Provide independent, strategic IT security and risk advisory to the Group CTO, Senior Management, Board and relevant committees to enable informed risk‑based decisions
Establish, maintain and enforce Group IT Security policies, standards, and frameworks, ensuring consistent adoption across Head Office and regional offices
Champion and cultivate a strong security and compliance culture across technology and business stakeholders
...
You will manage vulnerability governance across all applications within Global Corporate Systems & Services (EDW). You will oversee vulnerability management activities for multiple application towers, including ERP, BI, Billing, and HPTools, ensuring that you align remediation and fix deployments with application-specific risk assessments.
You will engage with application teams through bi-weekly meetings to review vulnerability statuses, discuss risk exposure, and prioritize remediation efforts. Additionally, you will generate and analyze vulnerability reports using tools such as Panaseer Vulnerability Management and MARS DB. These reports will identify non-compliance, including overdue Service level agreement items. Furthermore, they will support a structured remediation approach through bi-weekly sprint cycles. Maintaining accurate and updated centralized tracking of remediation progress will be a key part of your responsibilities.
A critical aspect of the role includes managing false-positive findings by working with Threat and Vulnerability teams, vendors, and stakeholders to validate issues and ensure resolution with supporting evidence.
...
Opportunity to work in complex cross-functional and geographically diverse teams
You will engage with application teams through bi-weekly meetings to review vulnerability statuses, discuss risk exposure, and prioritize remediation efforts. Additionally, you will generate and analyze vulnerability reports using tools such as Panaseer Vulnerability Management and MARS DB. These reports will identify non-compliance, including overdue Service level agreement items. Furthermore, they will support a structured remediation approach through bi-weekly sprint cycles. Maintaining accurate and updated centralized tracking of remediation progress will be a key part of your responsibilities.
...
Prioritize and track remediation efforts for identified vulnerabilities, collaborating with relevant teams to ensure timely resolution.
Stay abreast of emerging threats, vulnerabilities, and attack techniques to enhance VAPT strategies.
Establish and maintain robust security governance frameworks, policies, standards, and procedures in alignment with industry best practices (e.g., ISO 27001, NIST, internal compliance requirements).
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...