Company:
Sopra Steria is a listed European tech leader specializes in Consulting, Digital Service, and Software. We have 50,000 employees worldwide located in different regions (Europe, North America and Asia), whereby Singapore is the HQ for APAC. EvaGroup Asia Pacific is part of Sopra Steria, in charge of Infrastructure, Cloud and Cybersecurity services in APAC.
Responsibilities:
- Develop and review security design(s) for the project in scope: Security and risk management controls, ICT/Cloud resouces and services, related policies and standards, cybersecurity best practices, and business requirements/needs.
- Technical architecture diagrams depicting the deployment of security controls in existing network
- Conduct initial risk assessments to evaluate security risks and vulnerabilities
- Recommend mitigation/correction actions, security controls and process to implement
- Submit a Security Design Document detailing the security controls to secure the system
- Identify logical architectural elements such as the logical flow of control,
and the relationship between the elements (e.g., the trust boundary between
various services and components deployed at cloud services); - Identify physical or virtual architectural elements to build the architecture (e.g., security mechanism such as Firewall, access control, authentication);
- Select security services such as hardware-related, Software-related, cloudrelated (e.g., Native cloud service, security mechanisms available for authentication, token management, authorization, encryption methods
(hash, symmetric, asymmetric), encryption algorithms and security event logging); - Create an architecture design which allows all elements to be integrated to fufil needs and requirements
- Report to relevant stakeholders on the SBD activity
- Provide insights about regular findings
Competencies:
- Good working knowledge of security risk management, security governance framework and compliance (IT Security Audit / log review), technical vulnerability management (Vulnerability Assessment, Penetration testing), application security, security technologies (system hardening, IDS/IPS, firewall), security incident response and security assessment.
- Proficiency in written and spoken English is a must
- Autonomous, with the ability to drive and lead
- Excellent writing and communication skills to negotiate and provide solutions
- Proven stakeholder and inter-personal management skills
Qualifications:
- Bachelor’s degree or master degree in Information Security System, Computer Science, or relevant IT experience
- Preferably with minimum 8 years' experience in cyber security role, with relevant experience in Security by Design, Audits, Security Assessment and/or Compliance
- Possess one of more professional credentials: CISSP, CRISC, CISM, CISA, SSCP, CEH, ISO 27001 or equivalent