Position: Security Officer
Location: Dubai
Salary: 20K to 22k (AED)
Reporting Structure:
- Report to Security Officer onshore as a single point of contact from the Service Provider side with the client's Security team (ISRM).
Key Responsibilities:
Collaboration and Enforcement:
- Work with ISRM teams and the onshore Security Officer during the project to enforce ISRM policies and guidelines for suppliers' applications in scope.
Security Design:
- Set up the Security Design for suppliers' scope and incorporate security guidelines into the application design.
Audits and Checks:
- Conduct regular checks and audits to verify guidelines for the application delivery and operations team on the ground. Provide required reports to the client's ISRM and Ignite Teams.
Testing Support:
- Support Testing Teams in conducting Security Tests (SAST, DAST, and Pen Test). Handle identified security issues or violations.
Security Requirement Tracking:
- Ensure all security requirements are properly tracked and met during delivery.
BC and DR Coordination:
- Coordinate Business Continuity (BC) and Disaster Recovery (DR) simulation with the client's BC and DR team.
Forensic Investigations:
- Coordinate and support the client's SIRT team for forensic investigations by providing access to artifacts on systems, people, and processes.
Patch Management:
- Coordinate with the client's security team on periodic and emergency patch management.
Periodic Audits:
- Coordinate periodic audits (onshore/offshore) performed by the client's risk management teams.
On-Demand Reporting:
- Provide on-demand reports on:
- Assets
- Assets onboarding to Security solutions such as IAM, AD, PAM, AV, EDR, SIEM (use cases and alert simulation), Container Firewall
- Vulnerability management of container application images and patch status
- Audit/compliance status of compliance requirements
- Training and awareness status of the team
- Certification/recertification status of ODC
- Maintain repository of DR run books.
Minimum Experience:
- 7+ years of experience.
- Relevant industry knowledge and technology exposure in telecom.