Search/hcltech
Vendor

hcltech

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
hcl digital experience
Connections
98 relationships
Chinese AI company Zhipu claims its new model is a better bug-finder than Anthropic, OpenAI
ASIA IN BRIEF Chinese company Zhipu last week launched a new AI model called GLM-5.3 that it claims has bug-finding powers that match those possessed by American models. The company’s announcement includes benchmark data that finds GLM-5.3 beats Fable 5 and GPT-5.6 Sol on the CyberGym benchmark, a test of a model’s ability to solve real-world cybersecurity challenges. “As we scaled post-training, cyber capability developed faster than we expected. GLM-5.3 is state of the art on CyberGym for vulnerability discovery, and its gains are largest further up the exploitation chain,” the company wrote, adding that the model “did not simply become better at identifying isolated flaws: it began to reason across multiple stages of exploitation, forming coherent plans for complete exploitation chains.” The company said it has worked with Chinese companies to test the model on real-world codebases, and found 2,436 vulnerabilities across 269 projects, including 1,097 medium-to-high severity issues. The findings span system kernels, operating systems, browser engines, open-source infrastructure, web applications, and network protocols. “Many had remained unnoticed for years or even decades, with the oldest dating back roughly 40 years,” the announcement states. GLM-5.3 also performed worse than western models on other security and coding benchmarks. Yet the fact that the model is a highly-capable bug finder signals that China is not far behind in terms of being able to poke holes in its rivals software and developed that capability very quickly after the debut of Anthropic’s Mythos. Any advantage the US felt it had as the home of Anthropic has therefore dissipated. Korea signals legal action against Apple, Google app store strangleholds South Korea’s Communications Commission last week found Google and Apple had abused their app store monopolies, and promised stern sanctions will follow. In 2021, South Korea passed world-first legislation requiring app store operators to offer the option to use third-party payment schemes. Apple and Google did so, but charged a 26 percent transaction fee for doing so – meaning they earned almost as much revenue when users chose third-party payment providers as they did from their own schemes. The regulator has previously warned that it will impose the highest possible penalty available under law, which is three percent of revenue earned by non-compliant behaviour. That’s probably back-of-the-sofa money for Apple and Google. India has banned rideshare operators from offering customers the chance to specify the amount they will tip before a driver accepts a gig. Uber India introduced the feature last year, seemingly copying it from an Indian rideshare operator called Namma Yatri. Consumer affairs minister Pralhad Joshi criticized Uber for the practice at the time, as he saw it as a means for users to effectively jump the queue by offering drivers more money – and for rideshare platforms to improve their revenue because if tips are higher, so is the platform’s share of the gratuity. Last week, India’s Ministry of Road Transport & Highways issued a directive (PDF) banning the practice. Henceforth, rideshare apps can only offer users the chance to tip at the end of a journey, and all of the tip must go to the driver. “No feature, prompt, message, add-on, payment option, or user interface element should be displayed before completion of the ride that directly or indirectly encourages, induces, or creates an impression that payment of any additional amount may improve ride confirmation, driver acceptance, driver allocation, waiting time, or quality of service,” the directive states. Indian services giants reveal data breaches Indian tech services giants TCS and HCL last week both admitted to data breaches but say customer data is safe, and only employee data is at risk. TCS published a stock exchange filing that opens “This is to inform you that Company has received threat-intelligence alerts alleging possible exposure of certain employee information.” The filing says TCS investigated the matter “and has not found any credible evidence of a breach of TCS systems or customer environments.” The company says leaked info is “basic employee information” and more than four years old. Note that mention of the stolen data being at least for years old, because TCS’s filing says the attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue to pull off the heist. TCS says it “had strong safeguards in place against such techniques for more than two years,” perhaps suggesting the data heist occurred before the company shored up its defenses. “Based on the current review, these controls remain effective, and the Company continues to monitor the environment closely,” the filing states. HCL also used a stock exchange filing [PDF] to address what it called “claims made by a hacker group of potential exposure of limited data elements relating to HCLTech employees.” The company described the stolen data as “limited and dated to a few years back,” and added its assurance that customer data is safe. HCL’s investigation is ongoing. Lenovo’s enterprise unit finally posts a big profit Lenovo last week announced its quarterly results, including a $777 million profit