IT Security Officer
Summary
The IT Security Officer manages security vendors, testing, and incident response while providing cybersecurity consultancy. Key technologies include SIEM platforms, vulnerability scanners, cloud environments (AWS, Azure, GCP), and scripting with Python or PowerShell.
Key Responsibilities:
- Manage security vendors and deliverables.
- Manage periodic security testing.
- Assess mitigation/remediation for adequacy and effectiveness.
- Manage timely and effective mitigation/remediation.
- Review security reports.
- Review security policies, standards, procedures and guidelines.
- Provide cybersecurity consultancy.
- Respond to security alerts/advisories.
- Handle incidents.
- Conduct security awareness training.
- Broadcast email security advisories.
Job Requirement:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 4–7 years of experience in cybersecurity analyst or similar role.
- Strong understanding of network protocols, operating systems (Windows, Linux), and cloud security concepts (AWS, Azure, GCP).
- Proficiency with security tools such as vulnerability scanners, penetration testing tools, and SIEM platforms.
- Experience with scripting languages (e.g., Python, PowerShell) for automation.
- Familiarity with cybersecurity frameworks and standards (e.g., NIST, ISO 27001).
- Excellent analytical and problem-solving skills with a strong attention to detail.
- Ability to work independently and as part of a team in a fast-paced environment.
- Strong written and verbal communication skills, with the ability to articulate technical information to non-technical audiences.
- Proven ability to manage multiple tasks and prioritize effectively.
- Require CISSP and/or CISM certification.
What Are We Looking For:
- Enthusiasm for learning and development of skills in cybersecurity.
- Strong analytical capability.
- Understanding of the vulnerabilities listed in the Open Web Application Security Project (OWASP) Top 10.
- Understanding of incident management and handling.
- Experience in software development or security operations is preferred.
The following certifications are advantageous but not mandatory:
- GIAC Certified Incident Handler (GCIH)
- CompTIA Security+
- CompTIA CySA+
- EC-Council Certified Security Analyst (ECSA)
- EC-Council Certified Ethical Hacker (CEH)
- (ISC)2 Systems Security Certified Practitioner (SSCP)
- Offensive Security Certified Professional (OSCP)