IT Networking & Security Engineer
Responsible for security system administration, security incident
management, vulnerability assessment and security testing. Maintain
corporate compliance with security policies and applicable standards.
Ensure IT application systems and infrastructure security.
Job Brief
Essential functions conducting proactive research to analyse security
weaknesses and recommend appropriate strategies. Providing security design
reviews of new and existing systems. Identifying current and emerging
technology issues including security trends, vulnerabilities and threats.
Responsibilities
Governance, Compliance, Audits
-
Support the development and implementation of security policies,
standards, guidelines and processes to ensure the ongoing maintenance of
physical and logical security.
-
Develop and maintain a security control framework to ensure that
security management systems and policies are effective, providing
recommendation and remediation.
-
Support and maintain the Information Security Management System (ISMS)
to assure continuous compliance with regulations, laws and contractual
obligations by adopting and deploying industry and market standards and
accepted best practices.
-
Conduct independent security audits, risk management assessments to
verify and provide recommendations to improve security posture.
-
Participate in the security operational risk management activities as
part of the Enterprise Risk Management to identify threats and institute
appropriate security programs.
-
Develop and maintain a standard security contract framework for ITO
outsourcing to ensure a harmonised and consistent security control
framework.
-
Maintain documentation of policies, processes within the organization.
Training
-
Develop and maintain a security awareness program to assure a widespread
culture of information security awareness.
Incident Management
-
Support and maintain IT Security systems including network security and
SIEM system.
-
Conduct IT security incident investigation and threat hunting on the IT
environment.
-
Develop and support emergency procedures and oversee incident responses
as well as the investigation of security breaches and assist with
disciplinary and legal matters associated with such breaches as
required.
Tools
Familiarity with configuration, management of any security platforms /
tools such as ColorTokens, Seceon, CrowdStrike, NetSkope, Aruba Clearpass,
Fortigate would be a plus.
Requirements
- Good documentation and communication skills.
-
Minimum 7 to 10 years of experience in a similar role, i.e. in a
combination role of security risk, information security and IT.
-
Degrees in relevant fields such as Computer Science, IT Security,
Business IT, or IT engineering would be an advantage.
-
Proven experience in analysis, identifying, monitoring and controlling
security risks.
-
Experience in managing Identity / Access management, Intrusion Detection
/ Prevention, Data Protection and Data Leakage Prevention applications /
devices including installation, configuration and its availability.
-
Extended knowledge of relevant international security standards (ISO/IEC
27000 - series), best practices (CobiT, ITIL), third party reporting
(ISAE3402, SOC).
-
Must have a minimum of one of the certifications from ISACA’s CSX, CISA,
CISM, CGEIT or CRISC or ISC2’s SSCP, CCSP, or CISSP or GIAC’s GISP or
GSE.
Job description written in accordance with company standard practices.