Drive stabilization of S4 ADC (After hyper-care & transition for R2.0 ARU2, T&T, R2.1, US) & Sustain Blueprint/BGSAP through Integrated Support Model (ISM) in Upstream/IG Assets.
Work closely with ADC Deploy in the transition to BAU based on the QC3 ISM Readiness list cover process knowledge upskilling, SU, APFP nomination, hyper care support. These networks span across process area and organization/teams ranging from Asset Management, Supply Chain, Project & Wells, HM and Finance.
Working closely with IT SOM to improve service delivery performance for ADC, BLP and BG ERP. For ADC, through the ISM call – work with IT-SOM and APFPs in live assets to quickly stabilize ADC solution after hypercare period. This is measured with stabilisation of the ticket count.
...
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Perform detailed investigative works into all traffic anomalies against established, historical baselines of individual agencies. Reviewing and profiling the events of all monitored clients
...
Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation.
...
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
Assess exploitability and potential business impact of excessive privileges, insecure configurations, weak controls, technology vulnerabilities, and exposed services.
Recommend, track, and validate remediation activities to reduce organizational cyber exposure.
Support adversary simulation and purple team exercises to assess security control effectiveness.
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Issue Resolution: Escalate and collaborate with the engineering team to resolve security issues.
Security Reviews: Conduct security reviews on new features.
Security Awareness Training: Developing and delivering security awareness training to employees to ensure they understand security policies and best practices.
...
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
Identify malicious activities from legitimate file, email, user, or network activity, distinguishing between benign and harmful elements with precision.
Conduct manual research to gather threat intelligence and analyze attack vectors. Identify potential threats, study their behavior and techniques, and assess the methods used by attackers to provide actionable insights.
Assess and categorize events that have been manually reported. Review the details of each event thoroughly to determine its significance and severity, classifying it according to predefined criteria to ensure accurate prioritization and responses.
...