About the job
We are seeking a skilled Information Security Engineer / Analyst with 3-7 years of experience in information security, specializing in security solution design, engineering, implementation, and assurance.
Key Responsibilities:
- Define and manage the implementation of controls for access security and IT control requirements, with 3-5 years of relevant experience.
- Work with information security and IT general controls, including defining and documenting controls using frameworks such as COBIT 4.1 or 5.0, NIST Cybersecurity Framework, ISO 27k framework, and SANS 20 critical controls.
- Possess a deep understanding of information security technologies, including firewalls, IDS/IPS, Password Vaults, CASBs, SIEM, IT GRC, and DLP.
- Understand the regulatory environment and have experience interacting with regulators.
- Comfortably deliver tasks in an evolving environment.
- Have experience in application security and related technologies, such as Jenkins.
- Utilize the FFIEC Cyber Security Assessment Tool effectively.
- Hold applicable certifications such as CISSP, CISA, CISM, CGEIT, or CRISC.

