Head Of Cyber Security
Current▪ In charge of the cybersecurity architecture area; it consists of 3 teams: • IT Advisor: analyzes, selects, and implements new security solutions. • Business Advisor: supports the business, analyzes vulnerabilities, measures risk exposure, advises on security best practices in projects, and conducts application penetration testing. • DevSecOps: ensures the maturity cycle of secure development, performs static and dynamic application security testing (SAST/DAST), validates… Show more ▪ In charge of the cybersecurity architecture area; it consists of 3 teams: • IT Advisor: analyzes, selects, and implements new security solutions. • Business Advisor: supports the business, analyzes vulnerabilities, measures risk exposure, advises on security best practices in projects, and conducts application penetration testing. • DevSecOps: ensures the maturity cycle of secure development, performs static and dynamic application security testing (SAST/DAST), validates pipeline assembly (CI/CD), and manages API Management.▪ Renewal of the cybersecurity technology stack; involved the implementation of solutions such as: • DLP • EDR • Replacement of VPN with a VPN (ZTNA) • Replacement of SIEM • Traffic security (WAF, DNS, DDoS, CDN, and SSL/TLS certificates) • Mobile App security (SIM swap, vishing fraud, root detection, jailbreak detection, etc.) and its integration into various pipelines • MS365 E5 Security and Intune • Defining and applying security best practices on the new AWS landing zone • Applying the STRIDE model in threat modeling for applications migrating to cloud • Regulatory compliance, network monitoring, and asset evaluation • Brand Protection (analysis of findings and takedowns) • Organizational Score (measure and monitor) • Static and dynamic code analysis (SAST and DAST); integrated into pipelines • Vulnerability management (managing, tracking, and remediating security vulns in applications)▪ Improve the security maturity level of the software development lifecycle.▪ Define CIS controls to be used.▪ Collaborate in the bank's digital transformation process.▪ Conduct maturity assessment under the NIST framework.▪ Define security policies, standards, and procedures.▪ Present status report to the CISO.▪ Define OKRs and KPIs.▪ Perform cybersecurity PoCs.▪ Respond to internal audits.▪ Compliance with BCRA regulations. Show less