Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
IDEMIA Public Security seeks a cybersecurity specialist to perform security risk assessments and enhance security measures across various technologies. The ideal candidate will have significant experience in security assessments, risk management, and a strong understanding of cybersecurity tools and frameworks. This role involves collaboration with IT teams and requires occasional travel to customer sites for reviews and implementations.
IDEMIA Public Security, a division of IDEMIA Group, is the premium provider of trusted biometric solutions that revolutionize public security and identity, travel and transport, and access control. Our solutions—designed using advanced security features and encryption technologies—enable our clients to build safer and fairer societies where people can live, interact, and move freely.
This specialist role requires technical expertise across multiple cybersecurity verticals and technologies to perform security risk assessments, security operations, and security architecture reviews, ensuring compliance with cybersecurity and risk requirements for our solutions.
Work with partners to conduct and review comprehensive security assessments and penetration tests for customer ICT systems in on-premises and managed hosting environments.
Identify security and compliance gaps, perform threat risk assessments, and propose mitigating measures.
Standardize and refine security incident response and escalation processes.
Develop and recommend appropriate mitigation countermeasures in operational and non-operational situations.
Collate data points from stakeholders for security scorecard reporting and provide actionable insights.
Collaborate with the IT Infrastructure team to evaluate, implement, and enhance security measures such as network perimeter security, endpoint security, SIEM, patch management, MFA, and Privileged Access Management (PAM).
Coordinate with the Software team for security assessments including SAST, DAST, Source Code Review, Software Composition Analysis, and Secure Configuration Review.
Monitor security alerts, triage, mitigate, and escalate issues promptly.
Provide regular security advisories to stakeholders.
Manage IT security aspects across various domains including network, server, application, endpoint, email, physical, and logical access security.
Stay updated on IT/OT security advancements and introduce relevant enhancements to client systems.
Travel to customer sites as needed for cybersecurity reviews and implementations.
Degree or Diploma in engineering, science, or information technology or equivalent.
Preferably 5 years of experience in cybersecurity analyst/engineer roles.
At least 3 years of proven experience conducting security assessments using tools and methodologies such as OWASP, NIST, MITRE ATT&CK, and industry frameworks.
Strong knowledge of security risk management, governance, compliance, and assessment techniques including vulnerability assessments, penetration testing, and secure configuration reviews.
Basic understanding of security standards like NIST, ISO/IEC 27001/2, CIS Controls, PDPA. Knowledge of IM8 is a plus.
Proficiency in at least 3 of the following security tools:
Next Generation Firewalls (e.g., FortiGate, Palo Alto, Cisco FirePower)
Tenable Security Center
Endpoint Protection (e.g., Trellix, SCCM, Ivanti)
Data Loss Prevention
SIEM (e.g., Splunk, Elastic)
Python
Ansible