Marsh McLennan

Manager - Cyber Security Secrets Management Gurugram - DLF Building

Remote Gurugram, India
AWS Azure GCP
Description

Company:

MMC Corporate

Description:

We are seeking a talented individual to join our GIS Team at MMC Corporate This role will be based in Gurgaon/Noida. This is a hybrid role that has a requirement of working at least three days a week in the office.

Manager - Cyber Security Secrets Management

What can you expect?

  • To manage the exposed secrets in our environment across the enterprise.
  • With the growing use of advanced technologies, cloud technologies, complex configurations, and fast pace to the cloud migration, this poses significant risk of unauthorized access and data breaches.
  • Secrets Management Specialist who will be performing investigations in identifying, classifying, and securing sensitive information across our infrastructure
  • . This candidate will be responsible for overseeing and managing the entire lifecycle of secrets across the enterprise.
  • This candidate will be responsible for overseeing the secrets management programs to ensuring security policies and procedures for secure storing, rotation, and access control of secrets are followed.
  • This candidate will operate the various secrets tools/systems daily.
  • This person will be performing continuously scanning and identifying exposed secrets.
  • The candidate will be responding to, supporting all secrets alerts, incoming IR incidents, and remediating secrets exposures.
  • The role will be communicating with cross functional teams of the risks and vulnerabilities associated to exposed secrets. Investing in this critical role will reduce risk of costly breaches, and increased compliance with data security regulations.

We will count on you to:

Strategic Planning and Governance

1.         Strategy, Policy, and Procedures Advancement: Maintain and lead comprehensive secret management strategy aligned with the organization’s overall security posture, compliance requirements, and cloud-native security best practices. Maintain and strengthen policies, standards, and procedures for secrets management, including access controls, rotation, remediations, and incident response.

2.         Risk Assessment: Conduct regular risk assessments to identify potential vulnerabilities, gaps, and threats related to secrets exposures in cloud and on-premises environments.

3.         Compliance Oversight: Ensure compliance with industry standards, regulations (e.g., NYDFS, GDPR, Privacy, DORAs, etc.), internal policies, and cloud provider security standards (e.g., AWS Security Best Practices, Azure Security Benchmark, GCP Security Best Practices, etc.).
 

Secret Discovery and Inventory

1.         Automated Discovery: Implement automated tools and techniques to identify and categorize secrets across the organization’s infrastructure cloud and on-premises infrastructures, applications, and code repositories.

2.         Manual Assessment Reviews: Conduct regular manual reviews to supplement automated discovery efforts for legacy systems and custom applications.  

3.         Inventory: Maintain a comprehensive and accurate inventory of all secrets, including their type, detection date, location, access controls, and cloud provider specific attributes.
 

Secrets Rotation and Management

1.         Rotation Policies: Maintain and enforce security rotation policies for all secrets, including cloud based secrets to minimize the risk of compromise.

2.         Automated Rotation: Maintain and oversee the automated tools to rotate secrets on a regular schedule, integrating with cloud providers rotation mechanisms.

3.         Secure Storage: Ensure secrets are stored securely and following the organization’s encryption technologies in cloud based secret vaults or hardware security modules.

4.         Access Controls: Maintain and ensure access controls to limit access to secrets to authorized personnel, leveraging the organization’s identity and access management capabilities.

Remediation

1.         Implement corrective actions to address vulnerabilities and prevent future incidents, including configurating cloud security controls and updating security policies.

2.         Maintain and support the incident response plan for secret exposure incidents.

3.         Support incident investigations and conduct thorough investigations to determine the root cause of secret exposure incidents, analyzing logs and security events.

4.         Assist in post-incident reviews to identify lessons learned and improve security practices.

What you need to have:

  • Secret Management Tools: Assist with the evaluation and selection of secret management tools that integrate seamlessly with various cloud environments and provide fine granular access controls.
  • Integration: Integrate the secret management tools with other security tools and systems, including the SIEM solutions.
  • Develop and deliver training programs to educate colleagues about the importance of secret management, cloud security best practices, and the specific risks associated with cloud based secrets for appliable cross functional teams.

What makes you stand out?

  • Experience in Cyber secret management

Why join our team:

  • We help you be your best through professional development opportunities, interesting work and supportive leaders.
  • We foster a vibrant and inclusive culture where you can work with talented colleagues to create new solutions and have impact for colleagues, clients and communities.
  • Our scale enables us to provide a range of career opportunities, as well as benefits and rewards to enhance your well-being.

Marsh McLennan (NYSE: MMC) is the world’s leading professional services firm in the areas of risk, strategy and people. The Company’s more than 85,000 colleagues advise clients in over 130 countries.  With annual revenue of $23 billion, Marsh McLennan helps clients navigate an increasingly dynamic and complex environment through four market-leading businesses. Marsh provides data-driven risk advisory services and insurance solutions to commercial and consumer clients. Guy Carpenter  develops advanced risk, reinsurance and capital strategies that help clients grow profitably and pursue emerging opportunities. Mercer  delivers advice and technology-driven solutions that help organizations redefine the world of work, reshape retirement and investment outcomes, and unlock health and well being for a changing workforce. Oliver Wyman serves as a critical strategic, economic and brand advisor to private sector and governmental clients. For more information, visit marshmclennan.com, or follow us on LinkedIn and X.

Marsh McLennan is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, caste, disability, ethnic origin, family duties, gender orientation or expression, gender reassignment, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.

Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person

Marsh McLennan (NYSE: MMC) is a global leader in risk, strategy and people, advising clients in 130 countries across four businesses: Marsh, Guy Carpenter, Mercer and Oliver Wyman. With annual revenue of $23 billion and more than 85,000 colleagues, Marsh McLennan helps build the confidence to thrive through the power of perspective. For more information, visit marshmclennan.com, or follow on LinkedIn and X.

Marsh McLennan is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age, background, caste, disability, ethnic origin, family duties, gender orientation or expression, gender reassignment, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law.

Marsh McLennan is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh McLennan colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office-based teams will identify at least one “anchor day” per week on which their full team will be together in person.

Marsh McLennan
Marsh McLennan

0 applies

4 views

Other Jobs from Marsh McLennan

Investment Data Project Lead

Remote Melbourne, Australia

Senior Platform Engineer

Remote San Francisco, CA

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 401 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say