Perform scheduled inventories of mobile apps on the main public stores (at minima Google & Apple ones)
Seek confirmation or conduct research of the owner entity of each mobile app (via CISO network)
Maintain an inventory repository with the minimum following information:
Owner Entity,
Related internal application ID to have the link with the functional application (for any entity in Group)
Last release data,
Last pen test date,
Compliance with requirement related to P4 application (pen test before major update release or every 2 years)
Pen tests coordination:
Schedule complementary pen tests and prioritize them (criteria to be defined with Group CISO)
Centralize pen tests results and communicate them to the owner entity
Track remediation plan defined & managed by the owner entity (Vulnerability Management)
Reporting:
Define & maintain a dedicated dashboard
Provide the dashboard (or data)
to be integrated into the monthly Due Diligence Dashboard related to external attack surface monitoring done by the CDF EVS team.
Contributing Responsibilities
Analyze various sources of data to identify potential areas of risk and assist in developing appropriate process improvements
Assist in compiling accurate and timely reporting for the CDF management.
Assisting and participating in any special project or request was asked by steering monthly processes, information sources or internal applications upgrades, enhancements related to current reporting requirements, etc.
Assist in identifying opportunities for process improvement and greater efficiency
Note:
The candidate should have an IT background and experience coordinating with multiple project teams.
Technical Competencies
MS OFFICE PACK MICROSOFT EXCEL (Expert)
POWER POINT PRESENTATIONS (Expert)
Data Analysis (Expert)
Project Management/PMO (Proficient)
Risk Monitoring (Preferable)
Experience of vulnerability management system