Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.
Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.
Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.
...
Study, identify, and evaluate emerging security threats and risks, and develop effective mitigation strategies, tools, and systems to manage those threats and risks.
Implement vulnerability assessment and penetrations tests on communications & digital products, services, systems, and organizations to identify security vulnerabilities, and pursue corrective action to address them.
Undertake threat-intelligence gathering and horizon–scanning activities to increase situational awareness and preparedness against arising security threats and risks.
...
Document investigations, findings, and remediation actions accurately within case management systems.
Contribute to security use-case tuning and continuous detection improvement. Support automation initiatives through SOAR playbooks and workflow optimization.
Demonstrate ability to perform event analysis and tools utilization (identification, response, escalation)
...
Document investigations, findings, and remediation actions accurately within case management systems.
Contribute to security use-case tuning and continuous detection improvement. Support automation initiatives through SOAR playbooks and workflow optimization.
Demonstrate ability to perform event analysis and tools utilization (identification, response, escalation)
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...
Maintain alertness and quality of analysis regardless of time of day
Company Description
Clone & Freemen has been a trusted technology partner for over 28 years, specializing in creating integrated and innovative solutions for B2B leaders. From managed IT and cybersecurity to digital design and IoT systems, the company delivers tailored services through its MSP+ ecosystem. Operating as a full-service partner, Clone & Freemen bridges the gap between maintaining operational stability and driving forward-looking technological innovation. Their mission is to empower businesses with seamless, connected technology solutions that support both current operations and future growth. The company is known for its commitment to accountability and delivering impactful results.
...
Assess exploitability and potential business impact of excessive privileges, insecure configurations, weak controls, technology vulnerabilities, and exposed services.
Recommend, track, and validate remediation activities to reduce organizational cyber exposure.
Support adversary simulation and purple team exercises to assess security control effectiveness.
...
Perform detailed investigative works into all traffic anomalies against established, historical baselines of individual agencies. Reviewing and profiling the events of all monitored clients
...
Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation.
...