IT Security Analyst
JOB OVERVIEW:
To support IT security function at Ocean Network Express with the goal of information Confidentiality, Availability and Integrity.
DUTIES AND RESPONSIBILITIES:
Compliance:
Review Security Policy annually and propose changes where necessary.
Raise the level of security awareness amongst employees by scheduling training courses and tabulating their results. Subscribe to cyber security news and informing the relevant parties of known vulnerabilities.
Coordinate internal, external, customer, and certification audits, including gathering the evidence, liaising with the auditors, validating the audit findings, preparing the response, and monitoring the remediation efforts.
Understand global security and privacy legislation and its impact on compliance measures to be implemented
Operations:
Management of security tools such as anti-malware, web proxy, Security Information and Event Management (SIEM), Privilege Access Manager (PAM).
Management and liaison with our Security Operations Centre.
Respond to suspicious emails reported by users.
Conduct and coordinate Vulnerability Assessment and Penetration Testing (VAPT) with stakeholders
Conduct security assessment of systems and software to determine if controls are sufficient, and if not, recommend additional controls to be implemented.
Respond to incidents including investigation, containment, and recovery of procedures. Documenting incident reports and lessons learnt following the closure of the incident.
Application Development:
Understand application development security and implement measures to support the secure software development framework.
Projects:
Manage security projects to enhance the security posture of the organization.
QUALIFICATIONS AND EXPERIENCES:
Good understanding of information security principles and IT infrastructure including operating systems, applications, communications and network protocols.
Strong analytical mind and problem solving skills.
Ability to assess security threats and vulnerabilities against the potential impact.
Bachelor’s degree in an IT-related discipline.
Preference will be given to candidates with relevant professional certifications such as CISSP, CISM, Security+ etc.
1 to 5 years in an IT Security related role, with experience in implementation and administration of security tools.
Able to work independently with minimal supervision, and able to work well in teams.
Possess initiative and be self-motivated, with a thirst for knowledge and a willingness to learn.
Enthusiasm towards emerging technologies and how these can impact the organization.
Be sympathetic towards constraints and ability to negotiate a compromise.
Ability to communicate and convince stakeholders from various levels and backgrounds.