Responsibilities:
• Apply defense-in-depth concepts and information security controls (Administrative, Technical, Physical, Operational, Deterrent, and Compensating controls) within day-to-day security activities.
• Own technical implementation, configuration, and optimization of security technologies: IAM/PAM, NAC/TACACS, DLP, NDR/EDR, Sandboxing, Email Gateway, MDM, and SIEM (advanced query writing and use-case development).
• Support compliance activities related to information security frameworks and standards such as IS027001, SOC2 Type II, and ISO27701.
• Manage and track different audit missions and provide the support needed to stakeholders in the remediation plan.
• Develop and review information security and corporate policies and processes to ensure alignment with information security standards and regulations.
• Execute and support the information security awareness program, including security awareness trainings, phishing simulation campaigns, and security awareness sessions.
• Assess new user access requests and review existing access permissions against the least privilege and need-to-know principles
• Support information security assurance activities and risk management practices.
• Track and follow up on vulnerability remediation efforts in collaboration with IT, engineering, and operations teams.
Requirements:
• Bachelor's degree in engineering Or computer science.
• 7+ years of relevant experience
• GRC-related certification (e.g., CISSP, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor) is preferred.
• Strong understanding of information security & IT governance frameworks of and standards such as ITIL, PCI, SOC2 Type II, ISO27001.
• Strong knowledge of user access governance, including assessing new user access requests and reviewing existing access permissions against the least privilege and need-to-know principles.
• Basic knowledge of information security assurance activities and risk management practices
• Familiarity with cloud computing platforms and cloud security principles.
• Excellent written and verbal communication skills, with proven ability to produce clear, high-quality security documentation and reports.