Career Level: 5 | Career Family: Digital and Technology | Career Sub-Family: IT Security
The role also supports cyber security projects, security reviews, SOC activities, incident response and the secure adoption of emerging technologies including Artificial Intelligence.
Experience
At least 5 years’ experience in IT and/or Cyber Security, including strong experience in Vulnerability Management, Cyber Security Engineering, Security Operations, Cloud Security or a related discipline. Experience working in complex operational environments supporting critical infrastructure, internal stakeholders, technology vendors, managed service providers and outsourced security service providers is required. Experience supporting governance, audit, compliance or cyber security improvement initiatives is also desirable.
Skills
Suitable candidates should have experience of vulnerability management processes, technologies and remediation practices; cloud security principles, governance and cloud vulnerability management; OT or industrial control system security concepts; cyber security technologies including incident response, threat assessment, malware analysis and investigation of Indicators of Compromise; SOC, SIEM, EDR/XDR and threat intelligence technologies; security frameworks including ISO27001, NIST Cyber Security Framework, MITRE ATT&CK and Cyber Essentials; risk management, remediation planning, reporting, metrics, stakeholder communication, project delivery, vendor management, Artificial Intelligence security considerations and emerging cyber threat trends. Strong communication and presentation skills are required, with the ability to engage both technical and non-technical audiences.
Education & Qualifications
Suitable candidates should have an Honours Bachelor’s Degree and/or Master’s Degree, or equivalent, in Cyber Security, Information Technology, Computer Science, Engineering or a related discipline.
Mandatory Practicing/Training/Compliance Certification
Relevant cyber security certifications such as CISSP, CISM, CySA+, Microsoft security certifications, cloud security certifications, vulnerability management certifications or incident response certifications are desirable.
Professional Memberships
Professional membership of a recognised cyber security, information security, technology or risk management body is desirable but not mandatory.