About Us:
LTIMindtree is a global technology consulting and digital solutions company that enables enterprises across industries to reimagine business models, accelerate innovation, and maximize growth by harnessing digital technologies. As a digital transformation partner to more than 700+ clients, LTIMindtree brings extensive domain and technology expertise to help drive superior competitive differentiation, customer experiences, and business outcomes in a converging world. Powered by nearly 90,000 talented and entrepreneurial professionals across more than 30 countries, LTIMindtree — a Larsen & Toubro Group company — combines the industry-acclaimed strengths of erstwhile Larsen and Toubro Infotech and Mindtree in solving the most complex business challenges and delivering transformation at scale. For more information, please visit www.ltimindtree.com.
Job Description:
IT Security Analyst
Cloud Security Analyst
Reporting to the IT Security Manager, the IT Security Analyst is a position based in North Carolina.
Responsibilities:
- Hands on experience on security testing tools, such as Burp Suite, Mimikatz, Cobalt Strike, PowerSploit, Metasploit, Qualys, Web Inspect or other tools included within the Kali Linux distribution
- Experience in security assessment activities within a client’s environment, emphasizing manual stealthy testing techniques using commercially / freely available offensive security tools and utilities built into operating systems.
- Work closely with technical teams to assess the security posture of systems and applications through vulnerability assessments and penetration testing.
- Good understanding of cloud technologies and its security best practices
- Fine-tune WAF policies and configurations to optimize security while minimizing false positives.
- Configure, deploy, and maintain Web Application Firewalls (WAF) in production and development environments.
- Coordinating investigations and reporting of security incidents related to Network, Systems and applications
- Coordinate and execute IT security projects for Arista at multiple locations
- Engage in security research in keeping abreast of the latest security issues for Cloud enabled enterprises (including SAAS and IAAS)
- Monitoring system compliance with the IT framework for controls and levels of access; recommending improvements
- Collaborate with other groups inside Arista to manage security vulnerabilities and help manage risks
- Administer security-dedicated systems (Software, Firewall management, EDR, NDR, log collection, reporting , analytics, Cloud Security consoles) as appropriate
- Experience with CSPM tools such as WIZ,Lacework ,Google Security Command Center.
- Terraform, CloudFormation, Forseti and other similar tools experience is highly desired
- Conduct and collaborate on laptop and server forensics as well as Cloud / Service Provider forensics with the global security team
- Perform other related duties as assigned.
Qualifications:
- BA or BSc. in Computer Science, Management Information Systems, Information Assurance or related field
- Advanced degree desirable
- Must have 6+ years of progressive experience in computing and information security
- Knowledge of common adversary tactics and techniques, e.g., obfuscation, persistence, defense evasion, etc
- Knowledge of Mitre ATT&CK framework preferred
- Good knowledge of security fundamentals, Networking protocols, TCP/IP stack, systems architecture, and operating systems
- Must have practical experience in Privacy Controls and implementing them in a corporate environment
- Expert knowledge is desired of laptop operating systems (MacOS, Windows and Linux)
- Proven project management experience a bonus - specifically experience in managing remote office configuration and bringing up and working with remote / off-site vendors
- Experience working in a large cloud or Internet software company
- Business Application security analysis and practical experience is a plus (eg: SFDC, NS, SiSense)
- CISSP, GIAC or other security certifications desired.
- Knowledge of information security standards (e.g., ISO 17799/27002, etc.), rules and regulations related to information security and data confidentiality (e.g., FERPA, HIPAA, etc.) and desktop, server, application, database, network security principles for risk identification and analysis.
- This position requires some weekend and evening assignments as well as availability during off-hours for participation in scheduled and unscheduled activities.
Benefits/perks listed below may vary depending on the nature of your employment with LTIMindtree (“LTIM”):
Benefits and Perks:
- Comprehensive Medical Plan Covering Medical, Dental, Vision
- Short Term and Long-Term Disability Coverage
- 401(k) Plan with Company match
- Life Insurance
- Vacation Time, Sick Leave, Paid Holidays
- Paid Paternity and Maternity Leave
The range displayed on each job posting reflects the minimum and maximum salary target for the position across all US locations. Within the range, individual pay is determined by work location and job level and additional factors including job-related skills, experience, and relevant education or training. Depending on the position offered, other forms of compensation may be provided as part of overall compensation like an annual performance-based bonus, sales incentive pay and other forms of bonus or variable compensation.
Disclaimer: The compensation and benefits information provided herein is accurate as of the date of this posting.
LTIMindtree is an equal opportunity employer that is committed to diversity in the workplace. Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnancy, childbirth or related medical conditions), gender identity or expression, national origin, ancestry, age, family-care status, veteran status, marital status, civil union status, domestic partnership status, military service, handicap or disability or history of handicap or disability, genetic information, atypical hereditary cellular or blood trait, union affiliation, affectional or sexual orientation or preference, or any other characteristic protected by applicable federal, state, or local law, except where such considerations are bona fide occupational qualifications permitted by law.