- Conduct security risk assessments and gap analysis.
- Develop mitigation plans for identifying risks.
- Ensure compliance with:
- ISO 27001 o NIST o CIS Controls
- SOC2 o GDPR
- Industry-specific regulations
- Support audits and regulatory reviews.
Identity & Access Security
- Architect Identity and Access Management (IAM) solutions.
- Design MFA, SSO, Privileged Access Management (PAM), and RBAC frameworks.
- Support Microsoft Entra ID, PingFederate, CyberArk, and other identity platforms.
- Review access governance and privileged access controls.
Security Assessment & Vulnerability Management
- Conduct vulnerability assessments and penetration testing reviews.
- Evaluate security posture across applications and infrastructure.
- Define remediation plans and security controls.
- Support incident response and threat mitigation activities.
Network & Infrastructure Security
- Architect secure network segmentation and connectivity.
- Design firewall, VPN, proxy, and web security solutions.
- Define security monitoring and logging requirements.
- Ensure secure application delivery and network protection.
Security Governance & Policies
- Develop security policies, standards, and operating procedures.
- Define enterprise security controls and architecture patterns.
- Review security exceptions and risk acceptance requests.
- Support board-level and leadership security reviews.