We have an urgent requirement for Security Configuration Compliance Analyst - Banking domain experience is required for one of our banking client in Oman
Strong Experience of 7 years in system administration and configuration hardening of Enterprise Infrastructure Must to apply for this role
Strong Experience on operating system hardening, security baselines, and configuration best practices (e.g., CIS Benchmarks, STIG Must apply for this role
Strong experience in translating security policies and standards into technical configurations is Must to apply for this role
Strong experience on Application Infrastructure, Data Integrity and Security, Enterprise Database Systems and Network Security is MUST
Configuration Hardening Documents Development and Maintenance.
- Develop, document, and maintain standardized Security hardening document across the IT infrastructure (e.g. OS, DB, middleware, Infrastructure applications)
- Reference the documents to industry best practices (e.g. CIS, STIG, and vendor specific hardening controls) to ensure the full coverage of the technology hardening.
- Ensure the documents accurately reflect organizational security policies and configuration baselines.
- Ensure the developed documents are accompanied with custom automated scripts, tripwire templates or any form of automated checks.
- Regularly review and update the hardening documents to incorporate new policies and industry best practices.
- Implement version control and change management processes for configuration hardening documents.
- Collaborate with policy owners to understand and interpret security policies and standards to perform necessary customization to hardening documents.
Systems Configuration Compliance Automation
- Work closely with IT operations teams to implement and maintain Tripwire configurations for various operating systems, databases, middleware and applications.
- Provide guidance and support to technical teams on the proper use and interpretation of Tripwire configuration templates.
- Develop and maintain scripts (e.g. Python, PowerShell and Bash) to define custom rules
Regularly review tripwire templates and custom scripts to ensure consistency with the hardening documents.
- Automate the deployment and management of custom Tripwire templates using scripting and regex.
- Troubleshoot and debug custom scripts to ensure accurate and reliable configuration monitoring.
- Translate policy requirements into specific scripts, Tripwire configuration rules and monitoring parameters.
Configuration Compliance Monitoring and Reporting
- Utilize Tripwire or scripts to monitor and report on configuration compliance status across the organization.
- Analyze Tripwire findings and identify systems that deviate from defined configuration baselines and policies.
- Communicate effectively with technical and non-technical stakeholders regarding configuration compliance status and remediation efforts.
- Generate regular and ad-hoc reports on configuration compliance posture for management and relevant stakeholders.
- Identify and address discrepancies between Tripwire configurations and organizational policies and baselines
Continuous Improvement
- Stay up-to-date on the latest security trends, best practices, CIS and STIG baseline updates and Tripwire product updates.
- Identify opportunities to improve the efficiency and effectiveness of Tripwire configuration management processes.
- Contribute to the development and refinement of configuration management policies and procedures.
Technical Expertise
- Participate in technical discussions by explaining/demonstrating attacks and explain the recommended hardening controls to IT.
- Collaborate with application developers, management and project management teams by reviewing and measuring the effectiveness of proposed security controls to be implemented before proceeding with the implementation.
- Identify best practices and continuously propose improvements to technical processes, procedures and guidelines in alignment with the bank’s standards.
- Plan and manage the execution of hardening document reviews and systems configuration hardening reviews.
Skills: application infrastructure,regex,enterprise database systems,cis benchmarks,scripting,powershell,compliance,data integrity and security,python,configuration hardening,security,configuration best practices,configuration,network security,bash,stig,tripwire,system administration,operating system hardening,security baselines