Who We Are:
Novelus Team is a group of innovative people, excessively focused on accelerating technology deployment. Our most important asset is our employees, which is why we focus on providing a progressive, vibrant and empowering culture.
Why Novelus:
This is a great opportunity to be part of a company with record growth. Novelus employees enjoy a comprehensive set of benefits, including but not limited to:
- Friendly and collaborative work environment
- Personal and professional growth opportunities
- Exposure to dynamic projects and the latest technologies
Who We're Looking For:
- Operate the accepted security controls, identify and triage security events, coordinate response and remediation, and maintain evidence of compliance with Company-approved security requirements.
What You’ll Do:
- Review assigned EDR and security-monitoring alerts, validate suspicious activity, investigate affected users or devices, and escalate incidents under the agreed severity and response process.
- Administer approved endpoint policies and controls. Perform containment actions within delegated authority and obtain required approval for disruptive or irreversible changes.
- Review perimeter security configurations and proposed changes with the infrastructure team. Identify weak rules, access exposures and configuration gaps for authorised remediation.
- Run approved vulnerability assessments within agreed assets and windows. Validate findings, prioritise them by exposure and business impact, assign owners and verify remediation.
- Support privileged-access reviews, security baseline checks and compliance evidence. Maintain an exception register and report unresolved risks to the designated owner.
- Assist with security gap assessments, risk assessments, control implementation and policy updates within the agreed IT scope.
- Maintain audit evidence, support internal and external audits, and track corrective actions to closure
What You’ll Need:
- 3–5 years in security operations, including hands-on endpoint security, incident handling, vulnerability assessment and remediation coordination. Experience protecting enterprise users, servers and networks is preferred. Prioritise deployed EDR, SIEM and firewall vendor training, vulnerability analysis and incident-response exercises. Microsoft Certified Security Operations Analyst Associate, associated with SC-200 [4], is relevant when Microsoft security tools are used. Add security governance learning as responsibilities expand.
- Practical EDR, SIEM and firewall knowledge; Windows and Linux security fundamentals; incident investigation; vulnerability interpretation; and risk-based remediation. Working knowledge of ISO/IEC 27001, Information Security Management Systems (ISMS), and Governance, Risk and Compliance (GRC) practices, including risk assessments, security controls, compliance reviews, audit evidence preparation, policy and procedure management, control-gap identification, corrective-action tracking, and support for ISO 27001 certification and surveillance audits. Clear technical reporting, evidence handling, risk-register maintenance, and collaboration with infrastructure, application, compliance and audit teams are essential.