Information Secuirty Specialist

Open 20d

The Information Security Specialist is responsible for safeguarding the organization’s systems, data, and technology infrastructure by implementing and maintaining effective security controls and monitoring activities. This role supports the organization’s security and compliance objectives by identifying risks, responding to security incidents, and ensuring alignment with regulatory and industry standards.

• Monitor and respond to security incidents and alerts, supporting investigation, escalation, and resolution. • Maintain and implement security controls to protect systems, applications, and data against internal and external threats. • Perform security monitoring using SIEM and other security tools, analysing logs and events to identify potential threats and recommend remediation. • Support vulnerability management activities, including identifying, prioritising, and tracking remediation of security weaknesses. • Conduct security risk assessments and support internal and external security audits. • Ensure compliance with security standards and regulatory requirements, including PCI-DSS. • Implement and maintain Web Application Firewalls (WAF), DDoS protection, firewall technologies, and cloud-native security controls (e.g. Cloudflare, Akamai, Azure/AWS security services where applicable). • Support application security throughout the software development lifecycle, including static application security testing (SAST) using tools such as Veracode, Checkmarx, Trivy or similar. • Assist with container and cloud workload security, including Docker, Kubernetes and container image scanning. • Perform or support penetration testing, vulnerability assessments and security validation activities using industry-standard tools (e.g. Kali Linux, Burp Suite, OWASP methodologies). • Develop and maintain automation scripts using Python, PowerShell or Bash to improve security operations and monitoring. • Collaborate closely with Engineering, Infrastructure, DevOps and Compliance teams to embed security into development and operational processes. • Maintain security documentation, operational procedures and technical standards to support audit readiness and operational consistency.