Information Technology Security Officer
The Information TechnologySecurity Officer will support the cybersecurity governance, assurance, andsecurity management activities across security architecture, vulnerability assessment and penetration testing,risk assessment, system hardening, cloud security posture management,software clearance, firewall and network deviation management, cybersecuritypolicies and standards, and security metrics reporting. The officer will coordinate security reviews and assessments, maintaincybersecurity registers andtrackers, follow up on remediation and outstanding actions with relevantstakeholders, prepare security reports and management dashboards, and supportthe upkeep of cybersecurity policies, standards, specifications, anddocumentation. This role requires strongcoordination, analytical, documentation, and stakeholder management skills,with a good understanding of enterprise cybersecurity controls, riskmanagement, and governance processes. Roles and Responsibilities Security Architecture · Assist in maintaining security architecture diagrams, records, and approveddesign documentation. · Track security architecture review requests and coordinates input from project teams andrelevant stakeholders. · Maintain records of architecture decisions, recommendations, and approveddesigns. · Support preparation of security advisorymaterials and architecture review documentation. Vulnerability Assessment & Penetration Testing · Coordinate and scheduleVAPT engagements with system owners,vendors, and security testers. · Maintain the VAPT tracker and follow up on remediation of identified vulnerabilities. · Coordinate re-testing activities and update findingclosure status. · Assist in preparing VAPT reports, summaries, and presentation materials. Risk Assessment · Coordinate cybersecurity risk assessment exercises with system ownersand stakeholders. · Maintain the cybersecurity risk register and track risk treatment and remediationactions. · Support preparation of risk reportsand management reviewmaterials. · Facilitate risk acceptance, exception, and approvalprocesses in accordance with the requirements. Hardening Compliance · Coordinate security hardening compliance assessments with system and infrastructureteams. · Track hardening gaps and followup on remediation progress. · Maintain hardening compliance records, checklists, and trackers. · Support preparation of periodic hardeningcompliance reports. Cloud SecurityPosture Management · Monitor and triagefindings generated by CloudSecurity Posture Management tools. · Track cloud securitymisconfigurations and followup on remediation with system andcloud owners. · Maintain CSPM findingsand remediation statusrecords. · Prepare periodic cloud security posture reports and summaries. Software Clearance · Receive, log, and track softwaresecurity clearance requests. · Coordinate with requestors and vendors to obtain requiredtechnical and security documentation. · Maintain the softwareclearance register and approval status. · Support preparation of software securityevaluation summaries and monitor expiring clearances. Firewall & Network Deviation Management · Receive, track, and maintain firewallrule change and network securitydeviation requests. · Follow up with requestors and network teams on outstanding actions and expiring deviations. · Maintain deviation registers and prepare reviewsummaries for approval. · Coordinate periodic firewallrule and networkdeviation reviews with relevant teams. Policy, Standards & Governance / Cyber Specifications · Assist in drafting, reviewing, and updatingcybersecurity policies, standards, guidelines, and procedures. · Maintain the cybersecurity policy and standards documentation repository. · Track document reviewcycles, approvals, and expirydates. · Support preparation and review of cybersecurity specifications for projects,procurements, and tenders. Security Metrics & Reporting · Collate and consolidate cybersecurity data and status updatesfrom relevant teams andsystems. · Maintain cybersecurity dashboards covering vulnerabilities, risks, deviations,compliance, and audit items. · Prepare routine securitymetrics and management reports. · Follow up with responsible partieson outstanding cybersecurity actions andremediation items. Security & Compliance · Ensure activities are performed in accordance with the Board'scybersecurity policies,applicable regulatory requirements, and the Cybersecurity Code of Practice(CCoP). · Support cybersecurity assessments, internal and externalaudits, and evidence collection activities. · Maintain accurate and up-to-date cybersecurity records, reports, registers, and supporting documentation. · Protect sensitive and security-classified information in accordance with the Board's requirements. Technical Requirements Mandatory Technical Skills · Good understanding of enterprise cybersecurity concepts, including vulnerability management, securityrisk assessment, systemhardening, firewall controls, cloud security, and security governance. · Experience coordinating cybersecurity assessments, remediationactivities, and security review processesinvolving multiple technical and business stakeholders. · Ability to review and understand vulnerability assessmentfindings, security risk assessments, security architecture diagrams, firewall rules,and security compliance reports. · Familiarity with securityframeworks, policies, standards, and cybersecuritygovernance processes. · Strong analytical, documentation, stakeholder coordination, and follow-up skills. Good-to-Have · Familiarity with CSPM platforms and cloud securityconcepts across AWS, Azure, or equivalent cloud environments. · Experience with vulnerability management or VAPT tools and interpretingCVE/CVSS information. · Understanding of enterprise network architecture, firewallrules, security zones,and network segmentation. · Experience supporting cybersecurity audits, governance, risk, and compliance activities. Certifications · CompTIA Security+, ISC2 Certified in Cybersecurity (CC),or equivalent foundationalcybersecurity certification is highly preferred. · Certified Information SystemsSecurity Professional (CISSP),Certified InformationSecurity Manager (CISM), or equivalent will be advantageous. · Certified in Risk and Information Systems Control (CRISC),ISO 27001-relatedcertification, or equivalent risk/governance certification will beadvantageous. · Relevant cloud securitycertification such as Microsoft Azure Security, AWS Security, or equivalent will beadvantageous.