Position: Associate

Job type: Full-time

Salary: View Detail

Loading ...

Job content

Position Overview This role shall be responsible for supporting the information security agenda for ISS, with a primary focus on physical security and cybersecurity along with a secondary focus of local business continuity coordination. As part of the Information Security Office, this role will work closely with technology functions to identify areas of greatest risk and supporting initiatives to keep the information security and technology risk profile within appetite. This role includes responsibilities for interacting with internal customers at ISS and with internal and external audit functions responsible for managing compliance testing of control requirements. This role will report up through the Chief Information Security Officer who is based in the United States.

Responsibilities
  • Gain/leverage familiarization with, and perform administration for, ISS’ Security Tools and Technologies from McAfee and Cisco:
    • ePO o Anti-Malware solution
    • Intrusion Prevention Systems – Network-based (Cisco FirePOWER) o Intrusion Prevention Systems – Host-based (McAfee ENS Firewall)
    • Web Gateway and URL Filtering (Cisco Umbrella & McAfee Unified Cloud Edge)
    • Cloud Access Security Broker (SkyHigh/McAfee MVISION)
    • Email Gateway (Mimecast) o Endpoint Protection Suite (McAfee ENS)
    • Security Information and Event Manager (SIEM – McAfee ESM
    • Reporting and Metrics
  • Operational Activities
    • Administer SPAM protection utilities contained within the Email Gateway; configure sender and domain blacklists, maintain tracking for all reported emails.
    • Administer Web Gateway (URL Filtering); manage whitelist modifications, reporting and metrics.
    • Coordinate and perform reporting and monitoring functions on the Security Information and Event Manager (SIEM) in place within the ISS enterprise.
    • Create security baselines for workstation, desktops, network devices and database technologies. Audit assets for adherence with the documented baselines.
    • Monitor security vulnerability repositories and relevant security news websites for relevant bugs and news items.
    • Coordinate appropriate updates to the local business continuity plan from a business and technology perspective.
  • Administration, monitoring and management of the firm’s Physical Security Infrastructure:
    • Program and configure hardware objects, alerts, reports, personnel, templates, etc., using the firm’s CCure Physical Access Control Servers.
    • Manage overall server health and operational effectiveness.
    • Audit badge access and operator activities; generate reports as required.
    • Respond to escalations from badge system administrators regarding clearance issues.
    • Perform quarterly physical access audits for local and remote offices. (No travel required.)
    • Monitor physical security alerts; responding and escalating as appropriate
    • Monitor CCTV alerts; responding and escalating as appropriate.
  • Other appropriate duties as assigned to drive forward progress for the firm.

Desired Experience And Qualifications
  • 3-5 years of Physical Security and/or Cybersecurity experience
  • 2-5 years of experience with Mimecast, McAfee endpoint and proxy products, Umbrella Web Protection, SIEM, anti-malware and other tools is preferred.
  • 3-6 years of experience with establishing and monitoring information security controls
  • ISO 27001 experience is preferred
  • Certification(s) such as CISSP, CISA, CISM, CASP, Security+ preferred
  • Have a good and relevant IT degree
  • Have a high-level of risk intelligence and security awareness
  • Have strong analytical, organizational, and decision-making skills
  • Have strong verbal and written communication skills. Must be able to interface and coordinate work efficiently and effectively with ISS personnel in locations around the globe.
  • Strong administrative skills, with effectiveness in developing tasks and managing time and resources to achieve target dates.
  • Be able to balance hands-on skills with consultancy skills.
  • Must be a productive team player.
  • Strong computer skills (Microsoft Word, Excel, PowerPoint, Outlook, etc.)
  • Off-hour/on-call support may be required.
  • Occasionally may be required to shift work hours to align with the US business day.

Loading ...
Loading ...

Deadline: 20-06-2024

Click to apply for free candidate

Apply

Loading ...
Loading ...

SIMILAR JOBS

Loading ...
Loading ...