• Design and implement insider threat solutions, such as Data Loss Prevention (DLP), to safeguard sensitive information and prevent unauthorized data exfiltration.
• Define and enforce role-based access controls and separation of duties principles to prevent abuse and limit the effect of mistakes across systems and applications.
• Establish and maintain secure configurations for systems, applications, and network components in alignment with industry standards and ISO 27001:2022 requirements.
• Develop threat models and security design documentation to anticipate and mitigate emerging attack vectors.
Log Analytics & Systems Monitoring
• Deploy and configure centralized logging infrastructure and SIEM platforms to collect, store, and analyze security events across all systems and applications.
• Design and implement alerting rules and monitoring workflows to detect anomalies, suspicious activities, and potential security breaches in real time.
• Monitor, investigate, and respond to security alerts in coordination with the CISO office and provide recommendations for remediation.
• Optimize log retention, storage, and analytics performance to maintain compliance with regulatory and operational requirements.
Vulnerability & Risk Management
• Coordinate vulnerability disclosure processes and manage the bug bounty program to identify and remediate security weaknesses in a timely manner.
• Coordinate and oversee penetration testing engagements to validate security controls and identify gaps in the security architecture.
• Develop and maintain a process for tracking, prioritizing, and remediating identified vulnerabilities and security findings.
Secure Development & Configuration Management
• Establish and enforce secure coding principles and practices for all internal software development and third-party components.
• Implement configuration management processes to ensure systems are deployed and maintained in a secure, consistent, and auditable manner.
• Design and implement secure data masking techniques to protect sensitive information in non-production environments and during data processing.
Compliance Support & Collaboration with CISO office
• Work closely with the Information Security Officers to translate compliance requirements into clear technical specifications for architecture, logging, and monitoring.
• Provide evidence and documentation of technical controls to support compliance audits and regulatory assessments for ISO 27001:2022 and EU NIS2.
• Support the ISO’s in defining technical monitoring requirements and help validate that implemented controls meet compliance objectives.
• Develop and support cyber security incident exercises and participate in the Incident Response Team during security breaches.