Security Architecture Design:
- Develop and implement comprehensive security architectures for our systems and networks;
- Design security solutions that align with industry best practices and compliance standards;
- Collaborate with cross-functional teams to integrate security measures into the overall system architecture;
- Review security requirements and assess the security posture to identify gaps or improvements;
Risk Assessment:
- Conduct regular security risk assessments to identify vulnerabilities and potential threats;
- Analyse and evaluate existing security systems to ensure they meet the organization's requirements;
Incident Response:
- Develop and maintain incident response plans to address security incidents promptly;
- Work closely with the incident response team to investigate and resolve security incidents;
Cloud Security:
- Design and implement security measures for cloud-based infrastructure and services;
- Evaluate and recommend new tools and methodologies to enhance cloud security posture;
- Work closely with cross-functional teams, including cloud architects, developers, and operations, to integrate security measures seamlessly into cloud solutions;
- Provide guidance and support to ensure security is embedded throughout the cloud development life cycle;
Subject Matter Expert:
- Participate in designated projects and business initiatives as the security subject matter expert;
- Perform R&D in the field of IT security, including the IT security trending topics, including cloud security and IoT.
Requirements:
- Possess at least a Degree in Computer Science or Engineering;
- Have experience in the following areas:
- Identity and Access Management
- Application Security, cryptography, and protocols
- Secure System Development Life Cycle
- Security Incident Management and monitoring
- Vulnerability Management and penetration testing;
- Information Security Management, Risk Management, and Asset Security
- Computer, IT Security, Network Security, and Cloud Security
- Knowledge and experience in identifying and understanding common application security vulnerabilities,specifically the OWASP Top 10.
- Excellent interpersonal, communication, and presentation skills; capable of effectively communicating security risks to both technical and business audiences.