Job Description
Continuously monitor security systems, including firewalls, intrusion detection systems (IDS), and SIEM (Security Information and Event Management) tools. Identify, analyze, and respond to security breaches, incidents, and alerts, escalating when necessary. Maintain incident response procedures and ensure timely investigation and resolution of security events. Manage and enforce user access controls, including the creation, modification, and deletion of user accounts. Implement least-privilege principles and ensure compliance with role-based access control (RBAC). Conduct regular vulnerability assessments, scans, and penetration testing to identify and address weaknesses. Apply security patches and updates to operating systems, applications, and hardware promptly to mitigate risks. Maintain a patch management system to track and ensure timely implementation of patches across all systems. Develop, implement, and maintain organizational security policies, procedures, and standards. Ensure compliance with internal security requirements, industry standards (e.g., NIST, ISO 27001), and regulatory frameworks. Perform regular security audits and risk assessments to identify gaps and improve security posture. Educate employees on security best practices, including safe password management, phishing prevention, and data protection. Conduct security awareness training programs and phishing simulation exercises to reduce human error-related vulnerabilities. Provide guidance and support to staff on security-related issues, ensuring understanding and adherence to security protocols.Continuously monitor security systems, including firewalls, intrusion detection systems (IDS), and SIEM (Security Information and Event Management) tools. Identify, analyze, and respond to security breaches, incidents, and alerts, escalating when necessary. Maintain incident response procedures and ensure timely investigation and resolution of security events. Manage and enforce user access controls, including the creation, modification, and deletion of user accounts. Implement least-privilege principles and ensure compliance with role-based access control (RBAC). Conduct regular vulnerability assessments, scans, and penetration testing to identify and address weaknesses. Apply security patches and updates to operating systems, applications, and hardware promptly to mitigate risks. Maintain a patch management system to track and ensure timely implementation of patches across all systems. Develop, implement, and maintain organizational security policies, procedures, and standards. Ensure compliance with internal security requirements, industry standards (e.g., NIST, ISO 27001), and regulatory frameworks. Perform regular security audits and risk assessments to identify gaps and improve security posture. Educate employees on security best practices, including safe password management, phishing prevention, and data protection. Conduct security awareness training programs and phishing simulation exercises to reduce human error-related vulnerabilities. Provide guidance and support to staff on security-related issues, ensuring understanding and adherence to security protocols.