Position Purpose
The purpose of the position is to help with the information security topics mentioned in the direct responsibilities.
Direct Responsibilities
- Executing IT risk assessment reviews, identifying controls gaps and working in collaboration with subject matter experts to devise appropriate mitigation plans.
- Identifying key risk trends, issues and other insights requiring further investigation and following up with Technology as appropriate.
- Knowledge of Secure Development methodologies and frameworks.
- Hands-on experience in penetration testing and tools like AppScan, Webinspect, Fortify, AppSpider, BurpSuite, Qualys, Checkmarx, Coverity…
- Well-versed in conducting Security Review, Assessments and providing recommendations.
- Knowledge of OWASP, SANS standards.
- Experience in Process Improvement, Controls Enhancement and Reporting.
- Engaging with organization wide risk and control groups, including internal audit and territory control teams.
- Working with Technology stakeholders (including Production Support and Development teams)
to identify the IT risks affecting the organization and formulating appropriate remediation strategies based on full understanding of business exposure and compensating controls.
Contributing Responsibilities
- Excellent understanding of development security and its implementation in systems: identification, authentication, access control and provisioning, alignment of jurisdiction to business process
- Knowledge of single-sign-on security strategies (e.g. SAML, OAUTH2, SiteMinder etc.)
- Excellent understanding of authentication related mechanisms (Kerberos, One Time Passwords, PKI)
- Positive understanding of cryptography and its practical uses within secure application development
- Familiarity with common security vulnerabilities (e.g. OWASP Top 10)
- Strong technical skills required to understand vulnerabilities in detail and how to resolve/mitigate them.
- Excellent knowledge of programming best practices, design