Typically uses Scrum/Agile development techniques and tools for team collaboration, issue tracking and backlog management
Has working knowledge and experience in own discipline. Continues to build knowledge of the organization, processes and customers. Performs a range of mainly straightforward assignments. Typically follows prescribed guidelines or procedures to resolve problem. May train new team members and provide input to employee performance evaluations. Works with a moderate level of guidance.
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
Assess exploitability and potential business impact of excessive privileges, insecure configurations, weak controls, technology vulnerabilities, and exposed services.
Recommend, track, and validate remediation activities to reduce organizational cyber exposure.
Support adversary simulation and purple team exercises to assess security control effectiveness.
...
Prepare project documentation such as Project Plan, Technical Document, Material Document Submission, drawings and OMM.
Participate in the regular meeting of the project, allocate, arrange and complete the relevant work on time according to the meeting requirements and report daily or weekly progress at site.
Manage/Monitor/Track project and control cost to ensure project is completed on time within budget, contractual and safety standard
...
We seek to strike a balance between diversity, inclusion and merit to achieve our mission of infusing diversity in thinking and skillsets into our organisation. Candidates are assessed based on merit and potential, in line with our mission to attract and recruit the best talent available. Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.
Security Framework Alignment: Oversee the definition and maintenance of the Bank’s technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
...
Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...