Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Collaborate with other DIS Units, other Functions, and third parties in annual security posture assessment exercise to ensure closure for all security gaps discovered by the respective custodians within the committed timeline.
Communicates with stakeholders for projected business growth to ensure the network is operating at optimum performance for the business.
Establishes Level 2 maintenance and support contract with network and security vendors that incorporates service level and scheduled maintenance to maximize the availability, reliability and integrity of the apps.
...
Operational Excellence: Ensure timely renewal and compliance of hardware maintenance contracts and licenses. Implement and regularly test disaster recovery plans for business continuity. Recommend tech enhancements to streamline operations and reduce costs. Manage physical and virtual servers for optimal performance
Cloud & Infrastructure Strategy: Architect and implement cloud-based solutions aligned with business goals, ensuring consistency and cost-efficiency. Collaborate across teams to drive a standardized, modernized cloud infrastructure roadmap with a unified operating model
Solution Delivery & Support: Develop and support IT infrastructure solutions with high availability, scalability, and performance as well as act as a Level 3/4 subject matter expert for server and cloud-related issues
...
Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation.
...
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
Direct and mentor Information Security Managers across application security, security operations, GRC, and privacy domains, leveraging advanced technical depth to drive engineering skill set enhancements and operational maturity
Conduct periodic vulnerability assessments and penetration testing across infrastructure, developing actionable remediation roadmaps and infrastructure hardening plans
Own third-party and supply-chain security risk management, ensuring vendors meet contractual, regulatory, and security requirements
...
We seek to strike a balance between diversity, inclusion and merit to achieve our mission of infusing diversity in thinking and skillsets into our organisation. Candidates are assessed based on merit and potential, in line with our mission to attract and recruit the best talent available. Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.
Responsibility for the introduction, implementation, and continuous development of a methodology to ensure IT security requirements
Participation in the development of new solutions in the IT security environment and conducting security assessments for new or existing security solutions
Consulting and support for IT product groups and other Evonik units on information security matters, as well as guidance and consulting for IT projects in this context
...