About the Role
The Officer will be working on various cybersecurity functions including managing security vendors, overseeing security testing, handling incidents, and providing cybersecurity consultancy and advisory support.
Responsibilities
- Manage security vendors and their deliverables.
- Oversee periodic security testing activities.
- Assess proposed mitigation and remediation measures for adequacy and effectiveness.
- Ensure mitigation and remediation activities are completed in a timely and effective manner.
- Review security reports.
- Review cybersecurity policies, standards, procedures, and guidelines.
- Provide cybersecurity consultancy and advisory support.
- Respond to security alerts and advisories.
- Manage and handle security incidents.
- Conduct security awareness training.
- Disseminate security advisories via email broadcasts.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
Required Skills
- Minimum of 4–7 years of experience as a Cybersecurity Analyst or in a similar role.
- Strong understanding of network protocols, operating systems such as Windows and Linux, and cloud security concepts across AWS, Azure, and GCP.
- Proficiency in security tools such as vulnerability scanners, penetration testing tools, and SIEM platforms.
- Experience with scripting languages such as Python and PowerShell for automation purposes.
- Familiarity with cybersecurity frameworks and standards such as NIST and ISO 27001.
- Excellent analytical and problem-solving skills with strong attention to detail.
- Ability to work independently as well as collaboratively within a team in a fast-paced environment.
- Strong written and verbal communication skills, with the ability to explain technical information to non-technical audiences.
- Proven ability to manage multiple tasks and prioritize effectively.
- CISSP and/or CISM certification is required.
Preferred Skills
- Enthusiasm for continuous learning and developing cybersecurity skills.
- Strong analytical capabilities.
- Understanding of vulnerabilities listed in the Open Web Application Security Project (OWASP) Top 10.
- Understanding of incident management and handling.
- Experience in software development or security operations is preferred.
The Following Certifications Are Advantageous but Not Mandatory
- GIAC Certified Incident Handler (GCIH)
- CompTIA Security+
- CompTIA CySA+
- EC-Council Certified Security Analyst (ECSA)
- EC-Council Certified Ethical Hacker (CEH)
- (ISC)² Systems Security Certified Practitioner (SSCP)
- Offensive Security Certified Professional (OSCP)