- Prepare and maintain IT security policies, guidelines, SOP and action plans for review at least once a year.
- Evaluate, review and ensure SOP’s and other documents are relevant and up-to-update.
- Implement and follow the risk management methodology and comply with Service Management Requirement
- Develop and implement security management frameworks and governance.
- Handle IT Security Incident Management and manage IT security incidents until closure.
- Work with 3rd party suppliers to resolve IT security incidents
- Analyze and update on the latest security problems, risks and solutions
- Prepare and present the stake holders with reports and security score cards at the intervals defined by the stake holders
- Liaise and co-ordinate meetings on IT security matters 3rd party vendors, suppliers and security organisations
- Maintain and Manage Risk register
- Experience in performing User Account reviews for multiple technology stacks
- Tracking and managing the Asset Inventory and EOL/EOS of active softwares in the infra
- Experience in performing Risk Assessment
- Experience in performing GAP analysis
- Perform Security Awareness training to multiple stake holders
- Create and maintain the security baseline for multiple technologies
- Perform multiple reviews like account review, log review, rules review etc
- Perform activity review using system logs, database logs etc
- Generate VA report on weekly basis and follow-up to ensure closure of identified vulnerabilities within the SLA
- Manage all reported security incidents with the respective teams and ensure closure within the SLA
- Perform other activities necessary to secure the infrastructure
- Initiate, drive and ensure successful completion of internal and external audits
- Good understanding of Security Tools like SIEM, VAPT, Log Analysis and WAF
- Participate and assist in IT security incident response table-top exercises and technical assessment exercises
- Understanding of events from Splunk, Windows and Linux systems like RHEL, Solaris etc is preferred
- Experience in managing Antivirus, antimalware and other EDR solutions is a plus