for its Infrastructure Solutions Group (ISG) – the biz based on the 2014 acquisition of IBM’s x86 server operation that has seldom produced positive financials. Even during the early years of the AI boom, ISG’s profits were modest – just a few million dollars per quarter on turnover of billions. The business unit won a record $8.5 billion of revenue, up 98 percent year-on-year. AI was a big reason for the result, as buyers sought hardware to run inferencing workloads, The company says it has a pipeline for $54 billion of AI server sales, and has become the number two x86 server vendor as measured by revenue. Overall revenue came in at $26.95 billion, up 43 percent year-on-year, and cash won by its PC-led intelligent devices group jumped 27 percent to $17.1 billion and saw its PC market share reach 24.2 percent. Lenovo reckons the strength of its supply chain helped make those outcomes possible. India to build astronaut training facility India’s Space Research Organization (ISRO) last week issued a tender for construction of an astronaut training facility. The tender mentions extensive air conditioning works, plus a swimming pool, suggesting India wants to build a large tank in which the Vyomanauts who will fly its future Gaganyaan missions can train at home, instead of traveling to Russia or elsewhere as has been the case in the past. The tender covers $2.75 million worth of work. ®
theregister.comAug 17, 2026extracted
Cybersecurity jobs available right now: February 3, 2026
Cybersecurity jobs available right now: February 3, 2026 Application Security Engineer Liebherr Group | Germany | Hybrid – No longer accepting applications As an Application Security Engineer, you will As an Application Security Engineer, you will implement and automate application security testing, perform vulnerability assessments and penetration testing, and work closely with developers to remediate issues and enforce secure coding practices. You will monitor and respond to application security threats while maintaining security documentation and compliance requirements. Application Security Expert – Information Systems HCLTech | France | Hybrid – No longer accepting applications As an Application Security Expert – Information Systems, you will perform cyber risk analyses, approve application security architectures, and provide secure-by-design guidance for IT projects and internet-exposed assets. You will analyze vulnerabilities, manage security services such as DevSec pipelines and IAM, execute operational controls, assess gaps against standards, produce security metrics, and collaborate across teams to support the IS and Security functions. Cyber Incident Responder UBS | Singapore | On-site – No longer accepting applications As a Cyber Incident Responder, you will handle security incidents end to end, from identification and containment through eradication and recovery. You will perform forensic analysis of systems, accounts, networks, and malware, act as a key engagement point within major incident management, and support response strategies for severe incidents and critical attack scenarios. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Security Principal Engineer Hoare Lea | United Kingdom | Hybrid – No longer accepting applications As a Cyber Security Principal Engineer, you will work within a specialist consultancy to engage clients, understand requirements, and deliver high-quality reports, designs, and tender documentation. You will provide deep expertise in ICT and OT networks within commercial buildings, advise on securing building systems through segmentation, secure protocols, and lifecycle controls, and guide clients toward a more resilient security ecosystem. Digital Forensics and Cyber Investigations, Associate Director DFIR Control Risks | United Kingdom | Hybrid – No longer accepting applications As a Digital Forensics and Cyber Investigations, Associate Director DFIR, you will lead forensic incident response engagements, providing expert scoping, data collection, and investigative analysis for clients. You will support adjacent teams across regions, deliver high-quality and defensible outputs, proactively anticipate client needs, foster collaboration and innovation, and help convert enquiries into opportunities and proposals. Executive Director, Application Security Architect Sony Pictures Entertainment | USA | Hybrid – View job details As an Executive Director, Application Security Architect, you will lead security design reviews across application, data, and cloud domains. You will assess risks, define security standards, ensure systems comply with Sony’s requirements, and recommend secure design patterns and best practices. Lead, Cyber Security Engineer TAQA Group | UAE | On-site – No longer accepting applications As a Lead, Cyber Security Engineer, you will design, integrate, and optimize SIEM/SOAR platforms to improve threat detection, incident response, and operational efficiency. You will manage configurations, rules, and compliance requirements, provide technical account management, and administer users, log sources, and system troubleshooting to ensure reliable security operations. Lead Offensive Engineer McKesson | USA | On-site – No longer accepting applications As a Lead Offensive Engineer, you will ead complex red team engagements to simulate attacks across infrastructure, applications, and data. You will translate security objectives into offensive strategies, develop