Roles & Responsibilities
- Execute annual ITGC related to Info security and Network tasks with evident and documentation
- Follow up and ensure closure of incident event, and vulnerability/Penetration Test result remediation.
- Monitor security logs (such as firewall, Intrusion Prevention (IPS), Anti-Virus (AV), Email Gateway and Web Proxy) for security breaches and investigate a violation when one occurs
- Monitor identity and access management using Privilege Access Management (PAM) – CyberArk, BeyondTrust
- Administer and configure security devices such as Palo Alto, FortiGate, TippingPoint, TrendMicro Security Systems, Symantec & McAfee
- Investigate security alerts and provide incident response
- Analyze security breaches to identify the root cause
- Conduct security assessments through Tenable vulnerability scan and risk analysis
- Perform Infrastructure internal security audits
- Perform IT Security review, establish and maintain policies/procedures (e.g. Server, Network, Software, Access Privilege, Folder Access, GPO policy)
- Conduct penetration testing, which is when analysts simulate attacks to look for vulnerabilities in their systems before they can be exploited
- Analyze IT requirements and liaise with stakeholders in relation to cyber security issues and provide future recommendations
- Research the latest information technology (IT) security trends
- Prepare reports that document security breaches and the extent of the damage caused by the breaches
- Recommend enhancements to organization's current security infrastructure
- Keep up to date with the latest security and technology developments
- Generate reports for both technical and non-technical staff and stakeholders
- Maintain an information security risk register and assist with internal and external audits relating to information security
- Assist with the creation, maintenance and delivery of cyber security awareness training for colleagues
Qualifications
- Diploma or degree on Information Systems or other IT/security/network-related degrees
- 5+ years of experience in information security
- A passion for cyber security and a keen interest in IT
- Experienced with penetration testing and techniques
- Ability to identify and mitigate network vulnerabilities
- Understand patch management
- A good working knowledge of various security technologies such as network and application firewalls, host intrusion prevention and anti-virus
- Experience with vulnerability scanning tools (eg. Tenable etc)
- Experience in issues management (compilation, follow-up, closure) and reporting
- Experienced in installing security software and documenting security issues
- Excellent IT skills, including knowledge of computer networks, operating systems, software, hardware and security
- Analytical and problem-solving skills to identify and assess risks, threats, patterns and trends
|
|