|
Primary Responsibilities:
-
Perform audits to identify control gaps and implement
corrective action plans
-
Ensure alignment of security policies/standards with IT
infrastructure frameworks (e.g., ISO 2700x, NIST, ITIL)
-
Monitor compliance with corrective action plans, and address
non-compliance issues appropriately
-
Demonstrate understanding of discovery technologies to
identify system vulnerabilities (e.g. scanning tools)
-
Establish appropriate security controls based on defined data
classifications to align with applicable
laws/regulations/standards
-
Facilitate/lead security incident investigation
-
Analyse business requirements and ensure that solutions meet
established security policies and controls
-
Maintain metrics and report them.
-
Maintain current knowledge on information security topics and
their applicability program requirements
-
Communicate professionally with stakeholders/end users through
multiple communication
|
-
Bachelor's degree or higher level of education
-
6+ years of Information security experience
-
Experience with ISO27001 (ISMS), ISO31000 (Risk management),
HITRUST CSF, NIST Cybersecurity Framework, SOC Type1/2
-
Proven auditing skills and the ability to manage risk
assessments / projects independently
-
Proven excellent communication skills both verbal and written
-
Proven good presentation skills particularly ability to
present technology elements in manner personnel can follow and
act
Preferred Qualification:
-
CISSP, CISA or ISO27001 Lead Implementer or Lead Auditor
certification
-
Knowledge of world class protections against current and
future cyber threats in order to keep company information
secure (Risk Based Authentication, DLP, FW, IPS, Encryption,
Proxies, Sandboxing, Full Packet Forensics, Fraud Solutions,
PKI, big data security, etc.)
|