and execute vulnerability discovery methodologies, clearly report findings to technical and non-technical stakeholders, recommend remediation actions, and lead purple team exercises. Lead Product Security Engineer Dematic | USA | On-site – No longer accepting applications As a Lead Product Security Engineer, you will ntegrate and operationalize cloud security tooling to build a cohesive security platform. You will advance highly automated product security capabilities, respond to and remediate prioritized security alerts, support application teams in embedding cloud security across the SDLC, and proactively identify and mitigate vulnerabilities across cloud infrastructure and applications. Lead/Senior Cyber Threat Analyst Peoplebank | Australia | On-site – No longer accepting applications As a Lead/Senior Cyber Threat Analyst, you will produce cyber threat intelligence reporting aligned to national priorities, research and analyze threat actors, and fuse event data with all-source intelligence to identify emerging risks. You will recommend mitigations, maintain standard operating procedures, and build strong relationships with internal stakeholders and customers. Lead Cybersecurity Engineer-AI Chevron | India | On-site – No longer accepting applications As a Lead Cybersecurity Engineer-AI, you will embed secure-by-design principles into enterprise digital capabilities while serving as a subject matter expert in AI security. You will define security architectures for AI solutions, lead AI security research and proofs of concept, and develop SOPs and assessment checklists to support secure adoption of emerging technologies. Network Security Architect Siemens Energy | Israel | Hybrid – No longer accepting applications As a Network Security Architect, you will design and implement secure OT and ICS network architectures, including SCADA, DCS, and PLC environments. You will lead IT/OT segmentation and access control strategies, define OT security standards and policies, and conduct risk and vulnerability assessments to strengthen protection of critical systems. OT Security Architect dormakaba | Germany | Hybrid – No longer accepting applications As an OT Security Architect, you will design and implement advanced security solutions to protect OT and IoT environments and critical production systems. You will advise leadership on OT and IoT security strategy, conduct risk assessments, define security requirements for new systems, and respond to incidents to maintain operational resilience and continuity. OT Cyber Security Engineer Schneider Electric | India | On-site – No longer accepting applications As an OT Cyber Security Engineer, you will interpret process control network architectures using the Purdue model to identify and manage cybersecurity devices. You will execute commissioning, upgrades, backups, and recovery for firewalls, switches, NMS, and backup systems, analyze security logs and alerts, and ensure compliance with RIL cybersecurity standards by identifying and remediating gaps in existing deployments. Penetration Testing Team Lead Check Point Software | Israel | Hybrid – No longer accepting applications As a Penetration Testing Team Lead, you will lead and scale a global team of testers, fostering a high-performance culture through mentoring and collaboration. You will own end-to-end delivery quality and customer experience, support pre-sales and scoping, manage resources and utilization, drive operational excellence through KPIs and process improvements, and collaborate cross-functionally to support strategic objectives. Principal Engineer – Security Architecture RBC | Canada | On-site – No longer accepting applications As a Principal Engineer – Security Architecture, you will engineer and deploy automated security governance integrated into CI/CD pipelines from code commit to production. You will design reusable security architecture patterns for cloud and on-prem environments, build tools to automate policy enforcement, and lead the evaluation and integration of emerging security technologies. Principal Product Security Engineer – Secure Software Development Red Hat | Italy | Remote – No longer accepting applications As a Principal Product Security Engineer – Secure Software Development, you will define the long-term technical strategy for the SSD team while shaping the broader PSRD roadmap to balance security and developer velocity. You will act as the final escalation point for complex risks and architectural decisions, establish comprehensive secure development standards, and design secure CI/CD and build pipelines that ensure integrity and valid attestations. Red Team Operator AXA Group Operations | France | Hybrid – No longer accepting applications As a Red Team Operator, you will plan and execute advanced red team operations and adversary emulation to test defenses across people, processes, and technology. You will conduct penetration testing, perform vulnerability research and exploitation, and develop custom tools and scripts to demonstrate attack paths and drive actionable security improvements. Security Firmware Engineer, Senior Qualcomm | Ireland | On-site – View job details As a Security Firmware Engineer, Senior, you will design and develop security software for AI accelerator cards, enabling trusted device assignment, secure lifecycle management, and interconnect security. You will implement SR-IOV–based isolated execution and attestation, integrate