
Staff Security Engineer
Westinghouse Air Brake Technologies Corporation2 days ago
Bengaluru, IndiaStaff+
Responsibilities
- Lead the enterprise vulnerability management program across global technology environments.
- Manage vulnerability scanning platforms, assessment processes, remediation workflows, and enterprise security exposure reporting.
- Develop and improve risk-based vulnerability prioritization methodologies using threat intelligence, exploitability data, vulnerability scoring, and business context.
- Partner with infrastructure, cloud, application, operations, architecture, compliance, and business teams to drive vulnerability and control-gap remediation.
- Monitor remediation performance, establish service-level targets, and report risk reduction and remediation progress to leadership and stakeholders.
- Conduct vulnerability trend analysis and recommend strategic improvements for systemic security issues.
- Assess cloud environments for misconfigurations, vulnerabilities, and compliance risks.
- Collaborate with Security Operations to investigate critical vulnerabilities, active threats, and emerging enterprise security risks.
- Support threat management by evaluating threat intelligence and newly disclosed vulnerabilities and security advisories.
- Perform vulnerability validation, remediation verification, exception management, audit support, and compliance evidence collection.
- Lead and participate in cybersecurity projects involving security tools, platforms, and process improvements.
- Maintain vulnerability management standards, procedures, operational runbooks, and technical documentation.
- Provide Tier 3 escalation support for vulnerability management and related cybersecurity technologies.
- Evaluate new security technologies and industry practices to improve enterprise cybersecurity maturity.
- Support cybersecurity incidents, emergency activities, and planned maintenance during weekends or off-hours as required.
Requirements
- Bachelor’s degree in computer science, information technology, cybersecurity, or a related field, or at least five years of full-time cybersecurity experience.
- Demonstrated expertise leading enterprise vulnerability management programs across servers, endpoints, cloud platforms, applications, and network infrastructure.
- Extensive experience with vulnerability assessment technologies, remediation workflows, risk prioritization methodologies, and security exposure management.
- Strong understanding of vulnerability scoring frameworks, threat intelligence, exploitability analysis, and risk-based remediation.
- Experience developing metrics, reporting, and executive-level dashboards for security risk and remediation progress.
- Hands-on experience securing public cloud platforms such as AWS and Azure.
- Experience supporting Security Operations functions including threat detection, incident response, threat hunting, or security monitoring.
- Knowledge of enterprise operating systems, networking, system administration, and infrastructure technologies.
- Experience partnering with technical and business stakeholders across globally distributed environments to drive remediation.
- Strong project execution, communication, stakeholder management, time management, and influencing skills.
- Experience managing workstreams and maintaining operational transparency through IT Service Management platforms.
- Willingness to work weekends or off-shift hours during cybersecurity incidents.
- Preferred experience implementing Exposure Management or Attack Surface Management programs.
- Preferred experience integrating vulnerability management with Security Operations and Incident Response.
- Preferred knowledge of container, Kubernetes, and cloud-native security technologies.
- Preferred experience automating vulnerability management workflows using scripting or API integrations.
- Security certifications such as CISSP, GSEC, GCIH, Security+, or equivalent are preferred.
- Commitment to continuous learning and adaptation in an evolving cybersecurity landscape.
Benefits
- Hybrid work schedule with both on-site and remote work.
- Relocation assistance availability is confirmed.
- The role includes a temperature-controlled office environment, with occasional exposure to operational-area weather, fumes, chemicals, and loud noise.
- The position may require weekend or off-shift work for cybersecurity incidents, emergency activities, and planned maintenance.
- Equal employment opportunity and accommodation support are provided.