Set up, improve, and streamline certificate and key management operational processes (issuance, renewal, revocation, discovery, rotation, escrow) for continuous improvement and to eliminate outage risk from expiry.
Incorporate cryptographic and key management best practices (FIPS, NIST, X.509, PKCS) into operational workflows and platform configuration.
Monitor, analyze, investigate, and resolve day-to-day operational incidents relating to certificates, keys, and HSMs; provide advisory to application teams.
...
Manage internal and external security audit activities, including audit planning, coordination, tracking of audit findings, and ensuring the timely implementation and closure of remediation actions. Support compliance monitoring and continuous improvement efforts relating to ISO/IEC27000 certification and other regulatory requirements.
Manage and ensure authorised access governance in accordance with organisational and regulatory requirements, including reviewing, approving, revoking, and tracking access rights and exceptions where required.
Maintain the cybersecurity risk register, perform cybersecurity risk assessments, monitor risk mitigation plans, and follow up on remediation actions to ensure identified risks are addressed within stipulated timelines. Escalate significant risks to Management where necessary.
...