BAT is evolving at pace into a global multi-category business. Our purpose is to create A Better Tomorrow™ by Building a Smokeless World.
To achieve our ambition, we are looking for colleagues who are ready to join us on this journey! Tomorrow can’t wait, let’s shape it together!
British American TobaccoIndia has an exciting opportunity for a Security Posture Management Specialist in Bangalore India
This role focuses on strengthening BAT’s cybersecurity posture through continuous monitoring, vulnerability management, and charge surface oversight. It involves implementing and making sure security configurations, leading vulnerability scanning and remediation efforts, and proactively assessing emerging threats using tools like Microsoft E5 and Qualys. Additionally, the role requires generating actionable reports for leadership, driving strategic security initiatives, and collaborating across teams to ensure compliance and mitigation of risks.
Your key responsibilities will include:
- Develop and implement continuous monitoring and enforcement of security configurations and policies across platforms using Microsoft E5 capabilities, while reducing configuration drift and ensuring compliance with BAT security, technical standards, and external regulations.
- Lead and optimize vulnerability scanning using Qualys and other tools, ensuring effective execution of vulnerability management processes.
- Analyze, prioritize, and report vulnerabilities based on risk, exploitability, and business impact, providing actionable insights for remediation.
- Supervise cyber threat information channels, including CVE, CISA, NCSC, and vendor advisories, to proactively identify emerging vulnerabilities and exploits.
- Collaborate with IT and BAT partners to ensure remediation efforts are implemented, supervised, and completed in a timely and effective manner.
- Continuously discover, inventory, and maintain transparency of internal and external assets, including cloud resources, to provide comprehensive charge surface management.
- Supervise charge surface changes and proactively assess new exposures to identify and mitigate potential security risks.
- Generate actionable reports and dashboards for technical teams and leadership on vulnerability status and trends. Chip in to planning and selecting security tools and technologies to reduce risk.
What are we looking for?
- 5+ years of information security experience with hands-on expertise in vulnerability management, threat analysis, and handling overall security posture.
- Deep experience with security platforms including Qualys, Tenable, Rapid7, Microsoft E5 Security Stack (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Exposure Management), and cloud environments (Azure and AWS).
- Demonstrates understanding of threat intelligence sources such as CVEs, CISA advisories, and vendor bulletins, with the ability to drive effective remediation strategies.
- Demonstrable ability to translate technical vulnerabilities and security findings into business-relevant risk assessments and remediation priorities.
- Good communication, teamwork, project management, and multi-functional partner engagement skills to drive security initiatives.
- Bachelor’s degree or equivalent professional experience, with familiarity in SIEM platforms (Microsoft Sentinel, Splunk), threat modeling (MITRE ATT&CK), and compliance frameworks (ISO 27001, NIST, GDPR).
- Hands-on scripting and automation experience using PowerShell and Python to improve security operations and processes related to vulnerability oversight.
- Relevant security and cloud certifications preferred, including CISSP, CISM, GMON, Microsoft Certified, AWS Certified Security, Azure Security Engineer Associate, and CompTIA Security+.
What we offer you?
- We offer a market leading annual performance bonus (subject to eligibility)
- Our range of benefits varies by country and includes diverse health plans, initiatives for work-life balance, transportation support, and a flexible holiday plan with additional incentives
- Your journey with us isn't limited by boundaries; it's propelled by your aspirations. Join us at BAT and become a part of an environment that thrives on internal advancement, where your career progression isn't just a statement – it's a reality we're eager to build together. Seize the opportunity and own your development; your next chapter starts here.
- You'll have access to online learning platforms and personalized growth programs to nurture your leadership skills
- We prioritise continuous improvement within a transformative environment, preparing for ongoing changes
WHY JOIN BAT?
We’re one of the few companies named as a Global Top Employer by the Top Employers Institute – certified in offering excellent employee conditions.
Collaboration, inclusion and partnership underpin everything we do here at BAT. We are looking forward to enabling every individual to thrive, regardless of gender, sexual orientation, marital or civil partnership status, gender reassignment, race, religion or belief, colour, nationality, ethnic or national origin, disability, age, skills, experience, education, socio-economic and professional background, veteran status, perspectives and thinking styles. We know that embracing talent from all backgrounds is what makes us stronger and best prepared to meet our business goals.
We see the career breaks as opportunities not obstacles. Through The Global Returners program, we support professionals looking to restart their careers after an extended absence from the workforce (e.g. time out caring for family, parental leave, national service, sabbatical and/or starting an own venture).
Come bring your difference and see what is possible for you at BAT. Learn more about our culture and our award winning employee experience here.
If you require any reasonable adjustments or accommodations to help you perform at your best during the recruitment process, you are encouraged to notify us. We are fully committed to support you by making appropriate arrangements for you to demonstrate your full potential.