Responsibilities:
Assist in shaping the security roadmap, enforce security policies and regulatory compliance, and help manage security vendors, budgets, and tool selection.
Manage EDR/antivirus tools, threat hunting, and incident response.
Oversee firewalls, IDS/IPS, WAF, network segmentation, and access controls.
Lead vulnerability scans, patch management, and system hardening.
Enforce DLP, data classification, and access monitoring.
Support PAM implementation, manage bastion hosts and account lifecycles, and audit high-risk administrative activity.
Coordinate and perform penetration tests and vulnerability assessments, documenting remediation steps for key stakeholders.
Create security metrics, risk assessments, and technical reports for IT management and business leaders.
Qualifications:
Bachelor's degree in Computer Science, IT Security, or related field with at least 4 years of hands-on information security experience.
Financial services, insurance, or regulated industry experience preferred.
CISSP, CISM, OSCP, or equivalent is a strong advantage.
Proven experience conducting end-to-end pen tests for web, mobile, Active Directory, and internal networks.
Solid understanding of common flaws like OWASP Top 10, logic flaws, and privilege escalation.
Proficiency with security tools including Burp Suite, Nmap, Nessus/AWVS, Metasploit, and Cobalt Strike.
Hands-on automation and exploit proof-of-concept skills using Python, Go, or similar languages.
Working knowledge of SIEM, EDR, PAM, WAF, IDS/IPS, and honeypots.
Strong analytical problem-solving, stakeholder management, cross-team collaboration, and continuous learning abilities.
