Bachelor’s degree with a minimum of "5-6" years of experience in Information Security.
Good understanding on ISMS policies, standards, and security guidelines.
Knowledge of common cybersecurity frameworks and standards such as NIST, ISO and CIS controls.
Familiarity with security hardening best practices, vulnerability management, and configuration assessments.
Experience in implementing security audits and help translate findings into practical follow-up actions.
Good understanding of a wide IT infrastructure and technology landscape.
Collaborate with IT and business process owners to address control deficiencies and implement corrective actions.
Knowledge in Security Incident Response, Disaster Recovery, Business continuity management, Identity Access Review, Change Management.
Soft Skills & Collaboration:
Highly organized, with experience in project tracking, milestone planning, and status reporting, including in global and cross-functional environments.
Solid communication and presentation skills,
with the ability to explain complex topics clearly to a range of audiences.
Proactive and solution-focused approach, able to prioritize effectively and drive tasks through to completion.
Experience delivering workshops and training sessions to technical and non-technical stakeholders.
Collaborative working style, with the ability to operate effectively within complex organizational structures.
Core Responsibilities:
1. Security Policy Alignment:
- Support the review and mapping of GIS Cybersecurity policies to operational realities.
- Lead questionnaire / Audit development for Digital Infrastructure technologies and audit execution across global Digital Infrastructure teams.
- Execute Audits and Follow UP Actions, Assist in Tracking compliance across Digital Infrastructure teams.
- Work with the relevant business stakeholders to identify and evaluate actions to improve compliance of controls.