- Design and manage security KPIs.
- Manage security SLAs and publish risk-based dashboards.
- Design and implement vulnerability management program, manage VA and PT activities.
- Design and implement network, server and cloud security programs – on boarding, pre and post scanning.
- Periodic configuration reviews based on CIS benchmarks.
- Manage the application security program – oversee the risks and work with business application teams to mitigate risks.
- Co-manage the end point security, network security and server security program.
- Co-manage the security operations management program.
- Minimum 5 - 7 years of proven work or professional experience in security engineering.
- Prior working knowledge of web, mobile and cloud security.
- Hands on experience in building and maintaining security such as firewalls, intrusion detection, zero trust, authentication, etc.
- Good understanding of the concepts of IT infrastructure at all layers like Servers, Networks, End User Computing and Cloud.
- Risk based information security program design and implementation experience.
- Hands-on experience in implementation of standards like ISO 27001, NIST, CIS or similar.
- Hands-on experience in designing, implementing and managing DevSecOps.
- Hands on experience in security scans & threat intelligence.
- Hands on experience in conducting application security assessments – manual and tool based.
- Should have a good understating of OWASP, CIS and NIST guidelines for application security
- Should have hands on experience in designing security programs for cloud services including IAAS, PAAS and SAAS.
- Should have hands-on experience in native cloud security capabilities.
- Should have experience in implementing cloud security solutions like CASB.
- Good communication and presentation skills.
- Have experience in working with mid-level and senior level management and ability to understand business processes and requirements.
- Understanding and communicating security risks with core technology teams and business functions.
- Preferred to have CISSP, CCSP, CISM, and ISO 270001 LI/ LA Certifications.
Silakan referensi bahwa Anda menemukan lowongan kerja ini
di Fungsi.id, ini membantu kami mendapatkan lebih banyak
lowongan kerja berkualitas di sini, terima kasih!