---------------------------------------------------
SECURITYFOCUS JOBS - NEW OPPORTUNITY
---------------------------------------------------
JOB DESCRIPTION
---------------------------------------------------
Position: Technology Risk Consultant
Location: Amsterdam, , Netherlands
Type: Permanent F/T
Closing Date: 2008-07-03
Information Security Risk Specialist
The Information Security Risk Specialist maintains monitors and extends the security and compliance application infrastructure.
In an increasingly complex IT environment it is important for the company to ensure that proposed changes to infrastructure adhere to best practice. Using specialised knowledge of risks associated with application design, architectures and new technology endeavours the Information Security Risk Specialist will perform in-depth security and SOX risk assessments to assist the business and development teams through the life cycle of major initiatives and projects. During each review the IT Service Risk Specialist will assess impact and highlight risk whilst striving to ensure efficient implementation of appropriate measures and controls for compliance and service assurance.
Main Responsibilities:
Full responsibility for the maintenance and evolution of the Security and Compliance infrastructure within the company including:
•As an IT Service Risk Specialist you will be responsible for applying and supporting systems security processes, policies and tools. You will perform security risk assessment and recommend measures to deal with identified risks across many differing aspects of IT infrastructure.
•This position will work alongside the current Network/infrastructure teams to define Information Security requirements, for a range of developments of security infrastructure and capabilities.
•Maintaining the Security and Compliance infrastructure including Enterprise Security Manager (ESM), Tripwire, network IDS and Sharepoint sites.
•Reviewing proposed additions or changes to infrastructure that impact security or compliance.
•Advising & supporting management on Compliance and Security issues.
•Assisting with ensuring that the company as a reporting entity meets appropriate security standards in line with requirements set out by Sarbanes Oxley Legislation.
•Assisting in remedial action taken as a result of failures from a security or governance perspective
•Providing guidance and support to Affiliates on IT security or governance related topics, where necessary.
•Producing monthly & quarterly progress/ status reports.
•Assisting with incident management and investigation.
•Liaising with external vendors to ensure products meet baseline security requirements as defined by policy.
The position is based near Amsterdam, Netherlands and has no direct reports.
JOB REQUIREMENTS
---------------------------------------------------
Knowledge, Skills & Experience:
The ideal candidate will come from a “hands on” security background, preferably having working in a dedicated Information Security team in a large and diverse environment. They will have a demonstrated knowledge of security principles, risk assessment, products and architecture in distributed computing environments, core platforms, and network technologies in a global infrastructure. It is equally important to understand the security risks associated with the introduction of new technologies as well as the demonstrated ability to define appropriate countermeasures, both technological and procedural.
The candidate should have strong business awareness, IT security awareness and leadership skills, together with the ability to write about complex Information Security subjects for a non-expert IT audience.
Education:
•Degree level preferred or suitable proven experience
Knowledge and Experience:
•Three years solid experience in a role of this type
•Extensive understanding of Information security management best practices, including knowledge of policies and standards (ISO27001 and BS7799)
•An in depth knowledge of network security management technologies including firewalls, Cisco, Databases, Unix, Windows and middleware.
•Must have the ability to coordinate and manage a number of IT Security related projects.
•Must be capable of providing easy to understand documentation and training materials supporting the security infrastructure and associated security capabilities.
Personal Skills:
•Results oriented, team player, accurate and professional
•Self-starter capable of working on own initiative
•Strong planning and organisation skills.
•Excellent communication skills, both orally and in writing, at all levels
•Strong customer focus
•Ability to build and maintain effective working relationships at all levels
CONTACT
---------------------------------------------------
Please email your cv and a covering note explaining your current circumstances.
Darrin Johnson
[email protected]
---------------------------------------------------
SECURITYFOCUS JOBS
---------------------------------------------------
SecurityFocus now offers an online interface for
searching and managing job opportunities and resumes.
http://www.securityfocus.com/jobs
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.