Senior Cybersecurity Operations Specialist
|
SAPIENS INTERNATIONAL Security Specialist IT – Cybersecurity Operations | Cybersecurity Specialist | Full-Time | India |
ABOUT THE ROLE
Sapiens International is looking for a Security Specialist (Cybersecurity Specialist) to join our global IT Security team. This is a hands-on role for someone who wants to specialize in vulnerability management and cloud security — owning the end-to-end vulnerability lifecycle and the security of our cloud, container, and Kubernetes environments.
Familiarity with the other tools in our security stack — DNS security, CrowdStrike Falcon (EDR, Identity Protection, Exposure Management), Microsoft Purview, DLP, and email protection — is an added advantage, but the core of this role is hands-on, specialized ownership of vulnerability management and cloud security.
KEY RESPONSIBILITIES
Vulnerability Management & Automation
- Own the end-to-end vulnerability management lifecycle: asset discovery, scan orchestration, CVSS-based prioritization, ticketing, SLA tracking, and remediation validation
- Build AI-assisted automation pipelines that replace manual reporting, accelerate remediation, and surface actionable risk insights for stakeholders
- Develop integrations between security tools and ITSM platforms using Python, REST APIs, and scripting
- Maintain dashboards and automated reporting for vulnerability posture and compliance KPIs
Cloud Security
- Manage end-to-end security for cloud VMs, Kubernetes, and containerised workloads — ensuring secure configuration, runtime protection, and access controls across the infrastructure
- Manage and operate CSPM, CNAPP, and CWP platforms across cloud accounts — policy configuration, findings triage, SLA-driven closure, and compliance posture tracking against CIS, NIST, or PCI-DSS benchmarks
- Manage container image security and registry operations — image scanning in CI/CD and runtime, access controls, and audit logs, partnering with developers and DevOps teams to drive remediation without blocking releases
- Manage Kubernetes and cloud misconfiguration findings and translate them into actionable remediation tasks for platform and application teams
- Drive Azure, AWS, GCP, OCI security hardening in line with CIS, NIST, or equivalent frameworks
- Conduct security architecture reviews for new cloud workloads and projects
- Implement and manage modern authentication frameworks: cloud IDP, SSO, MFA, and Zero Trust principles
Other Security Tools & Projects (Added Advantage)
- Support administration of other tools in our stack — DNS security, CrowdStrike Falcon (EDR, Identity Protection, Exposure Management), Purview, DLP, and email protection/mail relay — as needed
- Work on additional security tool implementation, upgrades, and improvement projects assigned by the manager
- Partner with other IT and security teams to roll out new controls and policies
- Document standard operating procedures and runbooks for the tools you own
REQUIREMENTS
Experience
- 5+ years of experience in the cybersecurity field, with specialized, hands-on experience in vulnerability management and cloud security
- Proven experience owning the end-to-end vulnerability management lifecycle, from discovery through remediation
- Proven experience securing cloud, container, and Kubernetes environments, including CSPM, CNAPP, and CWP tools and compliance posture tracking
- Experience building security automation using Python, APIs, or scripting is a strong plus
- Exposure to other tools such as DNS security, CrowdStrike Falcon (EDR, Identity Protection, Exposure Management), Purview, DLP, or email protection is an added advantage
Technical — Must Have (Vulnerability Management)
- CVSS-based vulnerability prioritization, scan orchestration, and remediation validation
- Building automation and integrations between security tools and ITSM platforms using Python and REST APIs
- Maintaining dashboards and automated reporting for vulnerability posture and compliance KPIs
Technical — Must Have (Cloud Security)
- Hands-on experience with CSPM, CNAPP, and CWP platforms
- Securing cloud VMs, Kubernetes, and containerised workloads — configuration, runtime protection, and access controls
- Container image security and CI/CD scanning
- Cloud IDP, SSO, MFA, and Zero Trust principles
- Azure, AWS, GCP, or OCI security hardening (CIS, NIST, or equivalent frameworks)
- Security architecture reviews for cloud workloads
Soft Skills & Language
- Fluent written and verbal English
- Perceptive, fast learner with a strong sense of urgency
- Able to multi-task, and remain organized in a fast-paced global environment
- Highly independent and proactive, with a team-first mindset
Advantage (Not Required)
- Hands-on exposure to DNS security
- Hands-on exposure to the CrowdStrike Falcon platform (EDR, Identity Protection, Exposure Management)
- Familiarity with Microsoft Purview, DLP, or email protection/mail relay
- Security-related certifications: CISSP, CISM, CEH, CompTIA Security+, or vendor-specific (CrowdStrike, Microsoft, etc.)