Key Roles and Responsibilities:
Perform detailed audits of legacy systems to validate adherence to security standards, policies, and procedures.
Analyze User Requirements Specifications , Technical Design Specifications , and project documentation to extract and document comprehensive security requirements.
Monitor and analyze changes in ServiceNow (SNOW) related to system configurations, assessing for security-related updates and impacts.
Engage system owners and stakeholders to gather, review, and validate evidence of current security posture, configurations, and controls.
Document and maintain a comprehensive record of security changes from initial implementation through change requests to current state.
Collaborate closely with CCI and System Owners to conduct risk assessments, identify potential security vulnerabilities, and develop mitigation strategies.
Provide actionable recommendations and technical guidance based on audit findings and security assessments to enhance system security posture.
Partner with our CCI to evaluate and quantify risks associated with identified vulnerabilities, supporting risk management and mitigation efforts.
Stay abreast of emerging threats, vulnerabilities, and industry trends to proactively recommend security enhancements and best practices.
Required Skills and Qualifications:
Bachelors degree in computer science, Information Technology, or a related field; or equivalent practical experience.
Minimum of 3 years of hands-on experience in cybersecurity, with a focus on conducting comprehensive security audits and assessments within complex IT environments.
Strong knowledge of security frameworks, standards (e.g., NIST, ISO), and best practices.
Proficiency in analyzing and interpreting technical documentation, including User Requirements Specifications (URS), Technical Design Specifications (TDS), and architectural diagrams.
Exceptional analytical and problem-solving skills with a meticulous attention to detail.
Effective communication skills to engage with technical and non-technical stakeholders at all levels.
Additional Requirements:
Ability to work autonomously and as part of a team in a dynamic environment.
Excellent organizational abilities with the capability to manage multiple tasks concurrently.
Familiarity with tools like ServiceNow, vulnerability scanners, and audit software is advantageous.