Key Responsibilities
1. SOC & Incident Response
-
Oversee SOC operations, security monitoring, threat detection, ticket management, escalation, SLA management, and closure.
-
Lead incident response, investigation, containment, recovery, RCA, and corrective actions.
-
Maintain Incident Response (IR) plans and playbooks and conduct tabletop exercises and drills.
2. Technical & Infrastructure Security
-
Manage vulnerability assessments, penetration testing, technical security assessments, remediation, and overall vulnerability risk posture.
-
Oversee endpoint, EDR, server, network, firewall, VPN, segmentation, encryption, patching, and security hardening.
-
Validate security controls and coordinate remediation and closure of technical findings.
3. IAM & PAM
-
Manage IAM and PAM, privileged access, MFA, least privilege, role-based access, provisioning/deprovisioning, and periodic access reviews.
-
Ensure appropriate access controls and remediation of identity and access-related risks.
4. Cloud, Application & Data Security
-
Implement security controls for Azure/cloud infrastructure, identity, connectivity, configuration, logging, and monitoring.
-
Conduct application security reviews and coordinate SAST, DAST, penetration testing, and remediation.
-
Drive data protection, DLP, encryption, classification, and PII security controls.
5. OT/IT & Critical Infrastructure Security
-
Coordinate cybersecurity across OT and IT environments supporting port and terminal operations.
-
Conduct IT/OT risk assessments and implement segmentation and security controls aligned with applicable OT security standards.
6. Technology Projects & Security Architecture