Information Security Manager (Contract position)

Pearson Lanka (Pvt) Ltd
https://www.dreamjobs.lk/jobs/information-security-manager-contract-position
<p><strong><span style="color: rgb(0, 0, 0);">Information Security Manager</span></strong></p> <p> </p> <div dir="ltr"> <table> <tbody> <tr> <td> <p dir="ltr"><strong>ESSENTIAL DUTIES AND RESPONSIBILITIES </strong></p> <ul> <li dir="ltr"> <p dir="ltr"><span>Responsible for all Information Security activities within Growth markets (South Africa, Brazil, India, China, LATAM and Middle East)</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Accountable for Growth Region Security Governance, including driving geographic security forums, risk management, incident management and post incident reviews, and security improvement projects</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Review all business and technology projects and ensure CISO requirements are implemented, serve as a subject matter expert and consultant to various project teams</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Drive all Security Risk Assessment remediation work related to Infrastructure, Applications and Business Processes</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Work with business stakeholders to ensure that Information Security policies and standards are integrated with business processes in the Geography, for example S-SDLC process</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Review infrastructure & application security results from various static and dynamic security testing tools such as Qualys, IBM AppScan, Burp Suite and Checkmarx and interpret findings to various teams</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Provide recommendations to development teams in resolving application security issues</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Manage and coordinate all application security remediation work</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Perform other vulnerability identification including system level reviews, vulnerability scans, and penetration tests on infrastructure and applications as required.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Provide security training and awareness sessions to developers, system administrators, and business-focused personnel</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Work with cross-functional teams to drive the closure of identified vulnerabilities and security risks</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Remain up to date on current information security risks, concepts, and approaches.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Work with application development teams to ensure OWASP ASVS (Application Security Verification Standard) requirements are implemented</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Ability to create reports and perform risk assessments using industry standard control frameworks such as ISO 27001</span></p> </li> </ul> </td> </tr> </tbody> </table> </div> <p> </p> <p dir="ltr"><strong>EDUCATION and/or EXPERIENCE</strong><span style="color: rgb(0, 0, 0);"> </span></p> <ul> <li dir="ltr"> <p dir="ltr"><span>Possession of Bachelor’s Degree in an IT-related discipline is required.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>At least 8+ years of Information Security experience </span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Extensive experience in the information security field, designing and implementing enterprise security solutions in a global context.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Deep and Broad understanding related to technical security encompassing endpoint technologies, applications, application hosting, physical and virtual data  centre hosting</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Excellent verbal and written communication skills with a wide range of audiences including technologists,executives, business stakeholders and IT team members.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Experience in leading matrix global teams. </span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Certifications such as CISSP, CISM, CRISC, CGEIT and CISA are  an added advantage</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Strong problem-solving skills.</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Understanding of common web vulnerabilities, including OWASP Top 10, Application Security Verification Standard (ASVS) is required</span></p> </li> <li dir="ltr"> <p dir="ltr"><span>Familiarity with common security tools, including vulnerability scanners, Security Incident and Event Management, Intrusion Detection/Prevention Systems, Web Application Firewall, and web application assessment enabling tools.</span></p> </li> <li dir="ltr"><span>Ability to understand and communicate business impact of information security risks.</span></li> </ul> <p> </p> <p><strong><span>Please click the link to apply - </span>http://pearsonlankavacancies.peopleshr.com</strong></p>