The Information Security Engineer will be responsible for evaluating, testing, and integrating security tools, standards, and processes as per the security framework. They will identify, prioritize, and track security incidents and manage related platforms, including SIEM, DLP, and EDR.
Requirements
- Evaluating, testing, and integrating security tools, standards, and associated processes as per the security framework
- Identify, prioritize, and track security incidents and manage related platforms such as SIEM ( Wazuh, Blusapphire, Qualys ), DLP ( Email and Application), EDR and other security tools
- Improving and supporting application security tool deployments including static analysis and runtime testing tools
- Create and manage process to guide development and testing teams on proactively finding application security risks
- Improving and maintaining secure development standards
- Conduct periodic penetration testing services of application and Network related infrastructure
- Assess application, design threat models, risk, document potential risk vectors, recommend relative controls and ensure risk is addressed
- Maintain security risk register to track the identified risks and produce metrics to report the state of application security program and risk status
- Define hardening standard for various technology and assess compliance levels
- Provide clear communication on the issue to application owners and verify the efficacy of vulnerability remediation
Benefits
- Competitive salary
- Opportunities for career growth and professional development
- Collaborative and dynamic work environment