Lead Information Security Specialist
9 months ago
Make an Impact by
Organizes, conducts and performs Cybersecurity risk assessment and gap analysis process.
Establishes, reviews and verifies the ..
Make an Impact by
- Organizes, conducts and performs Cybersecurity risk assessment and gap analysis process.
- Establishes, reviews and verifies the Cybersecurity reviews conducted on Systems
- Performing Threat Modeling on new or existing Systems, identify threats/vulnerabilities and recommend mitigation strategies.
- Designing processes to identify, improve and optimize Cybersecurity risk management practices
- Communicates and assist Business Units to address identified cybersecurity risks to meet business local objectives.
- Monitors compliance with the Cybersecurity Standards, Policy and Architecture.
- Conduct Cybersecurity risk management awareness program to drive risk management best practices/culture into the Business Units and Program Managers.
- Prepares and/or coordinates Monthly/Quarterly Cybersecurity related Risk Meeting.
- Providing security advisory and recommend resolutions for security threat and vulnerabilities
- Maintain cybersecurity risk register and presenting it to the security risk deviation committee
- Performs all other Cybersecurity duties as assigned by the Management.
Skills for Success
- Bachelor’s Degree in computer science, Computer Engineering, Electrical Engineering or other relevant field of study
- At least 8 years of information security experience with at Least 4 years in security risk assessment
- Good understanding in the following areas: Platform Security, Data Security, Network Security, Physical Security, Security Assessment Tools, Security Monitoring Tools.
- Experienced in performing technical assessment and analysis on emerging technologies such as AI, Cloud and 5G and the evolving threat landscape
- Strong understanding of threat modeling and risk management principles and best practices, and able to explain it in a structured and easy-to-understand manner.
- Strong understanding of information security framework and practices such as ISO27001, PCI-DSS and OWASP.
- Strong analytical and problem-solving skills.
- Ability to multi-task and work as a team in a complex work environment, with minimal supervision
- Be able to communicate effectively with business user and project team
- Possess good working attitude and self-motivated to learn
Official account of Jobstore.