Cyber Security Lead Analyst
Cyber Security Lead Analyst
Role & Responsibilities
Performing security aspects of a portfolio of banking service platforms and applications by implementing/contributing compliance projects to the functional and technical team.
Assisting functional and technical teams throughout the major evolutions on platforms and applications. This focus will be a big part of the scope of work and requires understanding of the architecture, functionalities, and security policies.
Follow compliance level of Applications adhering to global audit and regulatory programs (ECB Audit, NIST, GDPR Compliance, NYDFS & SECAIA).
Expertise in Third Party Risk Management (TPSRM), including its processes, controls, and compliance requirements.
Improve and maintain the level of security of applications and platforms, in compliance with regulatory requirement and SG group security criteria.
Collaborate with application team and technical teams, to deploy, troubleshoot and maintain required security solutions with compliancy to security criteria.
Responsible for report preparation on BAU, key programs and maintain a good level of communication with different stakeholders of the projects.
Plan, organize and insure follow up actions and action plans, therefore being autonomous is a must for this role.
Independently perform Application Security Assessment (ASA), Security control assessment and provide security recommendations.
Perform risk review and work on derogation// ad-hoc request validations. Also maintain risk acceptance documents as per the group guidelines.
Drive Secure by design throughout SDLC of the applications.
Demonstrate and train teams on Secure by design and latest security technologies.
Profile Requirements
6 to 8 years of experience in the field of IT security with good Knowledge in information security.
Able to understand architecture issues in order to develop security policies or relevant recommendations on applications and projects. Also, should be able to discuss on an equal footing with the community of architects and project managers of the applications concerned.
Good knowledge on SDLC and hands-on experience in Security Environments and activities.
Knowledge on Application Security/ Vulnerability Management/ Cloud Security/ Thread modeling.
Awareness of digital technologies and understanding of functional domain and business processes.
Good in identifying & proposing process improvements, documentation preparation and consolidation on process/technical subject related to Security.
Knowledge on Cloud an network Security,IAM, Data encryption, SIEM.
Understanding on regulatory programs like GDPR, NYDFS, SCHREMS, DORA etc...
Knowledge on Cloud, Infra, Firewalls, Routers and Wifi
Exposure to JAVA, API, ASP.Net, Spark, Python, react.js languages and technologies respectively.
Exposer on security Tools - Qualys, Nessus, Nmap, Burp suite, SonarQube, netspaker, OWSAP, Open-Source tool for Security Tests.
Proper Work Ethics, Adaptability, Interpersonal skills and Problem-Solving Capabilities.
Mandatory Skills
Application Security/ Vulnerability assessment and penetration testing/ Risk Management/ Cloud Security/ API Security/ Vulnerability management/DevSecOps
Customer/ Business interactions
Good communication skills with negotiation and influencing skills. Especially the ability to persuade and influence others.
Additional Qualifiers
Security Certificate such as CISSP, CISA, CRISC, CEH, GISF, SSCP.
Worked on Risk Analysis and Security Recommendation. DB Security Testing.
Worked on Application Security Management/ Application Criticality
Development knowledge. Worked in SDLC.
Expertise in development of Rest web services and APIs
Experience in working on projects in Agile Methodology
Abilities/Skills required
Good in Customer/ Business/stakeholder interactions
Strong customer service ethos
Logical, structured approach to planning, problem solving and decision-making.
Self-starter with ability to manage own workload and deliverables along with others.
Excellent analytical skills.
Ability to be flexible, organize and prioritize work.
Attention to detail, plus excellent organizational and time management skills.
Highly developed relationship management skills.
Ability to work under pressure and to fixed deadlines.
Out of box thinking.
Quick understanding of upstream and downstream linkage.
Teamwork & Team-spirit