Specialist – Secure by Design ( Internal/External)
NewBe an early applicantole purpose:
The Secure by Design Specialist is responsible for protecting customer privacy by providing the best-in-class technical security and consultancy to Safaricom Ethiopia across a wide range of IT, network & telecoms solutions. The candidate will assist in identifying potential cyber security risks for new products, services, and operations and identify controls to minimize, mitigate or remove those privacy and security risks.
Key accountabilities and decision ownership:
Conduct security reviews, vulnerability assessments & penetration tests across all of Safaricom’s systems/infrastructure.
Ensure all new and existing systems/products/services comply with the Company’s security policies & standards and other industry best practices e.g. ISO27001, CIS and Ethiopia Data Protection Laws.
Review Design and implementation of the identified controls to ensure they are built into the product (at the Design & Build stages).
Provide timely and quality security assurance reports and advice to the business when required even with very tight deadlines
Do regular follow-ups with system custodians/owners to ensure any security risks identified are addressed within the agreed timelines
Define Cyber Security metrics and report periodically on security compliance across all networks/systems
Research on new threats/technologies/vulnerabilities/security design principles etc..
Working knowledge of Virtualization & Microservices technologies e.g. VMware, Open shift, Kubernetes, Docker etc will be an added advantage
Working knowledge and experience in DevSecOps technologies and practices i.e. Jenkins, Jira, Github, Gitlab etc will be an added advantage.
Core competencies, knowledge and experience:
Business Competencies:
Written and verbal communication
Technology Awareness
- Strategic Planning
- Leadership
Creativity and Innovation
Data Analysis
Business Know how
Business Continuity
- Risk Management
Telecommunications
Project and Programme Management
Client Relationship Management
Collaboration
Functional Competencies:
Knowledge Vulnerability assessment tools.
Knowledge of end-to-end system security assurance process.
Knowledge of operating systems like Windows, Linux, and UNIX.
Expertise in ethical hacking tools, techniques and methodologies.
Cloud security
Network security
Software development and DevSecOps.
Scripting language
Web and Mobile Application Penetration testing.
Must have technical / professional qualifications:
Bsc Degree in Electrical Engineering, Computer Engineering, Software Engineering or Computer Science or closely related field of study
Desired
Professional security training and certifications like Security+, CEH, Pentest+, CCIE, and CISSP
How to Apply
- If you feel that you are up to the challenge and possess the necessary qualification and experience, kindly proceed to create/ update your candidate profile on the recruitment portal and then Click on the apply button. Remember to attach your resume