Job description
Job Title: Senior Information Risk Consultant (Azure/Cybersecurity)
Location: Ireland/Remote
Job Type: Contract-US Shift
Client Overview:
Our client is a major financial agency of the United Nations, and an international financial institution funded by 191 member countries, with headquarters in Washington, D.C
Qualifications:
These are the points that the candidate must have to be successful in this position and to move forward to an interview.
- Years of experience overall in IT 7 to 10 years.
- Azure cloud services (including but not limited to capabilities for IAM, Network Security, Policy Management, Key Management, etc.)
- IT Products, platforms, and services (cloud and non-cloud)
- Solutions with complex hybrid architectures
- Identity and Access Management Governance
Technical Skills:
- Familiarity with a broad range of security technologies supplemented by in-depth knowledge in specific areas of relevance.
- Ability to quickly grasp how new technologies work and how they might be applied to achieve business goals.
- Analytical skills that enable synthesis of inputs from many sources and allow for strategic thinking and tactical implementation.
- Interpersonal skills that create openness and trust among colleagues
- Facilitation and conflict management skills that enable effective working relationships.
- Spoken and written communications that are compelling, convincing, and reassuring, and skills to articulate complex technical ideas to non-technical stakeholders.
- Pragmatic security expert with an inherent ability to balance security demands with business reality.
- Excellent relationship management skills
- Ability to think laterally and to have input to / propose detailed, complex solutions to technical issues.
Certifications (minimum below plus at least 2 "preferred"):
- CISSP or CISM (minimum required)
- CCSP (preferred)
- Microsoft Certified: Cybersecurity Architect Expert (preferred)
- Microsoft Certified: Azure Security Engineer Associate (At a minimum)
- Other Microsoft cloud security related certifications at the Expert level (preferred)
- GIAC certifications (preferred)
- Offensive security related certifications (preferred)
Responsibilities:
- Senior individual contributor for information security risk management projects. Sample projects/programs could include but are not limited to:
- Control design and assessment for high-demand technical areas such as ERP, IT Service Management, Identity and Access Management, IT Resiliency, Cloud, etc.
- Compliance framework mapping and implementation,
- Risk remediation management,
- Information Security risk reporting and monitoring
- Creation of roadmaps to mature or advance Information Security Strategies/Programs/Controls
- Design and enablement of cyber controls functions and processes
- Direct experience with GRC/Cybersecurity solutions, tools, and technologies, specifically ServiceNow and Archer
- Projects or roles requiring coordination across lines of defense working with technical, business, compliance, risk, and audit teams to deliver solutions.
- Delivery of Information Security Risk assessments including consulting on threat modelling, appropriate tiering of N tier products/platforms, design of infrastructure security controls to protect application components.
- Consult and review the implementation of authentication (SSO, L DAP, AD), authorization (fine grained and coarse grained), and cryptography (PKI, SSL, Kerberos, crypto algorithms) mechanisms within applications.
- Consult and deliver standards and guidelines on the hardening of both cloud and non-cloud application and infrastructure components, tools, and techniques to ensure the security of application and infrastructure components such as LINUX/Windows servers, Web servers (IIS, Apache, tomcat), app servers, Databases (Oracle and MS SQL), endpoints (MAC, Windows, Apple IOS, etc.), and Web Application Firewalls.
- Collaborate with the security penetration testing team and review, apply appropriate risk levels to the output of Application and Infrastructure Security assessments.
- Support governance activities for Identity and Access Management.
- Defining process and procedures for using External security service providers including scoping, management of services, remediation tracking, and exception management.
- Effectively communicates requirements and trains staff and managers in IT divisions to identify and manage risks throughout the project lifecycle.
- Maintain impartiality around IT systems to produce unbiased reports on information security risk.
- Conducts quality assurance reviews of security requirements for the implementation of identified solutions.
- Manages the engagement process of external risk assessment providers and acts as a liaison with internal IT project teams and business units.
- As an advocate of information security, works closely and proactively with IT project team leaders, service providers, and business units to provide security-related technical solutions. Identifies opportunities to improve business practices or IT security-related processes.
- Analyzes, recommends, and implements process improvements within the context of information security.
- Works closely with IT project teams to develop implementation plans for new security-related products and services.
If you are interested in this role or would like to discuss further, please call Nidhi on +353 1 645 5244 or email [email protected].
Candidate must have valid visa to work in Ireland (Stamp 1G/Stamp 4/EU Passport)
