← к выдаче
безопасность

GRC Cyber Consultant

сегодня

Описание от работодателя

Requirements: 3+ years in IT security and compliance Extensive, practice-based knowledge of security management frameworks, such as ISO 27k series, GDPR, SOC2 etc.; Proven track record of IT security audits/projects implementation Ability to develop information security policies, setup ISMS and guidelines, implement CIS20 and derive security requirements from them; Understanding access modelling. Ability to develop access models and assess them. Understanding of segregation of duties Experience in IAM & SSO solutions. Understanding of purpose and approaches of IAM. Knowledge of key tasks: identify, authenticate, and authorize Good knowledge of risk management, its purpose, and approaches. Ability to evaluate risks and create a risks management plan Understanding OWASP Top 10. Ability to describe vulnerabilities, ways of exploitations, and fix methods Understanding and implemented of vulnerability & patch management. Knowledge in vulnerability scanners. Ability to validate scan results and provide recommendations Ability to develop and conduct security trainings and workshops Good level of professional English Good communication skills, responsible, initiative, self-organized, eager to learn Experience in Secure SDLC or AWS Security would be a plus Responsibilities: Conduct security audits and consulting projects, create an action plan & practical roadmap based on the audit results Develop and enhance an information security management framework to ensure business sustainability Build and maintain compliance guidelines. Create policies and standards for IT security and compliance Conduct general IT security awareness training for the company staff Evaluate and manage corporate risks related to IT security Build and maintain application-specific threat models, explicitly apply security principles to design Participate in the corporate certification and compliance activities Design and implement security architecture and detailed cybersecurity designs together with IT and software development departments Prepare and document standard operating procedures and protocols Cooperation with Account Management, Sales & Marketing, Legal, Delivery and Clients for all security-related topics (audits, contractual compliance, reviews, risk assessments, etc.) Keeping up to date with developments in IT security standards and threats