It Security Manager
CurrentSaleCycle are a SMB based in the North East England which have a product hosted in AWS.Worked as part of a Small Information Security team using Scrum, focusing on the technical implementation of Information Security across a business of 115 people and the SaleCycle product.Was instrumental in taking SaleCycle from a company with a low level of Information Security maturity to one with mature and effective Information Security Controls, including helping attain ISO 27001 certificationMaintained clear and effective policies to maintain the company’s ISMS implementation, including writing and implementing the Vulnerability Management, Patch Management, Password usage, Network Security & Monitoring, and Access control policiesWorked with Engineering and Product teams to implement security in the development Pipeline, using techniques such as STRIDE Threat ModellingOrganised annual External Penetration Tests of the SaleCycle Web Application and ensured effective resolution of any issues found based on their severityHeld Risk Workshops with stakeholders across the business in order to accurately and effectively document information security risks and treatments within the Eramba GRC tool.Communicated Information Security concepts and information to all levels of the business, including directly to C-Level.Monitored the threat landscape in order to ensure that SaleCycle’s controls were appropriate and risk assessments were appropriate.Managed Information Security Incidents and conducted in-depth technical investigations including log analysis, using AWS GuardDuty, AWS Cloudwatch as well as manual log searches.Assisted in Patch Management and Vulnerability assessment of AWS Cloud based services and on-premise servers using tools such as Tenable.io and nmap.Implemented Security Testing such as SAST in CI/CD pipline using open source tools.Security Assessed third party suppliers and integrations in order to manage the risk that those suppliers may introduce