Key Accountabilities: |
Description |
Network Infrastructure & Connectivity Support Lead and oversee the secure design, implementation, operation, and continuous improvement of GDI’s network infrastructure to ensure availability, performance, resilience, and security across corporate and operational environments. Supervise network administration activities, including routers, switches, firewalls, VPN services, wireless networks, communication platforms, and related infrastructure technologies, to ensure compliance with approved security standards, operational requirements, and best practices. Ensure reliable and secure connectivity for users, systems, operational technologies, and external integrations through continuous monitoring, performance management, and proactive resolution of network-related issues. Enforce network security controls, including segmentation, access control, monitoring, logging, and secure communications, to protect organizational assets and support compliance with ISMS and regulatory requirements. Provide technical direction and oversight to Network Administration resources to ensure effective service delivery, compliance with service levels, and consistent implementation of operational and security procedures. Coordinate with internal stakeholders and external service providers to support communication systems, data center connectivity, VSAT services, internet services, and third-party connectivity requirements. Support incident response, business continuity, and disaster recovery activities by maintaining network resilience, availability, recoverability, and operational readiness. Ensure the security of Operational Technology (OT) and Industrial Automation and Control Systems (IACS) environments through network segmentation, secure remote access controls, monitoring activities, and implementation of applicable industrial cybersecurity requirements (including ISA/IEC 62443 standards).
|
Network Security & Access Control Lead and oversee the implementation, operation, and continuous improvement of network security controls and access management frameworks to protect GDI’s information assets, infrastructure, and operational environments. Define and enforce secure access requirements relating to authentication, authorization, network segmentation, privileged access, and remote connectivity in alignment with ISMS requirements, cybersecurity standards, and regulatory obligations. Oversee administration of identity and access controls across network and security environments and ensure adherence to the principles of least privilege and segregation of duties. Direct the configuration, management, and optimization of firewalls, VPNs, Network Access Control (NAC) solutions, intrusion detection and prevention technologies, and related security platforms in coordination with Network Administration resources. Monitor and review access rights, privileged accounts, network security events, and security logs to identify unauthorized activities and ensure compliance with approved security requirements. Coordinate periodic access reviews, access recertification activities, and remediation actions to maintain appropriate access governance and security compliance. Provide technical guidance on secure network architecture, access control design, and security requirements to support business needs while maintaining an effective security posture. Support incident investigations, forensic reviews, compliance assessments, and audit activities relating to network security and access management.
|
Incident Management & Operational Security Support Lead and govern the end-to-end incident management process for IT and security-related events, ensuring timely detection, response, resolution, and documentation in line with approved procedures and SLAs. Establish and maintain incident management processes, escalation procedures, communication protocols, and reporting mechanisms aligned with ISMS requirements and business continuity objectives. Oversee monitoring, triage, analysis, prioritization, and escalation of cybersecurity and operational incidents and coordinate response activities with internal teams and external service providers. Direct incident response and recovery activities, ensuring root cause analyses are completed and corrective actions are implemented to prevent recurrence and strengthen operational resilience. Provide technical leadership and guidance to IT support and Network Administration teams in resolving complex incidents and maintaining service availability. Ensure incident records, investigation findings, response activities, and closure documentation are accurately maintained to support audit, compliance, and performance monitoring requirements. Develop and maintain incident response playbooks, coordinate incident response exercises, and support disaster recovery and business continuity readiness activities.
|
Vulnerability Management Lead and govern GDI’s vulnerability management program to ensure timely identification, assessment, prioritization, remediation, and reporting of vulnerabilities across systems, networks, applications, cloud environments, and operational technologies. Oversee vulnerability scanning, assessment, reporting, and remediation activities and ensure identified vulnerabilities are appropriately risk-ranked, assigned, tracked, and resolved through approved remediation processes. Direct implementation of corrective actions, patch management activities, configuration hardening initiatives, and security improvement measures in coordination with Network Administration and other IT resources. Provide analysis, reporting, and recommendations regarding security risks, vulnerability trends, threat exposure, and remediation performance to management and relevant stakeholders. Support incident investigations, audit activities, compliance assessments, and security reviews through provision of vulnerability management data, remediation evidence, and security assurance information. Oversee vulnerability identification and remediation activities relating to OT and IACS environments in alignment with industrial cybersecurity requirements and operational risk considerations.
|
Compliance, Audit & Risk Management Ensure compliance with information security policies, standards, ISMS (ISO 27001) requirements, industrial cybersecurity requirements, and applicable regulatory obligations through effective implementation and monitoring of security controls and operational practices. Coordinate internal audits, external audits, cybersecurity assessments, certification activities, compliance reviews, and remediation programs to support audit readiness and ongoing compliance. Oversee identification, tracking, reporting, and remediation of audit findings, non-conformities, security observations, and control gaps and ensure corrective actions are completed within agreed timelines. Maintain security documentation, policies, procedures, access review records, vulnerability management records, incident documentation, and audit evidence required to support compliance and assurance activities. Conduct and coordinate security risk assessments, vulnerability risk assessments, and control reviews and ensure identified risks are appropriately documented and incorporated into relevant risk registers. Monitor implementation of risk treatment plans, mitigation activities, and corrective actions and provide reporting on residual risks, remediation progress, and risk exposure. Prepare and present security risk reports, compliance updates, assessment results, and cybersecurity insights to management and stakeholders to support informed decision-making. Conduct cybersecurity risk assessments relating to Operational Technology (OT) and Industrial Automation and Control Systems (IACS), considering operational impacts, safety implications, and applicable industrial cybersecurity requirements.
|