PCIe security protocols, and enforce secure boot, attestation, and security policies within Qualcomm’s trusted execution environment and security architecture. Security Consultant, Red Team, Mandiant Google | USA | On-site – No longer accepting applications As a Security Consultant, Red Team, Mandiant, you will you will identify security issues and design and implement controls, tools, and services to improve security. You will support and execute offensive cybersecurity engagements, work directly with clients to resolve issues, advise on remediation best practices, and collaborate with internal teams to expand and enhance client offerings. Senior Cyber Defense Analyst Abnormal AI | USA | Remote – No longer accepting applications As a Senior Cyber Defense Analyst, you will monitor and triage security alerts, investigate and respond to incidents across endpoint, cloud, and identity environments, and perform root cause analysis with documented remediation. You will proactively hunt threats using MITRE ATT&CK, analyze anomalies across diverse telemetry sources, and collaborate with threat intelligence, while also improving automation, playbooks, and detection logic to strengthen security operations. Senior Security Engineer LemFi | Ireland | Hybrid – No longer accepting applications As a Senior Security Engineer, you will secure and harden AWS infrastructure, implement and operate monitoring and detection capabilities, and embed security controls into CI/CD pipelines. You will maintain compliance and audit readiness, operate and tune SIEM for threat detection, and lead incident triage, response, and continuous improvement through playbooks and reviews. Senior Security Engineer, Application & Platform Security Sentry | Canada | Hybrid – No longer accepting applications As a Senior Security Engineer, Application & Platform Security, you will lead high-impact initiatives from concept through implementation to address critical security challenges. You will influence cross-company security objectives, evaluate scalable technologies to strengthen security posture, identify and mitigate threats and vulnerabilities, and enable teams to deliver solutions aligned with Secure-by-Design principles. Senior Security Architect Open Innovation AI | UAE | On-site – No longer accepting applications As a Senior Security Architect, you will design end-to-end security architecture for applications and hybrid cloud platforms while leading DevSecOps initiatives with automated CI/CD security controls. You will define security patterns for encryption, isolation, and zero trust, ensure regulatory compliance, and establish logging, monitoring, and documentation to support secure and scalable operations. Senior IT Security Penetration Tester Reserve Bank of Australia | Australia | Hybrid – No longer accepting applications As a Senior IT Security Penetration Tester, you will identify vulnerabilities across web applications, infrastructure, mobile, and wireless systems. You will produce clear reports with remediation recommendations for technical and business teams and conduct targeted vulnerability research on high-value systems. Senior SOC Analyst BESTSECRET | Italy | On-site – No longer accepting applications As a Senior SOC Analyst, you will monitor and analyze security events across cloud environments, optimize and create playbooks, and continuously improve detections and countermeasures. You will drive automation of responses and workflows, define detection rules, and identify hardening opportunities to help shape the future of the SOC.
helpnetsecurity.comFeb 3, 2026extracted
Cybersecurity jobs available right now: December 9, 2025
Cybersecurity jobs available right now: December 9, 2025 Associate Analyst, Cyber Threat Intelligence Sony | USA | Remote – No longer accepting applications As an Associate Analyst, Cyber Threat Intelligence, you will collect and analyze open-source threat data to identify signs of cyber threats. You will prepare analysis reports, threat assessments, and briefings for GSIRT and its stakeholders. You will also support projects that improve data collection, interpretation, and other threat intelligence processes. Cyber Security Manager Chubb Fire & Security | Australia | On-site – No longer accepting applications As a Cyber Security Manager, you will design and implement security solutions across cloud and on-prem environments. You will strengthen governance frameworks and improve overall security maturity. You will also serve as the SME, providing strategic and technical leadership for systems, applications, and data security. Cyber Security Threat Hunting Tools Administrator Vector Synergy | France | On-site – No longer accepting applications As a Cyber Security Threat Hunting Tools Administrator, you will design, deploy, and manage threat-hunting tools, ensuring they integrate smoothly with existing technologies. You will maintain secure operations, meet IT service management requirements, document deployments, and manage test environments. You will also apply workflow automation best practices to improve efficiency and reliability. