Responsible for managing and implementing the cybersecurity assurance programme. including vulnerability management, application security testing, penetration testing, and security compliance monitoring to protect enterprise systems and applications from security threats.
Manage vulnerability management programme using Scanners for comprehensive vulnerability scanning, assessment, remediation tracking, and reporting ensuring effective vulnerability management across the enterprise.
Manage and oversee FIM, DAM and firewall assurance operations, coordinating teams, tracking remediation, and ensuring timely closure of identified security gaps.
Oversee ATM security programme for ATMs including vulnerability assessment, penetration testing, security hardening, and compliance monitoring ensuring ATM security resilience.
Coordinate security compliance monitoring including baseline compliance scanning for security baselines, configuration compliance, and regulatory compliance with automated scanning and compliance reporting.
Lead IT Security assessment practice for multiple technologies including WAF, NGFW, IPS, ISE, Device Control, MFA, Web Proxy, Mail Proxy, EDR, Application Control, Sandbox, Routers, Switches, SD-WAN .. etc to Validate control effectiveness through configuration reviews, threat-based testing, rule analysis, logging verification, and use-case validation as per standards and industry best practice.
Integrate security into DevSecOps pipeline including automated security testing (SAST, DAST, SCA), security gates, and pipeline automation ensuring secure CI/CD.
Develop security assurance reports and metrics, prepare evidence for audits, and ensure audit readiness.
Minimum Qualifications
BSC in Communication Engineering or computer science
CISSP (Certified Information Systems Security Professional) certificate is preferred.
CEH (Certified Ethical Hacking) or OSCP preferred
GIAC certifications (GWAPT, GPEN) preferred
Master's degree in Information Security or related field preferred
Minimum Experience:
8+ Years of IT & Information Security experience with demonstrated leadership in vulnerability management, application security, and security assurance programmes
Job Specific Skills
Vulnerability Management experience with enterprise tools (Tenable, Nessus, Qualys)
Application Security Testing (SAST, DAST, SCA) experience with Fortify and similar tools
Penetration testing methodologies and frameworks (OWASP, PTES)
Security compliance monitoring and baseline management
DevSecOps integration and CI/CD security
Network security (Firewalls, IPS, WAF) management
Security reporting and metrics development
Audit evidence preparation and regulatory compliance (CBE, PCI, ISO 27001)