Information Security Specialist
- Posted 19 days ago
- Be among the first 10 applicants
Job Description
Role Overview
- Push for vendor's compliance with the company's information security and data privacy policies by performing contract reviews and onsite audit
- Develop consultative relationships with different departments to educate them about risk management and/or implement risk management best practices to prevent or mitigate loss related to data leakage
- Ensure that all committed resolutions of different divisions are monitored, reported and resolved on time
- Lead and conduct security awareness programs and deliver it across the enterprise
- Establish mandatory policies, minimum standards and/or written guidance related to information security and data privacy best practices.
- Govern projects in order to minimize compliance risks that often results from project plans that does not adhere to a proper security risk assessment. This includes analyzing the business and IT specifications in order to prescribe the appropriate information security controls.
- Represent Information Security in discussions with different stakeholders and extend assistance to educate relevant users on how to comply to the different information security and data privacy policies of the company
- Act as the project manager for initiatives owned by the Information Security division
- Work with IT and all relevant business stakeholders in addressing security incidents, breaches and different cyber threats reported by the security operations team.
- Graduate of Computer Engineering, Computer Science, Information Technology or other relevant science, technical and engineering courses
- With at least 2 years of information security / data privacy practice
- Can easily transition to a fast-paced environment and familiarize himself on business matters that can affect the security posture of the company
- Can communicate, present, and negotiate effectively, with strong command of the English language, both written and oral
- Has a keen eye on details with strong planning and analytical skills
- Knowledgeable in securing Network, Identity Access, Cloud systems, Endpoint devices, web and mobile applications
- Familiarity with security frameworks and privacy regulations (e.g. NIST Cybersecurity framework, CIS-CSC, ISO27001, Data Privacy Act) and risk management methodologies
- Relevant experience in Identity Access Management and Information Security Incident Response handling is a plus.
- Experience in designing and securing cloud platforms hosted in Amazon, Azure and Google
- Knowledge of information security risk management principles, methodologies, and risk assessment processes.
- Understanding of Governance, Risk, and Compliance (GRC) frameworks, security policies, and regulatory requirements.
- Knowledge of Data Loss Prevention (DLP) concepts, data classification, and information protection technologies.
More Info
Key Skills
CIS-CSC
NIST Cybersecurity Framework
Iso27001


