customer team members.
Incident Handling:
- Lead the response to major security incidents, including detection, analysis, containment, eradication, and recovery.
- Develop and implement incident response plans and procedures.
- Conduct post-incident reviews and provide RCA.
- Good understanding on peer device technology like router switch’s and how these technology work e,g ARP, MAC , DNS , SNMP, VRRP, Routing.
- Excellent troubleshooting skills on wireshark captures / PCAP etc
Qualifications:
Education:
- Graduate in Computer Science/IT/Electronics Engineering or equivalent University degree.
Certifications:
- Relevant certifications such as CCIE Security or CCSE or PCNSE equivalent.
Being You
Diversity is a whole lot more than what we look like or where we come from, it’s how we think and who we are. We welcome people of all cultures, backgrounds, and experiences. But we’re not doing it single-handily: Our Kyndryl Inclusion Networks are only one of many ways we create a workplace where all Kyndryls can find and provide support and advice. This dedication to welcoming everyone into our company means that Kyndryl gives you – and everyone next to you – the ability to bring your whole self to work, individually and collectively, and support the activation of our equitable culture. That’s the Kyndryl Way.
What You Can Expect
With state-of-the-art resources and Fortune 100 clients, every day is an opportunity to innovate, build new capabilities, new relationships, new processes, and new value. Kyndryl cares about your well-being and prides itself on offering benefits that give you choice, reflect the diversity of our employees and support you and your family through the moments that matter – wherever you are in your life journey. Our employee learning programs give you access to the best learning in the industry to receive certifications, including Microsoft, Google, Amazon, Skillsoft, and many more. Through our company-wide volunteering and giving platform, you can donate, start fundraisers, volunteer, and search over 2 million non-profit organizations. At Kyndryl, we invest heavily in you, we want you to succeed so that together, we will all succeed.
Get Referred!
If you know someone that works at Kyndryl, when asked ‘How Did You Hear About Us’ during the application process, select ‘Employee Referral’ and enter your contact's Kyndryl email address.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ASM Audits AWS Azure CCIE Compliance Computer Science DNS Encryption Firewalls Incident response Intrusion detection IPS IT infrastructure LDAP Network security NGFW OWASP PCAP Risk management Security assessment SOC SQL SQL injection TLS Vulnerabilities XSS Zero-day
Perks/benefits: Career development Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.