Job Description:
•Support and maintain security tools including Endpoint Security, SIEM, IPS/IDS, Email Security, NGFW, DLP, Security Assessment.
•Administration of information security systems and devices, review audit logs and security alerts.
• Perform activities related to IT security, including installation, configuration changes, and updates/patches.
• To investigate, resolve or mitigate security incidents in a timely manner.
• To conduct internal vulnerability assessments and remediate identified vulnerabilities.
• To work with external vendor for penetration testing and remediate findings.
• To work with external MDR/SOC providers to detect and follow up on cyber security incidents.
• To work closely with DevOps and Developers to assess, identify and mitigate security vulnerabilities, and integrate security best practices into the software development lifecycle.
• Generation of metrics, reports, relevant information to support compliance status.
• Point of contact for ISO27001, liaise with auditors, perform self-assessment to ensure compliance with company policy and regulatory requirements.
• Develop and maintain information security awareness program.
• Maintain documentation of security system configurations, procedures, and troubleshooting steps.
Job Specifications :
• Diploma or Bachelor's degree in Computer Science, Information Technology, Cybersecurity or a related field (or equivalent work experience).
• Relevant experience with security related solutions (Endpoint Security, VPN, Firewall, etc.) and handling of cyber security incidents and associated incident response tools.
• Strong knowledge of operating systems (e.g., Windows, Linux), network protocols, and server hardware.
• Understanding of security principles and best practices, including patch management and vulnerability assessment.
• Strong knowledge of malware families and network attack vectors.
• Good understanding of TCP/IP and internetworking technology including packet analysis, routing, and network security defenses.
• Minimum 2 years of related experience in cyber security or computer network defense role
• Strong understanding of MITRE ATT&CK Framework, NIST Cybersecurity Framework (CSF) and Kill Chain Methodology
• Relevant security-related certifications like CISSP, GCIH, GCIA, GCED, GCFA, CySA+ is a plus
• Good communication skills, with the ability to collaborate effectively with technical stakeholders.
• Strong attention to detail.