Senior IT Cyber Security Assurance And Risk Specialist

Job purpose

The purpose of the IT Cyber Security Assurance and Risk Specialist role is to continuously improve the protection of information systems by preventing unauthorized disclosure or modification. This involves coordinating with system owners and internal stakeholders to enhance Nawah's security posture.

Key activities, responsibility & accountability

  • Scope and perform penetration testing on systems, networks, and applications to identify vulnerabilities.
  • Utilize manual and automated testing methods to find and exploit code flaws, misconfigurations, and insecure software.
  • Use penetration testing tools and frameworks such as Metasploit, Nmap, Nessus, Burp Suite, Wireshark, Aircrack-ng, SQLmap, Tenable, John the Ripper, Hydra, OWASP ZAP, SOAP UI, Echo Mirage, etc.
  • Write clear and concise penetration testing reports detailing findings and recommendations.
  • Plan and provide technical trainings to junior team members for their professional development and growth.
  • Perform on-demand and scheduled security assessments on enterprise solutions.
  • Perform red team activities including but not limited to exploitation of identified vulnerabilities, breach attack simulations, phishing campaigns, and collaboration with the blue team to improve monitoring and defense measures.
  • Lead the vulnerability management program by performing scheduled and on-demand vulnerability assessments, vulnerability reporting, vulnerability prioritization, providing recommendations for remediation of identified vulnerabilities, and validating remediation of mitigated vulnerabilities.
  • Work on Endpoint Detection and Response tools for operations and investigations.
  • Perform secure architecture reviews for upcoming projects.
  • Conduct technical investigations of cybersecurity events and incidents, designing and recommending effective mitigations.
  • Stay updated on the latest security trends, threats, and technologies.
  • Provide technical guidance and support to IT teams on security-related matters.
  • Keep cybersecurity training and knowledge current by monitoring the latest security threats and vulnerabilities.
  • Develop and implement cloud security strategies and plans to protect cloud-based systems, networks, and data.
  • Work in collaboration with IT teams to ensure the security of all cloud systems.
  • Identify and mitigate potential threats and vulnerabilities within the cloud environment.
  • Ensure compliance with industry security standards and regulations for cloud environments.
  • Conduct security assessments through vulnerability testing and risk analysis specific to cloud infrastructure.
  • Monitor cloud environments for irregular activities and potential security breaches.
  • Provide technical support and guidance in relation to cloud security.
  • Stay updated on the latest cloud security trends, technologies, and best practices.
  • Conduct regular security audits to identify potential weaknesses in cloud infrastructure.
  • Support the audit teams during audits with required evidence.
  • Verify compliance to organization and regulatory requirements while onboarding new solutions within the organization.
  • Represent the Information Security Assurance Team in Enterprise Design Authority meetings and Enterprise Change Management Board meetings to ensure proposed changes and designs comply with organization and regulatory requirements.
  • Provide strategic recommendations to enhance the organization’s overall security posture.

Professional certifications

CEH, ECSA, OSCP, CISSP, GPEN, Cloud Security Certifications

Qualifications

Bachelor’s degree

Experience

3 years’ experience, diploma, military or police academy graduate with 8 years’ experience, or high school with 10 years’ experience.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available