POSITION NAME : Information Security Manager - Deputy Chief Manager
DESIGNATION : Deputy Chief Manager
POSITION GRADE : L5
DEPARTMENT : Information Security
SUB DEPARTMENT : Information Security
Job Location : Goregoan - Head office
OBJECTIVE OF THE ROLE :
To manage Information System Security Program to ensure system security by :
- Timely identification of System Security Vulnerability
- Tracking timely closure of the identified vulnerability
- Pro-actively identifying & providing InfoSec Requirements for new Business / Applications / System Requests
- Building governance practices for InfoSec activities
- Meeting regulatory compliance requirements
KEY RESPONSIBILITIES :
- Management of System Security Program
a. Application Security
b. Application Malware Scanning
c. Vulnerability Assessment
d. Penetration Testing
e. Secure Configuration Reviews (O.S., DBs, sub-systems, web service components, network devices, appliances etc.)
f. Conduct Secure Architecture Reviews
g. Firewall Rulebase Audits
- Security Device / Systems / Solution Management (e.g. VA Scanner, System Configuration Scanner, AppSec Scanner etc.)
- Analyzing Security Advisories, identifying actionable with stakeholders & tracking closure of actions
- Perform Risk Assessment to identify high risk observations which need immediate closure actions
- Tracking remediation of open Security observations
- Guide IT / Business Teams for remediation of Information Security observations
- Handling adhoc requests to proactively identify and provide InfoSec requirements at the initial stage of project (e.g. new applications, system integration, secure architecture, confidential data requests, risk assessment etc.)
- Identify new initiatives, security controls (technical / procedural) improvement areas in InfoSec Program
- Conduct POCs for new Security Solutions, implementation of new Security Practices / Processes / Controls across organization
- Ensure compliance with Information Security Policies & Processes
- Ensure Team is always audit / compliance ready
- Support internal / external audits for these domains
- Work as a Subject Matter Expert for CISO
- Manage Team (2-3 members) & Vendor Engagement
Didn’t find the job appropriate? Report this Job