About the Role
Responsible for ensuring cybersecurity requirements are embedded across technology solutions, infrastructure, applications, and digital initiatives.
The role acts as a trusted advisor to project teams, application owners, infrastructure teams, and management by identifying security risks, reviewing solution designs, assessing vulnerabilities, and recommending appropriate remediation measures.
Also, serves as a key line of defence to ensure cybersecurity risks are identified early, addressed appropriately, and aligned with business, regulatory, and industry requirements.
Responsibilities
Application Security & Secure Development
- Review application designs, architectures, and technical implementations from a cybersecurity perspective.
- Ensure cybersecurity controls are adequately addressed during application development and enhancement projects.
- Promote secure-by-design and secure-by-default principles.
- Conduct security reviews of applications before production deployment.
- Collaborate with developers to remediate security weaknesses identified during development and testing.
- Review findings from testings (SAST - Static Application Security Testing, DAST - Dynamic Application Security Testing), penetration testing, and vulnerability assessments.
- Establish and improve Secure Software Development Lifecycle (SSDLC) practices.
Security Architecture & Solution Assurance
- Participate in project reviews and provide cybersecurity recommendations.
- Review cloud, infrastructure, integration, and application architectures.
- Ensure security controls align with cybersecurity policies, standards, and regulatory requirements.
- Advise project teams on authentication, access control, data protection, encryption, logging, monitoring, and security best practices.
- Assess security implications of emerging technologies, including AI and SaaS solutions.
Vulnerability Management
- Review vulnerability assessment reports from internal and external parties.
- Risk-rank vulnerabilities based on severity, exploitability, business impact, and asset criticality.
- Ensure critical and high-risk vulnerabilities are prioritized and remediated within agreed timelines.
- Provide remediation guidance to infrastructure and application teams.
- Track remediation progress and escalate overdue critical findings.
- Perform trend analysis and identify recurring security weaknesses.
Security Risk & Assurance
- Conduct cybersecurity risk assessments for new systems, projects, vendors, and technology changes.
- Support third-party security assessments and due diligence activities.
- Review and validate effectiveness of security controls.
- Support audits, compliance reviews, and cybersecurity assessments.
- Contribute to policy, standards, and procedure improvements.
Cybersecurity Advisory
- Act as an internal cybersecurity consultant.
- Provide practical and risk-based guidance to stakeholders.
- Support infrastructure, networking, cloud, and application teams in addressing cybersecurity issues.
- Advise management on cybersecurity risks and treatment options.
- Translate technical risks into business impacts and recommendations.
Security Monitoring & Improvement
- Monitor emerging threats, vulnerabilities, and attack techniques.
- Review security incidents to identify lessons learned and systemic improvements.
- Recommend improvements to strengthen DIALOG's cybersecurity posture.
- Support cybersecurity awareness and capability-building initiatives
Requirements
- Bachelor’s Degree in IT or related field.
- Minimum 8-12 years of experience in cybersecurity, IT security, security architecture, application security, or related disciplines.
- Strong experience in: Application Security, Vulnerability Management, Security Architecture, Cloud Security, Risk Assessment, Penetration Testing Remediation and Secure Development Practices
- Experience reviewing technical solution architectures.
- Experience working with developers, infrastructure teams, vendors, and project teams.
- Experience managing security findings and remediation activities.