Key Responsibilities
- Perform the information security review of infrastructure products and verify their compliance to Information Security Standards (CISS).
- Work with the engineering teams and third-party vendors to obtain information required for the security review of these infrastructure products.
- Evaluate the security and compliance of the products by reviewing documentation and by hands-on testing.
- Document any findings, security breaches and non-compliant items.
- Investigate how non-compliant items can be remediated or how their risk could be mitigated and provide recommendations.
- Support Information Security Officers in their work for remediating any non-compliant items.
- Embed quality control measures in all processes and activities to ensure a robust and sustainable data integrity review that can adapt to meet the dynamic requirements of the IT IS organization.
- Take responsibility for producing quality work and maintain a professional reputation.
- Responsible for managing customer expectations.
- Must escalate issues appropriately and in a timely fashion with general management supervision.
- Support the organization through internal and external audits of the various processes and procedures in use.
Skills
- Security mindset; ability to think the way an attacker would think.
- Ability and willingness to both read and write technical documentation.
- Ability to learn and understand new technologies and understand the architecture of systems.
- Skills and experience in cloud technologies.
- Experience in multiple domains of technology.
- Experience with security testing is a plus.
- Excellent problem solving abilities and analytical skills. Ability to see the big picture with high attention to critical details.
- Strong customer relation and project management skills.
- Communication - excellent writing and verbal skills.
- Excellent interpersonal skills.
- Strong work ethic and judgment.
Qualifications
- Degree in a technology related discipline is strongly preferred.
- 3-5 years working in an Information Technology or Information Security related field.
Seniority Level:
Mid-Level