Cybersecurity Risk and Compliance Engineer
Hewlett Packard Enterprise Bengaluru, Karnataka, India
IT Services and IT Consulting · 10,001+ employees
About the role
The role involves managing and monitoring third-party and supply chain cybersecurity risks, including conducting vendor audits and assessing system vulnerabilities. You will also be responsible for defining cybersecurity requirements, creating detailed reports on findings, and recommending mitigation strategies to ensure compliance with company standards.
What they look for
Requirements
Candidates must hold a bachelor's degree in computer science, engineering, or a related field with at least 4 years of relevant experience. Proficiency in cybersecurity risk assessment, network security, and industry standards like NIST and ISO is required, with professional certifications such as CISA or CISSP preferred.
Benefits
Full description
Cybersecurity Risk and Compliance Engineer
This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office.
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
Within HPE, our Operations, Legal and Admin teams work across the business, providing visible accountability and measurable outcomes. With a variety of roles and responsibilities these teams really connect the dots, giving us the essential insights, support and capability to accelerate our transformation to be the world’s edge to cloud company. Join us redefine what’s next for you.
Job Family Definition:
Identifies, tracks, monitors, and manages cybersecurity risks within our supply chain. Evaluates and guides vendors, third parties and supply chain teams in the development and implementation of controls to address systems vulnerabilities. Researches threat intelligence, vulnerabilities, campaigns and indicators of compromise. Define cybersecurity requirements and performs annual vendor audits to assess and ensure controls are in place.
Management Level Definition:
Applies developed subject matter knowledge to solve common and complex business issues and recommends appropriate alternatives. Works on problems of diverse complexity and scope. May act as a team or project leader providing direction to team activities and facilitates information validation and team decision making process. Exercises independent judgment to identify and select a solution. Ability to handle most unique situations. May seek advice in order to make decisions on complex business issues. What you’ll do:
Responsibilities:
- Manages and proactively monitors Third Party Risk Management and supply chain cybersecurity system issues and threats.
•Develop cybersecurity audit assessments, scopes and content with accuracy and timeliness. •Coordinates and perform cybersecurity audit activities, third party assessments, assess controls in place, document and communicate findings. •Evaluate risks and controls in place to determine priorities and provide recommendations on mitigation strategies. •Ensure compliance with company cybersecurity standards, policies and government regulations •Create detailed cybersecurity reports with findings and gaps. Monitor actions to address findings until closure. •Combines industry expertise with a thorough understanding of information and security technology to direct vendor design of software patches. •Recommends and coordinates the development, enhancement, organization, and maintenance of a client's or company's security solutions, including research and security system analysis. •Evaluates internal systems, define or update supply chain cybersecurity standards, policies and processes. •Developing and tracking Third Party Assessments and audit related Plan & Milestones and associated performance metrics
What you need to bring:
Education and Experience Required:
- Bachelors degree required, preferably in computer science, engineering or related area of study
- Typically 4+ years of relevant experience
- Certifications: Preferred CISA or CISSP or other cybersecurity and risk related certification
Knowledge and Skills:
- Ease to communicate at all levels, including management level presentations and summaries.
- Advanced Cyber and IT security knowledge
- Advanced understanding of Cyber and IT security risks, threats and prevention measures
- Understanding of SQL and relevant scripting languages
- Advanced security system analysis skills
- Advanced understanding of security standards and best practices
- Advanced risk assessment and management skills
- Advanced understanding of networking and network security
- Advanced understanding of network monitoring and protocols
- Knowledge of relevant .Net development, programming and scripting languages
- Advance experience in writing technical reports that analyze and interpret results.
- Experience in Third Party Assessments (SaaS, IaaS, On Premises, Contractors, etc.)
- Understanding of relevant industry security standards and protocols including, NIST, ISO, SOC2 Type II, etc.
- Travel required.
What We Can Offer You:
Health & Wellbeing
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Unconditional Inclusion
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Let's Stay Connected:
Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.
#india
Job:
Information TechnologyJob Level:
Specialist
HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.
Hewlett Packard Enterprise is EEO Protected Veteran/ Individual with Disabilities.
HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.
Recruitment Fraud Alert
We have become aware of an increase in fraudulent recruitment activities in which individuals impersonate our company or authorized recruitment agencies to offer fake employment opportunities. These scams may occur through false websites, emails, social media, or chat-based applications and often aim to obtain personal information or money. Please note that Hewlett Packard Enterprise (HPE), its direct and indirect subsidiaries and affiliated companies, and its authorized recruitment agencies/vendors will never charge a candidate a registration fee, hiring fee, or any other fee in connection with its recruitment and hiring process. We also never request personal information such as back account details, Social Security numbers, or national IDs via social media or chat applications.
All legitimate job opportunities will come through official company channels, and candidates are responsible for verifying the credentials of any third party claiming to represent the company. Any reliance on fraudulent communication is at the individual’s own risk, and HPE disclaims legal liability for any resulting damages. If you suspect recruitment fraud, do not share personal information or make any payments and report the incident to your local authorities immediately.
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom