New York
Job DescriptionJob Description Cybersecurity Consultant About EXL EXL (NASDAQ:EXLS) is a leading operations management and analytics company that helps businesses enhance growth and profitability in the face of relentless competition and continuous disruption. Using our proprietary, award-winning Business EXLerator Framework, which integrates analytics, automation, benchmarking, BPO, consulting, industry best practices and technology platforms, we look deeper to help companies improve global operations, enhance data-driven insights, increase customer satisfaction, and manage risk and compliance. EXL serves the insurance, healthcare, banking and financial services, utilities, travel, transportation and logistics industries. Headquartered in New York, New York, EXL has more than 24,000 professionals in locations throughout the United States, Europe, Asia (primarily India and Philippines), Latin America, Australia and South Africa. EXL Analytics provides data-driven, action-oriented solutions to business problems through statistical data mining, cutting edge analytics techniques and a consultative approach. Leveraging proprietary methodology and best-of-breed technology, EXL Analytics takes an industry-specific approach to transform our clients decision making and embed analytics more deeply into their business processes. Our global footprint of nearly 2,000 data scientists and analysts assist client organizations with complex risk minimization methods, advanced marketing, pricing and CRM strategies, internal cost analysis, and cost and resource optimization within the organization. EXL Analytics serves the insurance, healthcare, banking, capital markets, utilities, retail and e-commerce, travel, transportation and logistics industries. Please visit www.exlservice.com for more information about EXL Analytics. Role Responsibilities: • Implement cybersecurity remediation activities across defined workstreams and sprint plans., • Configure and maintain identity and access controls including MFA, SSO, role-based access, least privilege, privileged accounts, service accounts, and periodic access reviews., • Support implementation of privileged access controls using tools such as Windows LAPS, PIM, managed identities, key vaults, or equivalent native security capabilities., • Execute vulnerability management activities including vulnerability scanning, findings validation, remediation tracking, and risk-based prioritization., • Implement and support patch management processes, including patch testing, deployment coordination, SLA tracking, and exception handling., • Configure centralized logging and monitoring integrations into SIEM platforms such as Microsoft Sentinel or equivalent tools., • Ensure critical infrastructure, applications, network devices, firewalls, SaaS platforms, and security tools generate usable logs for SOC monitoring., • Support SOC alert triage, incident investigation, escalation, evidence collection, and incident response playbook execution., • Maintain and update incident response plans, technical runbooks, communication workflows, and tabletop exercise evidence., • Implement backup and recovery controls, including immutable backups, scheduled backup validation, restoration testing, and recovery evidence documentation., • Build and maintain technical asset inventories, data inventories, network architecture diagrams, and mappings to critical business processes., • Support network security improvements including firewall rule review, network access controls, network segmentation, IDS/IPS logging, and secure remote access., • Implement data protection controls such as encryption, data labeling, retention enforcement, DLP policies, and secure data handling controls., • Support secure development controls including secure code repositories, SDLC documentation, coding/testing standards, peer review processes, and separation of duties between development and deployment., • Coordinate with MSPs and internal IT teams for hands-on execution of patching, backup, monitoring, and endpoint security activities., • Produce control evidence, implementation documentation, dashboards, and remediation status updates for governance and audit purposes., • Support OT/ICS security implementation, including passive monitoring setup, asset-boundary validation, OT evidence packs, and coordination with OM/GOP providers where applicable., • Build and run passive OT monitoring pilots using tools such as Zeek, Suricata, Malcolm, or similar platforms where required., • Track assigned activities through sprint plans, maintain implementation notes, and report progress against defined success measures. Candidate Profile:, • Bachelors degree in Computer Science, IT, Cybersecurity, Engineering, or a related field., • 48 years of hands-on experience in cybersecurity engineering, IT infrastructure security, security operations, or security control implementation., • Practical experience implementing identity and access controls, including MFA, SSO, RBAC, least privilege, privileged access, service accounts, and access reviews., • Hands-on exposure to Microsoft security tools such as Entra ID/Azure AD, Intune, Defender, Sentinel, PIM, Key Vault, LAPS, or equivalent platforms., • Experience configuring SIEM/logging integrations, validating log ingestion, supporting SOC monitoring, and assisting with alert triage or incident investigation., • Good understanding of vulnerability scanning, patch management, remediation tracking, exception handling, and evidence collection., • Experience supporting backup validation, restoration testing, disaster recovery documentation, and incident response playbook execution., • Familiarity with network security concepts such as firewall logs, IDS/IPS, network segmentation, secure remote access, and endpoint protection., • Ability to translate cybersecurity control requirements into implementation steps, technical runbooks, evidence packs, and closure documentation., • Exposure to OT/ICS, SCADA, passive monitoring tools such as Zeek, Suricata, Malcolm, or regulated environments would be preferred. What we offer: EXL Analytics offers an exciting, fast paced and innovative environment, which brings together a group of sharp and entrepreneurial professionals who are eager to influence business decisions. From your very first day, you get an opportunity to work closely with highly experienced, world class analytics consultants. You can expect to learn many aspects of businesses that our clients engage in. You will also learn effective teamwork and time-management skills - key aspects for personal and professional growth. Analytics requires different skill sets at different levels within the organization. At EXL Analytics, we invest heavily in training you in all aspects of analytics as well as in leading analytical tools and techniques. We provide guidance/ coaching to every employee through our mentoring program wherein every junior level employee is assigned a senior level professional as advisors. Sky is the limit for our team members. The unique experiences gathered at EXL Analytics sets the stage for further growth and development in our company and beyond.