Key Performance Areas
- Cybersecurity Management
- Infrastructure Management
- Risk Management and Compliance
- QMS and Documentation
Minimum education (essential) :
Engineering degree (Computer, Software, Mechanical or Electronic)Minimum education (desirable) :
OSCP (Offensive Security Certified Professional)PNPT (Practical Network Penetration Tester)CISSP (Certified Information Systems Security Professional)CCSP (Certified Cloud Security Practitioner)Minimum applicable experience (years) :
AWS' ecosystem :AWS Well Architected FrameworkTrusted AdvisorGuardDuty / SCP / SSM / IAM / WAFContainer services such as ECS / EKSIncident detection and response management.Performing penetration tests and vulnerability scans against networks and infrastructure, applications and AWS environments.Drafting and implementing security policies, security procedures, security design and implementation.The following would be advantageous :
ISO 14971 (risk management) complianceISO 27032 (cybersecurity) complianceSOC2 Type 2 (with HiTrust attestation) or HiTrust experience (or equivalent)Skills and Knowledge (essential) :
Deep understanding of automation, quality engineering, architectural methodologies, principles, and solution design.Familiarity with operational observability, including log aggregation, application performance monitoring, etc.Understanding of the following : Linux / Windows server and application administration and configuration, networking, scripting and automation, large scale distributed computing architecture.Solid knowledge of IT security (firewalls, EDR, IDS / IPS, SOAR, vulnerability scanning forensic and Threat Hunting).Understanding of AWS ECS & Kubernetes and Containerisation (Docker / Podman / Containerd) with implementation, support, and design.Knowledge in security classification frameworks like MITRE or the cyber-attack kill chain.Good knowledge and understanding of industry standards, memberships, and frameworks such as CIS and SOC 2.