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Architect Experis | Israel | On-site – No longer accepting applications As a Cybersecurity Architect, you will define security requirements and operational procedures for infrastructure, development, and application teams. You will design and implement secure architectures for cloud and on-premises environments. You will lead resilience and penetration testing across systems and manage security throughout their lifecycle. You will also develop and apply security standards based on frameworks such as NIST, ISO, and CIS. Cybersecurity Engineer Expert TXT GROUP | Italy | Hybrid – No longer accepting applications As a Cybersecurity Engineer Expert, you will perform vulnerability assessments on systems and applications in the aeronautical sector. You will apply bug-fixing techniques aligned with OWASP and SANS best practices. You will work with technical teams to manage security issues and support the definition and adoption of cybersecurity solutions and tools. Division Director, Cybersecurity BAYADA Home Health Care | USA | On-site – No longer accepting applications As a Division Director, Cybersecurity, you will develop and evolve a cybersecurity strategy aligned to BAYADA’s mission, regulations, and priorities. You will advise executive leadership on emerging threats, resilience, and cyber risk. You will identify and manage risks affecting clients, staff, operations, and AI-powered solutions. You will also lead security measures that protect data, systems, and AI assets while ensuring privacy and compliance. Email Security Analyst (AI Operations) Aegis AI Security | USA | Remote – No longer accepting applications As an Email Security Analyst (AI Operations), you will analyze suspicious emails, attachments, and links to identify threats and attack patterns. You will create reports and dashboards that highlight trends and support actionable recommendations. You will document and improve processes for investigation, escalation, and communication. Information Security Manager (SOC Operations) Mazrui International | UAE | On-site – No longer accepting applications As an Information Security Manager (SOC Operations), you will oversee SOC monitoring, detection, and incident response. You will manage IT compliance and governance, maintain alignment with ISO 27001, lead audits, address findings, and support security training. You will design and maintain security architecture and integrate security into system and network designs. You will also manage risk, incidents, and change processes to ensure secure operations. Information Security Officer Retail inMotion | Ireland | Hybrid – No longer accepting applications As an Information Security Officer, you will lead the deployment, maintenance, and improvement of the Information Security Management System in line with ISO 27001, PCI DSS, and business needs. You will develop policies, deliver staff training, and coordinate internal and external audits. You will also analyze security alerts, manage vulnerabilities, and work with teams to reduce risk. Information Systems Security Officer Docebo | Canada | Hybrid – No longer accepting applications As an Information Systems Security Officer, you will manage the FedRAMP governance model and maintain all ATO package documents, including the SSP, SAR, ConMon artifacts, and POA&Ms. You will build and run the continuous monitoring program, define required telemetry, and oversee vulnerability intake and reporting. You will triage vulnerabilities, manage POA&Ms, and ensure remediation meets FedRAMP expectations. IoT Architect Philip Morris International | China | On-site – View job details As an IoT Architect, you will work with cross-functional teams to define functional specifications for complex B2C and B2B2C use cases. You will design security architecture for embedded firmware and AWS cloud solutions, translate concepts into real designs, and guide development and testing. You will support product teams with best practices for cloud, firmware, and security, drive key architectural requirements, and contribute to firmware development for next-generation products. Network Security Lead Gas Networks Ireland | Ireland | Hybrid – No longer accepting applications As a Network Security Lead, you will design and maintain network security architecture across perimeter, DMZ, B2B, data center, and OT-adjacent environments, using segmentation and zero trust principles. You will define rule-base strategy, manage the full policy lifecycle, and reduce over-privilege. You will administer and optimize next-gen firewalls and related security controls. You will also ensure comprehensive logging, high-quality alerts, and SIEM and SOAR integration. Offensive Security Researcher Upwind Security | Israel | On-site – No longer accepting applications As a Offensive Security Researcher, you will research vulnerabilities in major cloud providers and emerging technologies. You will work with product and GTM teams to turn findings into features. You will investigate cloud-native environments, including Kubernetes, eBPF, and AI/ML-based detection, and translate results into production-ready detections. OT Cyber Security Consultant Moore Kingston Smith | United Kingdom | Hybrid – No longer accepting applications As an OT Cyber Security Consultant, you will assess OT and ICS security risks across operational assets and supporting systems. You will develop and refine security requirements for OT system design and protection throughout the supply chain and nuclear operations. You will also perform security assurance activities to verify that suppliers and asset owners have adequate security measures in place. Security Consultant II (Mobile Application Penetration Tester) NetSPI | Canada | Remote – No longer accepting