Job description summary:
BCA is looking for anIT Security Officer(Consultant) to strengthen oursecurityoperations and governance. In this role, you will overseesecurityvendors, manage testing cycles, and provide expert consultancy — ensuring that government systems remain resilient against evolving cyber threats.
What the officer will be working on:
- Managesecurityvendors and deliverables.
- Manage periodicsecuritytesting.
- Assess mitigation/remediation for adequacy and effectiveness.
- Manage timely and effective mitigation/remediation.
- Reviewsecurityreports.
- Reviewsecuritypolicies, standards, procedures and guidelines.
- Providecybersecurityconsultancy.
- Respond tosecurityalerts/advisories.
- Handling incidents.
- Conductsecurityawareness training.
- Broadcast emailsecurityadvisories.
Job requirement:
- Bachelor's degree in Computer Science, Information Technology,Cybersecurity, or a related field.
- Minimum of 4-7 years of experience incybersecurityanalyst or similar role.
- Strong understanding of network protocols, operating systems (Windows, Linux), and cloudsecurityconcepts (AWS, Azure, GCP).
- Proficiency withsecuritytools such as vulnerability scanners, penetration testing tools, and SIEM platforms.
- Experience with scripting languages (e.g., Python, PowerShell) for automation.
- Familiarity withcybersecurityframeworks and standards (e.g., NIST, ISO 27001).
- Excellent analytical and problem-solving skills with a strong attention to detail.
- Ability to work independently and as part of a team in a fast-paced environment.
- Strong written and verbal communication skills, with the ability to articulate technical information to non-technical audiences.
- Proven ability to manage multiple tasks and prioritize effectively.
- Require CISSP and/or CISM certification.
What are we looking for:
- Enthusiasm for learning and development of skills incybersecurity.
- Strong analytical capability.
- Understanding of the vulnerabilities listed in the Open Web ApplicationSecurityProject (OWASP) Top 10.
- Understanding of incident management and handling.
- Experience in software development orsecurityoperations is preferred.
The following certifications are advantageous but not mandatory:
- GIAC Certified Incident Handler (GCIH)
- CompTIASecurity+
- CompTIA CySA+
- EC-Council CertifiedSecurityAnalyst (ECSA)
- EC-Council Certified Ethical Hacker (CEH)
- (ISC)2 SystemsSecurityCertified Practitioner (SSCP)
- OffensiveSecurityCertified Professional (OSCP)