Develop, maintain, and publish information security policies, procedures, standards, and guidelines, ensuring compliance with best practices and regulatory requirements.
Oversee security incidents, handle alerts from GCSOC, GICS, and security devices, and assess reported phishing emails to mitigate risks.
Conduct regular security reviews including user account audits, access rights management, and vulnerability assessments on servers, networks, and web applications.
Manage patch management processes, ensuring timely application of security patches, and liaise with the operations team to meet deadlines.
Monitor and analyze security events using SIEM tools like Splunk and ArcSight, and evaluate the security posture of cloud service providers.
Serve as the primary contact for IT security-related matters, offering guidance and ensuring regular reporting on the security status to management.
Qualifications
Bachelor’s degree in computer science, Information Technology, or a related field.
Good experience in security practices, SIEM tools, network protocols, security incidents, etc.
Familiarity with ITIL processes and best practices.
Ability to work in a fast-paced, dynamic environment.
Availability to work outside regular business hours for maintenance and on-call support.