Technical
Experience :
- Technical SME for Technology architecture, DevSecOps
principles, CI/CD pipelines , APIs
- A deep understanding of IT risks and controls,
particularly in DevSecOps principles, CI/CD pipelines (and the relevant
tools e.g. Jenkins, GitLab, APIs and Microservices
- Architectural assessments, therefore, knowledge of
Technology Architecture best practices will be an added advantage
- Experience within Audit or Risk Management / Assurance.
- Cyber Security SME - Penetration Test, Vulnerability
Assessment, Security Monitoring etc.
- Information security experience in any one of the areas
including Security operations, Offensive security, Defensive security,
Security architecture or Security engineering
- Experience working with CrowdStrike, Splunk, Qualys,
Defender ATP, Proxy, Endpoint Detection & Response tools, SIEM and
Mail Gateways
- Scripting language understanding is a must (Python,
Bash, PowerShell, etc.)
- Strong understanding of Payment flows
- Experience knowledge of security tools like IPS/IDS,
WAF, SIEM/SOC, Nessus, Qualys, Wireshark, Metasploit, etc.
- Knowledge of security best practices, HSM, payment
technologies.
Strong
Networking, Identity and Access Management,
Active Directory, Cloud,
Windows, or Linux skills. Familiarity with the MITRE Attack framework and
knowledge of common security vulnerabilities, threats, and controls
(e.g.
OWASP Top 10)