Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Work with development teams to remediate findings that require broader application or architecture changes, providing secure coding guidance and reviewing fixes before closure.
Maintain sprint-based remediation tracking and burn-down reporting for vulnerability backlogs.
Fix vulnerabilities surfaced by security tooling embedded in our CI/CD pipelines as part of the regular development workflow — keeping the pipeline "green" without bypassing or ignoring findings.
...
Review and maintain cybersecurity policies, standards, and procedures, ensuring alignment with regulatory requirements (e.g., Cyber Security Act 2024, MHA, NCII sector requirements).
Perform and support cybersecurity risk assessments, recommending mitigation or acceptance plans to ensure secure operation of systems and digital platforms.
Coordinate with internal IT team, vendors, concessionaires, and project teams to embed cybersecurity-by-design in all technology initiatives and digital platforms.
...
Observe and participate (where possible) in vulnerability assessments and penetration testing activities.
Assist with incident response procedures under the guidance of senior engineers, potentially involving basic scripting for log analysis or remediation tasks.
Contribute to security documentation by keeping records and updating procedures as instructed.
...
Internal Penetration Testing: Perform regular, deep-dive manual penetration tests on our web applications. You must be able to go beyond automated scans to find complex logic flaws, session management issues, and bypasses.
Infrastructure Hardening: Conduct recurring vulnerability assessments of our servers (Windows/Linux) and networking devices.
Remediation & Collaboration: Work directly with our development team to provide technical "how-to" guidance on fixing vulnerabilities, such as implementing mTLS, securing API endpoints, and hardening database configurations (SQL Server/PostgreSQL).
...
Review network vulnerabilities in collaboration with cybersecurity teams and external vendors and drive remediation activities to closure.
Perform security remediation activities including upgrading network device firmware and software, enabling or disabling security features within network management consoles, adjusting security policies and configurations to reduce risk
Work closely with Network Engineering to ensure security controls are aligned with network design, performance and availability requirements
...
Attend technical meetings with customers, respond to RFP, ensure successful Proofs-Of-Concept (POCs) and advise on best practices.
Initiate necessary tests, audits and changes to ensure end-to-end solution integrity/technical feasibility across the products and services sold to the customers.
Diploma/ bachelor's degree/ Professional Certificate preferably in IT/ Information Systems/ Computer Science
...
Internal Penetration Testing: Perform regular, deep-dive manual penetration tests on our web applications. You must be able to go beyond automated scans to find complex logic flaws, session management issues, and bypasses.
Infrastructure Hardening: Conduct recurring vulnerability assessments of our servers (Windows/Linux) and networking devices.
Remediation & Collaboration: Work directly with our development team to provide technical "how-to" guidance on fixing vulnerabilities, such as implementing mTLS, securing API endpoints, and hardening database configurations (SQL Server/PostgreSQL).
...