Experis™ is the global leader in professional resourcing and project-based workforce solutions. We accelerate organizations’ growth by intensely attracting, assessing and placing specialized expertise in IT, Finance & Accounting, Engineering and Healthcare to precisely deliver in-demand talent for mission-critical positions, enhancing the competitiveness of the organizations and people we serve.
Threat and Vulnerability Management
Workplace: Kraków
Nr Ref.: KL/28/11/2016
Main Accountabilities:
- Hardening Guidelines: Ensures that for all relevant appropriate hardening guidelines are available and adopted to security needs. Works together with the service providers to ensure that the hardening guidelines are implemented.
- Assessment Report Management: Defines the report format, reviews the security configuration reports from the providers, triggers timely provision of reports, requests changes updates etc. Reviews and checks completeness of reporting results and also quality of the provider reports.
- Deviation Management and Exception Hardening: Assesses the reports and risk assesses deviations from expected configuration. Maintains a database of deviations and accepted exceptions.
- Exception Handling: Reviews exception and manages escalation of unaccepted deviations. Works with service providers and InfoSec Risk Management in cases of different assessments of risk
- Communication: Communicates deviation to the relevant organizations for mitigation and also exceptions to all relevant bodies.
- Management Reporting: Reports the security status in terms of security configuration to the relevant bodies (i.e. InfoSec Management, Service Management)
- Others: On-boarding of new applications, systems, service providers etc. Integration of new service providers into the Security Configuration Management processes and activities.
Knowledge, Skills, Experience:
- Graduate level with IT focus or equivalent practical experience
- At least 4 years business experience in IT/IS
- At least 2 years of experience in Information Security
- In-depth security configuration knowledge of two or more of the following: Windows Server OS, Linux Server OS, Cisco iOS, SAP, AIX, SQL, Oracle Databases, or IaaS cloud solutions
- In-depth knowledge of security configuration baseline documentation such as Center for Internet Security- Security Benchmarks, US Defense Information Systems Agency - Security Technical Implementation Guides, or SANS Top 20 Critical Security Controls
- In-depth knowledge of ISO 27001/27002 Certification for ISMS, Sarbanes Oxley (SOX) Compliance, and international data privacy laws
- Good English language skills (spoken and written)
- Ability to communicate compliance requirements to technical and business stakeholders
- Good management skills for interaction with service provider and internal organization
- Team player & multicultural sensitivity
- Knowledge of security auditing and vulnerability assessment tools such as RSA Archer, QualysGuard, FireEye Retina, Onapsis, or Rapid 7-Compliance
- Knowledge of security auditing and vulnerability assessment techniques & methodologies
- Desired Information Security Certifications such as CASP, CCNA Security, CCSP, CISA, CISSP, or CISM.
Offer:
- Stable job based on diffrent forms of contract
- Access to education platform with over 3000 different IT trainings
- Private medical insurance (Medicover) and Multisport card
- Professional development opportunities
- The pleasant atmosphere in an ambitious and professional team
