Job Description
This role reports to the Chief Information Security Officer within Engineering. He/she will be responsible for ensuring compliance with the set cybersecurity policies and procedures, and assist in the assessment and identification of cybersecurity risks, and the development of appropriate mitigation plans to address the identified risks. In addition, the role ensures appropriate monitoring and response to security events, potential vulnerabilities, exposures, and policy compliance and audit issues.
Responsibilities
Will include and are not limited to:
- Review security alerts and ensure they are investigated and addressed within defined timelines
- Track closure of vulnerabilities with internal teams and partners to ensure remediation within the stipulated timelines as per the process
- Use available security tools to conduct internal assessments and assess internal and external cyber risk profile in order to prevent, detect and respond to threats and suspicious activities
- Drive end user machine compliance with IT support and end users to ensure security software compliance targets are met across office, shops and call centers
- Conduct regular reviews of internal controls to ensure compliance with established policies and applicable regulations
- Assist in the development and delivery of training and awareness activities for employees
- Assist in deployment of new security technology within the Opco and other related security projects
- Assist in evidence collation for risk assessments and audits
- Stay abreast with cyber security news and trends to incorporate learnings in day to day security operations
Qualifications
- Undergraduate degree in Computer Science, IT or related field
- At least 3 years’ experience in IT, Information security, Audit or Risk management
- Technical knowledge such as IT support and networking, Cyber/Information security tasks and tooling
- Professional or industry certifications in information/cyber security e.g. CISM, CISSP, CEH, etc. an added advantage
- Knowledge and use of security tools (Identity and Access Management, Privileged Access Management, Active Directory management, Security Incident and Event Monitoring, Vulnerability Management) an added advantage
- Strong analytical and problem-solving skills with a willingness to learn
- Excellent interpersonal skills for stakeholder management and building collaborative relationships
- Excellent and effective communication skills with ability to engage employees at all levels
- Team player and able to handle and prioritize multiple projects simultaneously
- High personal standards and results oriented
