The Security Officer for Infrastructure & Operations helps deliver on the vision of I&O Security Management and is accountable for information security and compliance within the Global Infrastructure & Operations (GIO) scope. The role will assist in the development of long-term security strategies and manage its execution to ensure the IT services and functions meet all mandated security standards & policies and effectively assess & control security risks.
Requirements 'must have'
- 5+ years of experience in IT Security and other operational / compliance IT roles
- Broad technical security knowledge of IT services, technology and IT solutions
- Extensive experience in delivering IT security projects, assessments and audits
- Practical experience of risk management
- Experience in implementing Policies and Procedures in compliance with Information Security Management System Standards (ISO 27000 series)
- Strong knowledge of regulatory requirements and security policies and standards
- Profound knowledge of Information Security and Compliance standards (e.g. ISO 27001 / 2, GDPR, NIST, HIPAA, etc)
- Strong knowledge and understanding of networking & infrastructure security, both on premise and in cloud (IaaS)
- Excellent English (written & spoken) - other languages are a plus
Tasks :
Perform Risk assessments on : new projects, assets or ToolsManage Risk Register on compliance exemptions and risk acceptance (including expiry and renewal)Collaborate with the Security MSPs and the rest of security officers from other regions to deal with global emerging threats. Compliance managementProvide Security Reviews & Approvals on SNOW changesSecurity representation in zone CAB / E-CAB when requiredSecurity reviews of new demands and project charters :○ I&O projects (Global or Regional)
○ IITSC projects (with I&O components)
Support / drive Security initiatives (Global or Regional) Protect Security OperationsLead the Security operations related to the Network, this includes the following components :○ Firewall main configuration
○ IDS / IPS rules configuration
○ WAF default configuration and baseline
○ Proxy configuration
○ IoC lifecycle Detect Security Operations
Lead / Drive globally the vulnerability management processWork on Security Incident & Problem management