Job summary: ( خلص وظیفه)
The IT Security Specialist will function as the overall security expert for the enterprise IT environment. This includes oversight of security projects, facilitation of security and audit assessments, IT systems hardening and security best practices, compliance programs, vulnerability remediation, security scanning and reporting, disaster recovery preparedness, and change management.
The individual will report to Chief Information officer / Deputy Chief Information Officer..
Job Description: (شرح وظیفه)
Ø Function as the overall security expert in the enterprise.
Ø Protects system by defining access privileges, control structures, and resources by conducting periodic vulnerability and security risk assessments and scans of IT Infrastructure.
Ø Defines, recommends and manage security configuration and operations standards for security and information systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems.
Ø Defines and validates baseline security configurations for operating systems, applications, databases, networking and telecommunications equipment.
Ø Determines security violations and inefficiencies by conducting periodic audits.
Ø Liaison to Networking to ensure security in architecture and technology changes.
Ø Ensure endpoint security and adherence to approved data policies as per DAB norms and regulatory standards for business, technology and procedural changes.
Ø Identifies and makes recommendations regarding critical points of failure. Recommends changes required to expand recovery plans
Ø Maintain and update the IT Incident Response Plan. Works with teams to resolve issues that are uncovered by various internal and monitoring tools.
Ø Develops, refines and implements of enterprise-wide security policies, procedures and standards to meet compliance responsibilities. Monitor compliance programs according to policies and procedures for breaches or exposure.
Ø Provides security support for application- and infrastructure related projects to ensure that security issues are addressed throughout the project life cycle.
Ø Focus on security for emerging technologies in internet channels.
Ø Assists in the development and implementation of information security disaster recovery test plans.
Ø Monitors the legal and regulatory environment for recent developments.
Ø Ensures recovery drills are performed and analyzes performance.
Ø Develops and delivers IT risk & security awareness and compliance training programs.
Serve as systems security advisor to the CIO or Deputy CIO.