applications As a Security Consultant II (Mobile Application Penetration Tester), you will conduct penetration tests on mobile applications and their APIs. You will identify issues in data storage, communication, and cryptography. You will also create and deliver penetration testing reports and work with clients to improve their security posture. Security Operations Center Lead Syensqo | Italy | Hybrid – No longer accepting applications As a Security Operations Center Lead, you will develop and implement the SOC and VOC strategy to support organizational security and business needs. You will create security policies, standard operating procedures, and incident response plans. You will also define and report KPIs to measure and improve SOC and VOC performance. Senior Associate Director, Principal Incident Responder HSBC | India | Hybrid – No longer accepting applications As a Senior Associate Director, Principal Incident Responder, you will lead technical and forensic investigations for global cyber events, ensuring timely threat identification and reducing risk to HSBC’s assets. You will oversee post-incident reviews, assess control and detection effectiveness, and support necessary improvements. You will also lead forensic services, ensuring sound evidence collection, preservation, analysis, and presentation while maintaining chain-of-custody for incident and vulnerability investigations. Senior Infrastructure Engineer HCLTech | France | Hybrid – No longer accepting applications As a Senior Infrastructure Engineer, you will manage and maintain hosted infrastructure across servers, storage, backups, security, OS, VMware, Citrix, and databases. You will design and implement upgrades and produce technical documentation and compliance reports. You will ensure security and resilience through hardening, backup and recovery, and DR measures. You will automate operational processes using CI/CD and provisioning tools, and deploy dashboards and KPIs to monitor and optimize infrastructure performance. Senior Threat Hunter & Digital Forensics Engineer Etisalat Services Holding | UAE | On-site – No longer accepting applications As a Senior Threat Hunter & Digital Forensics Engineer, you will track emerging threats through intelligence sources and lead forensic investigations for incidents such as APTs, ransomware, insider threats, and major breaches. You will use forensic tools to collect and analyze evidence with proper chain of custody. You will perform deep analysis of SIEM, IDS/IPS, firewall, EDR, and network data, and develop advanced threat-hunting queries and detection logic to uncover stealthy activity. Senior Security Engineer Suncorp Group | Australia | Hybrid – No longer accepting applications As a Senior Security Engineer, you will deliver security automation tools that improve resilience and efficiency. You will advise teams on complex security issues and help implement uplift strategies across technology platforms. You will identify emerging threats, design controls, and optimize processes while sharing knowledge to strengthen capability across teams. SOC Analyst Arctiq | USA | On-site – No longer accepting applications As a SOC Analyst, you will investigate and respond to system, service, and network attacks using forensic and incident response skills. You will apply your security expertise to support projects and programs. You will also work with Security Engineers to build proactive defenses, automation, and event detection into the Arctiq SOC. Specialist Information Security 4flow | Germany | Hybrid – No longer accepting applications As a Specialist Information Security, you will manage compliance requirements, conduct risk assessments, and support evaluations of control effectiveness. You will refine policies, standards, and procedures, lead audits and certifications, and help develop and operate the Information Security Management System (ISMS). Tech lead – Vulnerability Management Colt Technology Services | United Kingdom | Hybrid – No longer accepting applications As a Tech lead – Vulnerability Management, you will design and manage periodic penetration testing and configure vulnerability scans and reporting. You will troubleshoot scan failures and tool issues, identify false positives, and work with vendors to resolve them. You will drive remediation efforts with stakeholders and monitor progress to ensure vulnerabilities are mitigated as required. Threat Intelligence Specialist Deutsche Börse Group | Germany | Hybrid – No longer accepting applications As a Threat Intelligence Specialist, you will conduct threat intelligence operations and deliver strategic, actionable reports that guide decisions and reduce risk. You will collect and analyze intelligence from OSINT, commercial feeds, dark web sources, and industry groups to identify emerging threats. You will work with SOC, CERT, and leadership to support investigations, incident response, and awareness efforts. You will also perform threat hunting based on relevant IoCs. Vulnerability Analyst VSolvit | USA | On-site – No longer accepting applications As a Vulnerability Analyst, you will analyze logs from multiple systems, build and maintain SIEM dashboards and alerts, and understand OS and network log patterns. You will configure and review Nessus scans, validate findings, reduce false positives, and prioritize remediation. You will support vulnerability lifecycle processes and apply risk scoring methods such as CVSS.
