Senior/IT Security Analyst (St Andrew's Community Hospital)
Job Summary:
Reporting to the Senior Manager, IT Infrastructure & Security, this role is part of a team of security practitioner who is responsible for organization-wide IT Security across all digital footprint.
The role of the security team covers development and maintenance of Policies and Procedures, monitoring of external threats and technologies, internal security health checks against compliance and controls, strengthening the Organization’s security posture, security framework for security and risks assessment for new and enhanced systems, etc.
Depending on experience, suitable candidates would be pegged to the appropriate job grade.
Job Scope:
Develop and maintain IT Security policies & procedures, including incident response plan.
Develop and maintain IT Security framework for security and risks assessment for new infrastructure/systems, enhancements, 3rd party integrations, as well as protection of sensitive data/information to cover the digital footprint like Digital Assets, Physical Devices, and Networks & Users.
Monitor and be updated on the latest security threats, trends, & technologies, and make recommendations based on the relevance to the Organization.
Plan and oversee security monitoring, vulnerability scanning, penetration testing, security assessment, remediation, and closure of findings.
Manage incident/violation response, escalations, recovery, root-cause analysis, rectification, and documentation.
Review and maintain security controls and risks mitigation solutions through collaboration with other IT teams, management of security vendors, and service performance.
Level up Organization’s IT Security readiness through security awareness activities, phishing simulations, and planning & conduct of regular security tabletop exercises.
Coordinate security audits, compliance checks, and follow-ups for gap closure.
Keep management appraised of the IT Security posture (overall readiness, strength, and ability to prevent, detect, and recover from Cyberthreats) of the Organization.
Perform other relevant IT Security duties consistent with the job role.
Requirements:
Recognized Degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent from a reputable university.
Equivalent professional experience may be considered. Relevant certifications such as CISSP, CISM, CCSP, Microsoft Security, AWS Security or CCNA/CCNP Security would be advantageous.
Experience in information security, cybersecurity operations or infrastructure security.
Experience developing security policies, incident-response plans and risk-assessment frameworks.
Experience in managing security monitoring, vulnerability assessments, incidents and remediation.
Experience coordinating audits, vendors, compliance reviews and management reporting.
Strong knowledge of security governance, risk assessment, incident response and data protection.
Able to assess systems and recommend proportionate security controls.
Strong analytical skills with ability to prioritise risks and close findings.
Strong communication, stakeholder-management and security-awareness facilitation skills.