Responsibilities:
- Protects both internal service delivery assets and client facing managed services
- Compliance & Auditing: Ensure strict alignment with industry-standard frameworks (e.g., ISO 27001, PCI-DSS). Lead governance adherence, internal audits, and external client compliance assessments
- Stakeholder & Client Management:
oServe as the primary point of contact for client security inquiries, presenting security metrics, risks, and proposed mitigation controls
oDirect engagement with customer to provide technical expertise and guidance regarding the optimization of the managed security environment
o Work closely with stakeholders, review security policies of the existing environment
o Direct the development, implementation, and enforcement of InfoSec policies, cybersecurity roadmaps, and incident response plans
o Develop, implement, and maintain the firm's sustainable information security framework, policies, and risk management plans
- Operational and Implementation:
o Establishes, implements, and upgrades an organization’s cybersecurity measures to protect networks and systems from potential attacks
o Coordinate rapid triage, response, and post-mortems for any security breaches or service disruptions
o Execute existing configurations, security policies and identify areas of improvement
o Provide analysis report on existing current and areas of improvement
- Create Security Awareness:
o Collect existing materials of security awareness. Prepare for the security awareness training
- Vendor Management: Manage third-party technology vendor licensing, relationships, and budget planning