Tech Stack
AWSAzureCloudCyber SecurityOpenStackSwitching
About the role
- Develop and implement comprehensive security policies, protocols, and procedures.
- Develop an IT security architecture roadmap that will identify security controls and identify and assess current and new technologies that will enforce the organization’s security priorities
- Provide guidance for and help maintain security policies and procedures, risk assessments, incident response activities, vulnerability management, and forensic/investigative activities
- Stay abreast of industry best practices in risk management techniques and integrate new methods and tools as appropriate
- Lead and manage the security team, providing guidance and support to ensure effective security operations.
- Conduct regular security assessments and audits to identify vulnerabilities and implement corrective actions.
- Provide in-depth support for information security incidents including internal violations, hacker attacks, viruses and system outages.
- Assist with the investigation of security breaches, policy violations, and other security incidents
- Ensure that controls comply with contractual obligations, corporate policies, and legal and regulatory requirements
- Collaborate with other departments to integrate security measures into all aspects of the company's operations.
- Ensure compliance with relevant industry standards, regulations, and best practices.
- Develop and deliver security training programs to educate employees on security awareness and best practices.
- Prepare and present regular reports on the security status and initiatives to senior management.
- Monitor vendor and third-party security reports/lists and ensure solutions to resolve issues are put into place by the appropriate team
- Ability to educate a non-technical audience about various security measures.
- Identify, assess, and prioritize IT risks to data and systems, including external threats, cyber-crimes, internal threats, and third-party risks.
- Advise relevant stakeholders on the appropriate courses of action to mitigate or eliminate risk
- Coordinate the development of implementation plans and procedures to ensure that business-critical services are recovered in the event of a security or disaster event
- Provide 24x7 support for network and security issues
Requirements
- Eight or more years of direct Information Security experience.
- Three or more years in a senior Security management role.
- Expert proficiency of common information security management frameworks, such as NIST, ISO/IEC 27001 etc.
- Excellent written and verbal communication skills and high level of personal integrity.
- Experience with firewall architecture, management, and maintenance (preferably FortiNet or Cisco)
- Strong IT knowledge across various technologies such as operating systems, networks and routing, remote access, anti-malware, monitoring, etc.
- Deep familiarity with Microsoft computing technology
- Strong hands-on security operations, problem-solving, and project/time management skills
- Experience with architecting security compliance requirements and standards into workable technology solutions
- Experience working with Legal, HR, Audit, and management personnel on security and privacy matters
- Proven ability to work and communicate effectively with internal and external customers, contractors and vendors
- Active CISSP, CISM, or equivalent advanced security certification
- Preferred Previous security experience in the Telecommunications Industry
- Experience developing and managing departmental budgets and solid financial acumen
- Demonstrated experience leading in a complex, multi stakeholder organization
- Networking domain knowledge: TCP/UDP, Routing and Switching protocols
- Working experience on virtualization technologies such as KVM, Hyper V, ESXi and OpenStack
- Working experience with Microsoft Defender Suite of Products
- Working experience with Tanium Platform
- Knowledge experience with AWS and/or Azure
- Experience with developing and refining security operations processes and maintaining metrics/reporting.