We're Hiring: IT Security Consultant (ITSO)!
IT Security Officer (ITSO)
Role Overview
We are looking for an experienced IT Security Officer (ITSO) to support infrastructure security, security governance, risk management, incident response, threat monitoring, and security compliance. The role will involve working closely with internal stakeholders, external vendors, security partners, and relevant government/security organisations to maintain and strengthen the security posture of the IT environment.
Key Responsibilities
- Develop, maintain, and periodically review IT security policies, procedures, and security action plans.
- Assess and recommend appropriate IT security products, solutions, and technologies for infrastructure environments.
- Implement and manage security risk assessment methodologies in line with relevant service management requirements and industry standards.
- Develop and maintain security management frameworks, governance structures, and security controls.
- Establish and manage IT security incident management processes, including security incident detection, response, investigation, and resolution.
- Coordinate with external partners, vendors, and service providers to resolve security incidents and security-related issues.
- Participate in security incident response simulations, technical assessments, and security exercises.
- Conduct forensic investigations when required, including secure disk image acquisition and analysis.
- Monitor and analyse emerging security threats, vulnerabilities, and security solutions relevant to the IT infrastructure.
- Conduct regular security reviews with key stakeholders, communicate security risks and issues, and recommend appropriate improvements.
- Liaise with external suppliers, security organisations, and government/security authorities on IT security matters.
- Review and follow up on security reports generated by central security monitoring tools, ensuring timely investigation and remediation.
- Manage and maintain the IT asset inventory required for security monitoring and ensure servers, networks, databases, and other relevant assets are properly onboarded to central security tools.
- Support additional security activities and initiatives required to strengthen the organisation's overall IT infrastructure security posture.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related discipline.
- Proven experience in IT security, cybersecurity, or infrastructure security.
- Strong understanding of information security principles, security best practices, risk management, and security governance.
- Hands‑on experience with a range of security tools and technologies.
- Knowledge of security incident management and incident response.
- Familiarity with digital forensics and forensic investigation techniques/tools.
- Strong analytical, troubleshooting, and problem‑solving skills.
- Good written and verbal communication skills.
- Ability to work independently as well as collaboratively with internal teams and external stakeholders.
- Experience working with external vendors, suppliers, security partners, or service providers on security‑related matters.
Desired Certifications
- CISSP– Certified Information Systems Security Professional
- CISM– Certified Information Security Manager
- GCIH– GIAC Certified Incident Handler
Experience Level
- Associate Consultant: Less than 4 years of relevant IT security experience
- Consultant: 4–6 years of relevant IT security experience
- Senior Consultant: 7+ years of relevant IT security experience
Key Skills / Keywords
IT Security | Cybersecurity | Infrastructure Security | Security Governance | Security Risk Assessment | Security Policies | Security Frameworks | Incident Management | Incident Response | Threat Monitoring | Vulnerability Management | Digital Forensics | Security Tools | Security Compliance | IT Asset Management | Security Operations | Risk Management | Vendor Management | Security Assessments | CISSP | CISM | GCIH