Responsibilities
Cloud Security:
Design, implement, and maintain security controls for cloud environments (e.g., AWS, Azure, GCP).
Monitor and audit cloud resources for security misconfigurations and vulnerabilities.
Implement and manage cloud access controls, encryption, and identity management.
Assurance:
Perform security assessments and audits to ensure compliance with relevant standards and regulations (e.g., SOC 2, ISO 27001, NIST, HIPAA, GDPR).
Conduct risk assessments and provide guidance for risk mitigation.
Develop and maintain security policies, procedures, and documentation.
Security Operations (SecOps):
Develop and maintain security incident response plans and procedures.
Monitor security alerts and incidents, investigate and respond as necessary.
Collaborate with cross functional teams to enhance security posture and ensure continuous improvement.
Participate in on-call rotation for security incident response.
Vulnerability Assessment and Penetration Testing (VAPT):
Plan and execute regular VAPT assessments on internal and external systems.
Identify and assess security vulnerabilities, prioritizing them based on risk.
Provide detailed reports and remediation recommendations to stakeholders.
Coordinate with development and IT teams to ensure timely vulnerability remediation.
Research and Innovation:
Stay current with industry trends, emerging threats, and cutting-edge security technologies.
Research and recommend new security tools and methodologies to enhance the security program.
Qualifications
Bachelor’s degree in computer science, Information Technology, or a related field.
7 to 10 years of experience in information security, with expertise in Assurance, Advisory, VAPT, Cloud Security, SecOps
Strong understanding of security principles, technologies, and methodologies.
Hands-on experience with security tools and platforms, such as vulnerability scanners, penetration testing tools, cloud security solutions, and SIEM systems.
Excellent analytical and problem-solving skills.
Strong communication and collaboration skills.
Ability to work independently and as part of a team.
Certifications
Relevant security certifications, such as CISSP, CISA, CISM, CEH, or OSCP, are preferred.
Additional Information
This position requires a high level of attention to detail and the ability to work under pressure.
The ability to work flexible hours, including occasional weekends and evenings, may be required