
Security Consultant
- Mumbai, Maharashtra
- Permanent
- Full-time
As a Security Consultant at Kyndryl you will join the Kyndryl Consultant Profession, working with other Kyndryl Consultants, Architects, Project Managers, and cross-functional Technical Subject Matter Experts – presenting unlimited opportunities with unmatched support through our investment in your learning, training, and career growthWho You AreYou’re good at what you do and possess the required experience to prove it. However, equally as important – you have a growth mindset; keen to drive your own personal and professional development. You are customer-focused – someone who prioritizes customer success in their work. And finally, you’re open and borderless – naturally inclusive in how you work with others.Primary Domain Skills Area 1 any 2 firewalls as L3/ SME level ( Check Point, Palo Alto, FortiGate, Cisco) : Checkpoint Skills and Palo Alto Skills are preferred . Checkpoint Skills are Mandatory .Secondary Domain Skills Area 2: WAF/NAC ( F5 ASM , Radware WAF , Imperva WAF and or Akami WAF ) and ( Cisco ISE , Forescout NAC , Aruba Clear PassF5 ASM and Imperva WAF skills are Preferred with F5 ASM /WAF skills being mandatory .Required Skills and ExperienceFirewall Configuration/ Management:
- Candidates should have at least -12+ years of experience working in Security Domain ( SOC, Implementation and or Consultancy of Security Solutions
- Design, configure, and maintain firewall policies and rules, Natting.
- Configuring and Managing User defined categories, Whitelisted / Blacklisted URLs.
- Configure the Firewall policy for UTA feature to scan AV, IPS, Sandboxing encryption / decryption and know to allow exception from UTM scanning.
- Configure the Application policy bases on default available list or know to create custom application.
- Hands-on expert experience on NGFW firewall Checkpoint Cisco, Fortinet and Palto Alto to do failover, HA config, upgrade and L3 level of troubleshooting to packet capture.
- Monitor firewall performance and security, ensuring optimal operation.
- Performs security hardware and software maintenance to upgrade / downgrade devices.
- In depth knowledge and skills of working independently on Firewall management tools like FMC, Panorama, Forti Manager, Analyzer, Algosec.
- Configure the Context /Vdom/VSX base firewall and work with virtual firewalls.
- Design, configure, and maintain WAF Traffic inspection and Filtering rules and policies
- Configuring and Managing Whitelisted / Blacklisted URLs.
- Configuration of Traffic Protection against various attacks ( SQL injection , XSS , Zero day attacks
- Deep knowledge on Rate limiting and Bot Management policies .
- Deep Knowledge of HTTS Protocol & SSL/TLS
- Monitor WAF security logs and alerts to detect and respond to threats.
- Perform regular security assessments and vulnerability testing on web applications.
- Conduct incident response and forensic analysis in the event of a security breach.
- Knowledge of OWASP Top Ten
- Hands-on experience with one or more WAF platforms (e.g., Imperva, AWS WAF, F5, Azure WAF).
- Hands-on experience of upgrading WAF ( hardware based WAF)
- Design, configure, and maintain NAC of various OEM ( Cisco or Forescout or Aruba . )
- Create authentication ,authorization and posture policy for user
- Create device authentication, authorization policy and shell profiles
- Good knowledge of TACACS/Radius protocols
- Expert knowledge of Design and architecture .
- Deep Knowledge of integration of NAC with other network and other infrastructure components ( ie Switches , wireless controller , firewalls, AD , LDAP )
- Familarity with direcetory services like AD and LADAP
- Troubleshooting knowledge of NAC ( Cisco ISE, Forsecout etc)
- Plan and execute firewall and WAF migrations from different OEM or Same OEM to different hardware, ensuring minimal disruption to network services.
- Implement new firewall solutions, including Planning to execution with next-generation features.
- Test and validate firewall configurations with industry best practise before deployment.
- Hands on experience of execution of firewall & WAF Migration projects/assignment in BFSI and other industry verticals
- Provide expert consulting services on network security design and architecture.
- Develop secure network designs tailored to client needs, ensuring compliance with regulatory requirements.
- Collaborate with clients to understand their security requirements and provide customized solutions.
- Create and maintain detailed network documentation, Network Diagrams and procedures.
- Conduct regular security assessments and audits to identify and mitigate vulnerabilities.
- Provide the training session to colleague and customer team members.
- Lead the response to major security incidents, including detection, analysis, containment, eradication, and recovery.
- Develop and implement incident response plans and procedures.
- Conduct post-incident reviews and provide RCA.
- Good understanding on peer device technology like router switch’s and how these technology work e,g ARP, MAC , DNS , SNMP, VRRP, Routing.
- Excellent troubleshooting skills on wireshark captures / PCAP etc
- Graduate in Computer Science/IT/Electronics Engineering or equivalent University degree.
- Relevant certifications such as CCIE Security or CCSE or PCNSE equivalent.