Review and approve cloud solution designs, ensuring secure-by-design principles, threat modeling, and compliance with best practices and reference architectures.
Support Operations and the Supply Chain Security Manager by managing intake, triage and investigation of thefts reported within the region of responsibility
Works with key market stakeholders within the region to understand how illegal trade impacts the geography and to support prevention of illegal trade
Ensure that suspect sample testing is conducted on a timely basis, and liaise regularly with stakeholders across multiple functions including QA, Regulatory Affairs, Legal
...
Support Operations and the Supply Chain Security Manager by managing intake, triage and investigation of thefts reported within the region of responsibility
Works with key market stakeholders within the region to understand how illegal trade impacts the geography and to support prevention of illegal trade
Ensure that suspect sample testing is conducted on a timely basis, and liaise regularly with stakeholders across multiple functions including QA, Regulatory Affairs, Legal
...
Support Operations and the Supply Chain Security Manager by managing intake, triage and investigation of thefts reported within the region of responsibility
Works with key market stakeholders within the region to understand how illegal trade impacts the geography and to support prevention of illegal trade
Ensure that suspect sample testing is conducted on a timely basis, and liaise regularly with stakeholders across multiple functions including QA, Regulatory Affairs, Legal
...
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
Identify malicious activities from legitimate file, email, user, or network activity, distinguishing between benign and harmful elements with precision.
Conduct manual research to gather threat intelligence and analyze attack vectors. Identify potential threats, study their behavior and techniques, and assess the methods used by attackers to provide actionable insights.
Assess and categorize events that have been manually reported. Review the details of each event thoroughly to determine its significance and severity, classifying it according to predefined criteria to ensure accurate prioritization and responses.
...
Collaborating with technical, sales, and bid teams to design, demonstrate, propose, and implement customized cybersecurity solutions that meet customer needs and compliance requirements.
Driving the cybersecurity sales pipeline by developing winning proposals, identifying new market opportunities, tracking performance, maintaining forecasts, and sharing market intelligence.
Defining and executing the digital cybersecurity roadmap, acting as the key liaison between global cyber teams, industry stakeholders, and local clients while promoting cross-functional collaboration.
...
Translate technical risks into business impact and process resilience, to support decision-making at operational (engineering, maintenance, etc.) and management levels
Assess vulnerabilities, lead system hardening, and design compensating controls for ICS/SCADA platforms
Collaborate with engineering, plant, and IT security teams to integrate OT security into operational processes
...
Manage and perform IT Audits including planning, scheduling, work paper review, management discussion, and report preparation.
Research & implement IT security measures. Conduct security research in keeping abreast of latest security issues.
Manage, coordinate and execute Disaster Recovery (DR) Planning and Testing. Oversee the regular testing of the plan and update for major changes in hardware, applications, business and regulatory requirements accordingly.
...
Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
...