Translate technical risks into business impact and process resilience, to support decision-making at operational (engineering, maintenance, etc.) and management levels
Assess vulnerabilities, lead system hardening, and design compensating controls for ICS/SCADA platforms
Collaborate with engineering, plant, and IT security teams to integrate OT security into operational processes
...
Manage and perform IT Audits including planning, scheduling, work paper review, management discussion, and report preparation.
Research & implement IT security measures. Conduct security research in keeping abreast of latest security issues.
Manage, coordinate and execute Disaster Recovery (DR) Planning and Testing. Oversee the regular testing of the plan and update for major changes in hardware, applications, business and regulatory requirements accordingly.
...
Prepare project documentation such as Project Plan, Technical Document, Material Document Submission, drawings and OMM.
Participate in the regular meeting of the project, allocate, arrange and complete the relevant work on time according to the meeting requirements and report daily or weekly progress at site.
Manage/Monitor/Track project and control cost to ensure project is completed on time within budget, contractual and safety standard
...
Collaborate with our product team to provide feedback on product features and latest release based on client feedback and industry trends
Attend trade shows and events to represent the company and promote our network security solutions
Ability to lead project and ensure successful project closure on-time will be a plus. Such tasks include client kick-off meetings, planning and configuration, knowledge transfer and documentations
...
Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
...
Identifies and addresses legal and customer security requirements within the region
Supports the implementation of the global Information Security Management System (ISMS) and global business continuity standards within the region
Implements the global risk-based approach to protecting information and other assets within his/her region and performs vulnerability management related tasks
...
Act as the business focal point for ERP access management and security, including ownership and continuous improvement of Job Archetypes, business roles, and governance.
Partner with Enterprise Access Management and IT teams to ensure access provisioning, security controls, compliance activities, and access reviews are completed effectively and on time.
...