Job Overview
- Experience Level
- +3 years
- Employment Type
- Full-time
- Workplace Type
- In office
- Location
- Not specified
- Job function
- IT & Tech
- Application Deadline
- 12 June 2025
About the Role
Security Design and Architecture:
o Design and implement robust security architectures that encompass network, application, and data security.
o Develop and enforce security policies, standards, and procedures to ensure the protection of information systems.
Software Security:
o Implement secure software development lifecycle (SDLC) practices, including secure coding standards, code reviews, and vulnerability assessments.
o Work closely with development teams to integrate security into the software development process.
o Conduct security testing of applications, including static and dynamic analysis, and penetration testing.
o Identify and address software vulnerabilities and provide guidance on secure coding practices.
o Develop and maintain tools and frameworks for automating security testing and compliance.
Risk Assessment and Vulnerability Management:
o Conduct comprehensive security assessments, including penetration testing, vulnerability scanning, and threat modeling.
o Identify and assess vulnerabilities and security risks, and develop mitigation strategies.
o Collaborate with development and operations teams to prioritize and remediate vulnerabilities.
Incident Response and Management:
o Lead and coordinate incident response activities, including detection, containment, eradication, and recovery.
o Perform post-incident analysis to identify root causes and implement preventive measures.
Security Monitoring and Operations:
o Implement and manage security monitoring tools, such as SIEM systems, IDS/IPS, and firewalls.
o Analyze security logs and reports to identify suspicious activities and potential security breaches.
Compliance and Audit Support:
o Ensure compliance with relevant regulations and standards, such as ISO 27001, PCI DSS, NIST and GDPR.
o Support internal and external audits by providing necessary documentation and evidence.
Requirements
- Bachelor’s or Master’s degree in Communication Engineering, Computer Science, Information Security, Cybersecurity, or a related field.
- 3-5 years of experience in information security, with a focus on security engineering and software security.
- Strong knowledge of security technologies, including firewalls, encryption, IDS/IPS, SIEM, and endpoint protection.
- Extensive experience in secure software development, application security, and threat modeling.
- Familiarity with secure coding practices and security testing methodologies.
- Relevant certifications such as CISSP, CEH, OSCP, or similar.
- Experience with cloud security, network security, and application security.
- Excellent problem-solving skills and the ability to handle complex security challenges.
- Strong communication skills, with the ability to explain technical concepts to non-technical stakeholders.