Position Summary :
The job will require individual to possess strong written and verbal communication, administrative, infrastructure planning and risk management skills. It would entail consulting and advising the team on Cyber security & assurance and work with third parties(MSSP ,OEM & Partners) to onboard best Cyber security practices within the compliance framework.
Key Activities & Responsibilities :
- Responsible for overall Cyber security practice for -IT system and infrastructure ( On Premises Infrastructure, Cloud & Applications)
- Availability of IT services and developing a resilient infrastructure to reduce failures.
- Cyber security assurance & compliance on Data center & Cloud Operations ( Availability ,Capacity planning , Security compliance, IM / SR / PM / IR
- Ensure to implement the best practices & NIST,ISO,MITRE ATT&CK framework and methodologies are maintained, followed to ensure effective monitoring, control and support of service delivery to users.
- Managing MSSP ,OEM & partners for their service delivery , Review regularly, measuring the SLA,SLO & SLI
- Ensuring Cyber security incident response plan with their appropriate resolutions(Monitoring & Reporting ). Adhere to escalation matrix and co-ordinate in escalation mitigation. Support Projects to seamless transition from project to operation with required processes (Build to Operation)
- Have responsibility for scoping penetration testing activities to identify security weaknesses within the company,
- Develop a culture of in-depth understanding as to why security testing is required at both business and internal team level
- Analysis of information protection technologies and processes to identify technology security weaknesses & enhance the controls
- Lead ongoing risk assessments & audit of data processing systems to confirm the design of logical controls are effective and meet regulatory and legal requirements; and
- Provide quality reports to summarise test activities, including objectives, planning, methodology, results, analysis and recommendations to both technical and non-technical audiences. From the output of the reports provide suggested approaches to enhance further.
Required Skills and Capabilities :
Expert knowledge & understanding of IT Infrastructure landscape & management (DLP, Secure web gateway, EDR, XDR, SIEM,VPN,SSL,SSO,VAPT etc)ITIL framework & Knowledge of architecture landscape and planning, operations and governance principles to design, run and govern enterprise.Knowledge to support the enterprise infrastructure and ensure seamless infrastructure management.Apply principles, practices, and methodologies to run, maintain and troubleshoot IT infrastructure and applications with SLAs.Ability to design and implement IT security principles, methods, practices, policies and tools.Practical and problem-solving approach with ability to meet deliverable expectations of Management irrespective of constraints.Knowledge of applying multidisciplinary governance frameworks, theories, and concepts to ensure that IT investments, regulatory, legal, risk, compliance etcFormal project management principles and practices, ensuring effective management of scope, resources, time, cost, quality, risk and communications.Apply contract management guidelines and partner engagement theories to build and govern productive and enduring partner relationships.(ref : hirist.tech)