helpnetsecurity.comDec 9, 2025extracted
Cybersecurity jobs available right now: October 7, 2025
Cybersecurity jobs available right now: October 7, 2025 Application Security / DevSecOps Engineer AvetixCyber | USA | Remote – No longer accepting applications As an Application Security / DevSecOps Engineer, you will integrate security tools and processes into CI/CD pipelines, perform secure code reviews, architecture risk assessments, and threat modeling. Develop and maintain security automation scripts and policies for build pipelines. Manage vulnerability triage, prioritize fixes, and track closure through ticketing systems. Cryptography Governance Analyst RBC | Canada | On-site – No longer accepting applications As a Cryptography Governance Analyst, you will work with the cryptography governance team to maintain the governance framework and support the creation and upkeep of related policies and procedures. You will collaborate with cross-functional teams to execute governance processes and ensure compliance with relevant security standards. Additionally, you will analyze data, provide recommendations for governance workstreams, and help mitigate cryptographic compliance risks. Cybersecurity Analyst Societe Generale Global Solution Centre | India | Hybrid – No longer accepting applications As a Cybersecurity Analyst, you will ensure applications comply with global audit and regulatory programs. You will deploy, troubleshoot, and maintain security solutions, while independently conducting Application Security Assessments, security control evaluations, and providing security recommendations. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Engineer Zung Fu Company Limited | Hong Kong | On-site – No longer accepting applications As a Cybersecurity Engineer, you will design, implement, and manage a comprehensive suite of security tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), and endpoint protection. Proactively monitor networks, systems, and cloud environments for security breaches and anomalies, utilizing tools such as SIEM, EDR, and native platform logs. Conduct vulnerability assessments, penetration testing, and patch management to identify, prioritize, and remediate security weaknesses across servers, PCs, and network devices. Cyber Security Engineer Thales | Italy | Hybrid – No longer accepting applications As a Cyber Security Engineer, you will design, implement, and monitor security measures to protect systems and data. You’ll define security requirements, configure and troubleshoot security tools, and automate solutions to mitigate vulnerabilities. You will also conduct vulnerability assessments, penetration tests, and regular security scans. Cybersecurity and IT Risk Lead Farmlands Co-operative Society | New Zealand | On-site – No longer accepting applications As a Cybersecurity and IT Risk Lead, you will develop and execute the cybersecurity strategy aligned with the NIST CSF 2.0 and maintain a multi-year maturity roadmap. You will own and operate the enterprise IT risk management program, ensuring integration with enterprise risk and internal audit functions. Cybersecurity PAM Manager PwC | USA | On-site – No longer accepting applications As a Cybersecurity PAM Manager, you will manage client engagements relating to the creation of business processes and solutions enabled by identity and access management. As a Manager you are expected to lead teams and manage client accounts, focusing on strategic planning and mentoring junior staff. Cyber Security Manager RICS | United Kingdom | Hybrid – No longer accepting applications As a Cyber Security Manager, you will develop and implement security policies, procedures, and governance frameworks. Manage and respond to security incidents, including investigations and remediation. Conduct regular risk assessments to identify vulnerabilities and recommend mitigations. Ensure compliance with relevant regulations and standards (e.g. GDPR, PCI-DSS). Cyber Security OT Assurance Senior Analyst ENOC | UAE | On-site – No longer accepting applications As a Cyber Security OT Assurance Senior Analyst, you will conduct OT cyber security analysis of the technology environment to identify gaps and recommend solutions for improvement. Validate and verify OT systems security requirements definitions and analysis and established system security designs. Conduct periodic cyber security assessments of existing OT controls and the technology landscape within the Organization (vulnerability scanning, penetration testing and Red Teaming exercises). Cyber Security Specialist Commit | Israel | On-site – No longer accepting applications As a Cyber Security Specialist, you will lead and manage security projects across enterprise IT environments, ensuring alignment with best practices and regulatory requirements. Secure and maintain servers, storage platforms, and network infrastructure, with a focus on availability and resilience. Data Loss Prevention Specialist / Engineer Delphi Consulting | India | Remote – No longer accepting applications As a Data Loss Prevention Specialist / Engineer, you will be responsible for implementing, administering, and managing compliance policies and tools across Microsoft 365 workloads to ensure regulatory alignment, data protection, and risk management. Data Protection Officer humm group | Ireland | Hybrid – No longer accepting applications As a Data Protection Officer, you will develop, implement and oversee the Group’s data protection framework, policies and processes to ensure compliance with GDPR/UKGDPR and industry best practice. Implement systems and processes to monitor, identify and mitigate data protection risks across business units and jurisdictions. Director of Application Security Hewlett Packard Enterprise | USA | Hybrid – No longer accepting applications As a Director of Application Security, you will define and execute the enterprise application security strategy aligned with business objectives and regulatory requirements. Develop