Source description
About the role
Ability to perform risk analysis on the network architecture and identify threat, vulnerability and risks
Good understanding of cloud network and on-premises network security solutions like Firewalls, VPC, network segmentation, security groups, IPS/IDS, WAF, NAC, Web proxy, and load balancers etc.
Conduct risk assessments and security evaluations of network services and on-prem and cloud infrastructure
Identify and assess threats, vulnerabilities, risks and potential attack vectors and prioritize the mitigation
Assess and manage IT risk treatment in all new projects or infrastructure within its scope (integration of security into projects, secure by design processes)
Enforce Group policies / standards and/or procedures / good security practices within its department.
Develop and implement risk mitigation strategies and security controls
Drive security program such as Pen test and Vulnerability programs globally
Evaluate security configurations, policies, and procedures
Perform security validations and exceptions for different need on day to day basis (AV , Browsing exceptions, RAF, admin rights, firewall flow, secure share etc.);
Assess compliance with industry standards and regulatory requirements (e.g., NIST, SOC 2, PCI-DSS, OWASP)
Communicate risk and security recommendations to stakeholders
Contribute to security audits (internal audit / regulators) within its scope
To act as a security expert and point of contact on all the operational security and risk management activities
CCNA/CCNP Certification
Network Security Certification in Cloud platforms Azure -( SC-100 & AZ-500) and AWS Security Certifications
More at Societe Generale