Conduct vulnerability assessment and penetration testing, including reporting and remediation plan. Coordinating with application and system owners for patch deployment.
Coordinating with security governance for security projects, PoCs, and enhancement.
Documenting, mitigating, and reporting security findings reported by ADSIC, internal stakeholders, etc.
Assist Technical Security in conducting regular network security assessments.
Involvement in security audits like ISO27001 and NESA.
Identify risk and network exposure including those related to malicious programs, viruses, improper system access, unauthorized systems, and improper network use.
Conducting self-assessment and risk assessment.
Maintain list of assets, ensuring updates and patches are deployed and working with technology vendors in troubleshooting and enhancement.
Update information security related documents like procedure, guidelines, baselines, asset register.
Maintain, operate, and manage security devices including the following devices but not limited to: Cisco Firewall, Cisco Wireless LAN Controllers, Cisco ACS 5.0, Cisco ISE, Cisco IronPort, McAfee NSM, Firemon Risk Analyzer, SIEM, Privilege Access Management Software, Vulnerability Scanner.