The Job
- Execute enterprise-wide cybersecurity programs for both IT and OT.
- Enhancing, reviewing and formulating of Information Security related procedures.
- Work with Security Operations Center to verify and close SOC alerts, including blocking of blacklisted IP and investigate anomalous activities.
- Lead and perform POC/testings of Cybersecurity IT/OT products and services.
- Lead and organize vulnerability assessment and penetration testing with both internal and external teams and follow up with remediations and closures.
- Lead the team to administer various security systems such as EDR, WAF, vulnerability scanner, IPS, Privileged Access Management, secure internet access platform, including onboarding of new systems and accounts.
- Participate in cybersecurity drills and exercises.
- Attend to threat intel notifications and regulators' requests and lead the team to fulfil the recommendations.
- Lead cybersecurity team in Incident Response.
- Provide cybersecurity guidance such as Security by Design to project teams.
- Any other Cybersecurity & Compliance related functions that may be assigned.
The Requirements
- Minimum 6 years of related working experience in Information Security & compliance.
- Possess Security related certifications such as CISA, OSCP, CEH, CISM, CISSP would be an advantage.
- Good understanding on Security Architectures.
- Good understanding in OT Security.
- Experienced in Secure-by-Design Principal and secure coding.
- Hands-on experience in networking, system administration, application project development.
- Willingness to hands-on as part of mentoring the team to meet its objective in a collective manner.
- Highly resourceful individual who possess strong analytical skills.
- Well verse in security related products such as firewall, Intrusion Protection System, etc.
- Well verse in Security Standards such ISO27001, IEC62443, NIST & CyberSecurity Act. etc.
- Well verse in MITRE ATT&CK framework.
- Good understanding of various regulation/laws related to cybersecurity.
- Able to explain technical ideas to non-technical audience such as Senior Management and other Internal Stakeholders.