When you're a part of our team, you'll see how we bring good energy to our business and our employees. Together, we will support our corporate strategy, high standards and the communities where we live and work. Our collaborative approach, commitment to diversity and inclusion along with our safety-first culture helps reinforce our internal brand position where People Matter. That's why we're dedicated to the development of our employees, so that they can reach their career goals.
What you can expect in a typical day:
The Senior Cyber Security Specialist is a critical member of the Information Technology Security and Compliance team. The role acts as an interface between the Director, IT Security, the North American Cyber Security team and the technology assets in Ireland including Whitegate refinery and Top Oil IT. The role is accountable for supporting delivery of the cyber risk-based programs including technology threat risk assessment process, 3rd party risk assessments, insider threat as well as providing consultative services and executing activities to deploy, operate and maintain cyber security technical controls in full compliance to our policies and standards. The role must be able to translate IT-risk into business focused language for our stakeholders identifying required technical controls and infrastructure priorities, as well as develop metrics for ongoing performance measurement and reporting. This role acts as the liaison between business entities within Ireland and the cyber security team and will include acting as the key liaison between IT and the business for regulatory compliance activities associated with the NIS Directive and PIC Compliance.
The role can be based at the Whitegate Refinery or Top Oil offices in Dublin.
Key Responsibilities:
- Participate in the corporate vulnerability management program by conduct vulnerability assessments, assessing criticality and assist in the mitigation of controls to address identified vulnerabilities
- Liaise with our Manages Security Service Partner Security Operation Center for all European assets, ensuring asset visibility, defining priority use cases and responding to alarm escalations.
- Participate as a member of the CIRT and run appropriate defensive protocols if a breach/attack occurs
- Conduct testing to identify vulnerabilities and collaborate with cybersecurity team to update defensive protocols when necessary
- Conduct threat and risk analysis and analyze the business impact of new and existing systems and technologies to eliminate risk, performance, and capacity issues
- Support the execution of the enterprise cyber security awareness activities, including the performance of regular phishing tests and the execution of annual mandatory training
- Develop, maintain and support the implementation of enterprise IT and Cyber Security policies, standards, and procedures.
- Support the execution of the enterprise & IT risk governance framework, including performing risk and control assessments, maintenance of the enterprise IT & Cyber Security risk register, and monitoring and reporting on the remediation status of identified risks
- Perform research, testing, evaluation, and deployment of security technology and procedures
- Support internal and external audits through interfacing with internal & external auditors
- Evaluate and support the documentation, validation, assessment and reporting processesnecessary to ensure compliance with PCI-DSS, NIS Directive and other applicable industrystandards, regulations, and frameworks
- Engage all relevant stakeholders in managing the corporate cyber security program
- Conduct internal technical and procedural information security assessments to identifyvulnerabilities and propose appropriate remediation
- Implement security improvements by assessing the current threat and security situation,evaluating trends in key security indicators and anticipating change in the risk profile
- Coordinate the process of identifying and implementing information security requirements relatedto privacy to achieve and maintain required compliance
- Optimize and tune existing security tools, identify required upgrades to security systems and workwith appropriate teams to implement and maintain security controls
- Maintain professional and technical knowledge by attending educational workshops, reviewingpublications and participating with relevant Security Focus groups
- Knowledge of IT and OT (ICS) technology and cyber security would be considered an asset
What you’ll need to succeed:
Professional skills
- Excellent social, communication and relationship building skills
- Ability to interface at all levels
- Ability to establish priorities and develop critical tasks
- Organized and able to prioritize effectively
Education and experience
- A minimum of 10 years IT experience, with 5 years in an information security role
- A technical bachelor's degree, preferably in Computer Science, or equivalent work experience
- Cyber Security Certifications: CISSP, CISM, GIAC, CRISK
- A strong understanding of cyber security operations and technology and compliance
- Experience with Cyber Risk Management programs
- Strong leadership abilities, with the capability to work with minimal supervision
- Excellent verbal, written and interpersonal communication skills, including the ability to communicate effectively with the IT organization, project and application development teams,management and business personnel
- Experience working with legal, audit and compliance staff
- Experience with common information security management frameworks, such as InternationalStandards Organization (ISO) 2700x, NIST Cyber Security Framework as well as recognized riskframeworks such as ISO 31000
Irving Oil supports a diverse and inclusive work environment and welcomes applications from all qualified applicants.