and mature programs for secure software development. Partner with engineering, DevOps, and cloud teams to embed security tooling into CI/CD pipelines and workflows. ForgeRock IAM Developer HCLTech | United Kingdom | On-site – No longer accepting applications As a ForgeRock IAM Developer, you will design and implement ForgeRock Access Manager (AM) solutions for secure authentication, authorization, and session management across banking applications. You will define and enforce access policies aligned with regulatory standards and perform security assessments, threat modeling, and performance tuning of ForgeRock AM components. Global Cybersecurity Compliance Manager Amer Sports | Germany | On-site – No longer accepting applications As a Global Cybersecurity Compliance Manager, you will design, implement, and maintain a unified cybersecurity compliance program aligned with internal policies and external regulations. Develop dashboards, KPIs, and reporting to monitor global compliance status. Manage annual PCI DSS assessments, SAQs, and ROC processes with external QSAs. Identify compliance risks and gaps; propose and drive mitigation plans. Information Security Compliance & Audit ODDO BHF | Germany | Hybrid – No longer accepting applications As an Information Security Compliance & Audit, you will define and execute security audit and control plans for ODDO BHF’s internal ecosystem and external suppliers, ensuring alignment with standards such as ISO 2700x, BSI, and NIST. You will also develop and implement monitoring plans and review self-assessment results using a risk-based approach. Lead Threat Researcher Arctic Wolf | Ireland | Hybrid – No longer accepting applications As a Lead Threat Researcher, you will analyze threat surfaces and telemetry, collaborate with leadership to address threats, and enhance detection coverage. You’ll develop and refine detections, write secure and efficient code, and create runbooks and reports. Additionally, you’ll document findings and communicate insights across technical and non-technical teams. Manufacturing Cybersecurity Lead Bridgestone | Italy | Hybrid – No longer accepting applications As a Manufacturing Cybersecurity Lead, you will be responsible for safeguarding the organization’s OT environments, including ICS, SCADA, PLCs, and other industrial systems, from cyber threats. You will lead a team of Cybersecurity Specialists to design and implement processes, policies, and solutions based on industry-leading practices, supporting the secure deployment of industrial control systems and applications across manufacturing plants. Penetration Tester CyberForce R&D | Israel | Hybrid – No longer accepting applications As a Penetration Tester, you will conduct penetration tests on applications, networks, cloud environments, and infrastructure to identify security vulnerabilities. Simulate real-world attacks to evaluate security controls and assess the effectiveness of defensive measures. Develop detailed reports outlining findings, risk assessments, and remediation recommendations. Penetration Tester TMC | France | Hybrid – No longer accepting applications As a Penetration Tester, you will perform penetration tests on networks, applications, and infrastructure, conduct vulnerability assessments, and recommend remediation strategies. You will simulate real-world attacks to test resilience, collaborate with SOC and Blue Teams on security enhancements, and support incident investigations with offensive security expertise. Senior Cloud Security Engineer CyberGate Defense | UAE | On-site – No longer accepting applications As a Senior Cloud Security Engineer, you will design, implement, and manage Microsoft Purview DLP policies across all Microsoft 365 workloads. Administer and secure Microsoft Entra ID (Azure AD), including Conditional Access, Identity Protection, PIM, and SSO integrations. Perform comprehensive Cloud Security Gap Assessments against standards like NIST and ISO 27001, providing actionable remediation plans. Senior Security Architect Shift Technology | France | Hybrid – No longer accepting applications As a Senior Security Architect, you will design and maintain the security reference architecture for our Azure-native, Windows, and Kubernetes-based SaaS products. Lead threat modeling exercises (e.g., STRIDE) with development teams for new products and features to identify and mitigate risks early in the SDLC. Develop security-as-code and Infrastructure as Code (IaC) to create guardrails and detect insecure configurations. Senior Security Consultant (AI/ML Penetration Testing) NetSPI | Canada | Remote – No longer accepting applications As a Senior Security Consultant (AI/ML Penetration Testing), you will conduct engagements on AI/ML systems, web applications and API’s independently and provide technical oversight. Design and execute advanced adversarial testing (e.g., evasion, data poisoning, model extraction, inversion/inference) to expose vulnerabilities in AI/ML pipelines and architectures. Senior Security Engineer Aerospike | USA | Hybrid – No longer accepting applications As a Senior Security Engineer, you will design, implement, and maintain security controls that protect global infrastructure and real‑time data platform. You will develop secure architectures, automate security processes, and collaborate with DevOps and Platform teams to embed security into every layer of technology stack. SOC Cyber Threat Hunter StratasCorp Technologies | USA | On-site – No longer accepting applications As a SOC Cyber Threat Hunter, you will monitor real-time alerts, sessions, statistics, and full packet capture data. You will operate and manage intrusion detection and packet capture tools such as Wireshark, WinDump, and TCPDump, along with SIEM and CSSP security tools to oversee MSC networks. Your duties include examining alerts, performing triage, determining threat scope, correlating data, and conducting strategic analysis of IDS/IPS data.
helpnetsecurity.comOct 7, 2025extracted