24 Sep
|
Mizuho Global Services
|
Mumbai
24 Sep
Mizuho Global Services
Mumbai
Job Title: Security Posture Assessment
A security posture assessment responsible for building a baseline view of organization's security capabilities end-to-end. The ultimate aim of such an assessment is to build maturity in the organization’s cyber resilience strategy to minimize the risk of cyberattacks and data breaches. To understand organisation’s security posture, a holistic view of the personnel, processes, policies and technologies any organisation engages with is essential.
However, conducting a security posture assessment as a point-in-time exercise defeats the purpose; any organisation evolves continuously, so the security posture must be dynamic. Therefore, security posture assessments should be a continuous exercise to respond to growing cyber threats.
Qualifications
· Graduation/Post graduation in, Computers, Information Systems, Computer Science, or Information technology systems
· 10+ years of work experience in cyber security /Information security project, with security posture assessment
· At least one technical certification required (CISM, CISSP, CEH, CRISC, OSCP, ISACA, GIAC, ISO2701)
· Experience with Network Security design, NIST Cybersecurity Framework and Risk Management Framework is strongly preferred.
· Knowledge of banking business and information technology practices and trends in banking sector
· Awareness of appropriate local laws and regulations dealing with technology;
· Ability to communicate effectively, both orally and in writing.
· Strong analytic skills and business judgment with ability to independently assess and resolve complex program/project issues
Skills Required
· Conduct Vulnerability assessments and analyse security control and configuration to identify the potential risks to organizations information system and data
· Strong analytical thinking skills to interpret assessment result, prioritize risks, and recommended effective resolutions.
· Must have a better understanding of Risk assessment and Vulnerability assessment
· Awareness of relevant laws and regulations impacting information security, privacy and data protection.
Personal skills:
- Valuable Team player/Possess Positive and learning attitude
- Good Verbal and Written communication skills
- Sense of Ownership,
Priorities and Autonomous
· Ability to travel up to 50% of the time
What we offer:
· Working on international projects
· Wide range of possibilities to gain both technical and soft skills as well as professional certifications
Roles & Responsibilities
· Able to evaluate the potential impact of security vulnerabilities, prioritize risks based on their severity and potential consequences.
· Responsible for analysing and creating cyber risks reports and developing structured strategies to enhance cyber risk.
· Able to perform simulated attacks to identify the vulnerabilities also exploit weaknesses to assess real world risks and provide inside into potential breaches.
· Able to asses overall security architecture also the recommended impartments for a robust security posture.
· Ensure adherence to regulatory requirements and validate that security controls meet compliance standards
· Able to provide the documentation for audits with detailed with the logical explanations.
· Develop response plan for identified vulnerability, mitigate and contain security incident, analyse and learn form security breaches.
· Able to implement recommended security measures to ensure system ad software are up to date. Collaborate with security team to address vulnerability.
· Oversee the security posture assessment processes and allocate resource for remediation efforts. Communicate with stockholders about security status.
· Strong network reconnaissance and identify the local network topology of Internet Protocol (IP) or non-IP based network infrastructure also identify internal network’s packet filtering mechanisms such as firewall, IDS or IPS;
· vulnerability research to provide the security recommendations based on the latest security trends and best practices
· To avoid breaches of legal, statutory,
regulatory or contractual obligations related to information security and of any security requirements.
· Better understanding of SQL Injection and Cross Site Scripting (XSS)Better understanding of Broken authentication and session management
· vulnerability retest and verification shall be performed upon the completion of the vulnerability remediation activities by the system owners within the stipulated time frame;
· Better understanding of Sensitive data exposure many web applications do not properly protect sensitive data, such as credit cards, tax IDs, and authentication credentials
· Understanding of CIA triangle and risk assessment on the risks of CIA of the organisational information assets
· Information and documentations requested for the SPA exercise are provided on time
· ensuring the availability of the system, network and application administrators to assist our consultants especially when performing the onsite activities;
· A detailed definition of the scope of the network and systems tested as part of the assessment clarification systems or segments that are considered during the test
· Details on the methodologies used to complete the testing (port scanning, map etc.)
· Better understandings of whether/how the systems/host/application may be exploited using each vulnerability.
· Understanding the critical assets to the business and the attack surface. This ranges from the organisation’s exposure to malicious attackers, in the form of endpoints, infrastructure, and the network, to understanding which assets carry the highest risk in the case of a breach.
· Understanding whether internally or to a third-party or vendor - and where data is stored and processed. What data needs the most protection, and where do security controls need to be implemented to meet your compliance requirements?
· Better understanding on how network and digital architectures designed to bolster security requirements? Do you have a zero-trust security strategy or a strong access management system?
Able to understand the comprehensive business continuity and disaster recovery policies in place, as well as a robust incident response process, so that the organization has a strong response to cyber threats?
📌 Sr Security risk analyst-AVP/ Senior Officer (Mumbai)
🏢 Mizuho Global Services
📍 Mumbai