National Ict Senior Security Analyst
Current*Designing a user awareness program tailored to your local environment and observed user behaviour for addressing specific threats and monitor or measure its effectiveness via KPI (training completion rate, number of incident reports, rate of clicked on unsafe links. Reduced a great number of phishing incidents or compromised id cases. * Reviewing a contract with a Managed Security Service Provider (MSSP) involves assessing various aspects of the agreement, including service delivery processes and Key Performance Indicators (KPIs). Clarify and support onboard procedure , review and fine-tune escalation procedure of an incident response, threat intelligence sharing and continuous improvement. Improved security posture and reduced surfaces of attack, reduced waste resources.*Reviewing security controls for their effectiveness and fit for purpose is essential for ensuring that they adequately protect your organisation while also enhancing user experience. If one was not suitable then develop Selection Criteria for Security Controls that are effectiveness in threat mitigation, usability, scalability, compatibility, cost effectiveness and compliance. Conducted in-depth investigations into fraud and insider threats, maintaining close collaboration with local law enforcement.*Performing an internal audit based on the MITRE ATT&CK framework by evaluating our existing security controls to determine how effectively they detect, prevent, and respond to the tactics and techniques outlined in the MITRE ATT&CK framework. Map current controls to ATT&CK techniques, gaps analysis and review incident response plan.*Attending regular vendor review meetings is a strategic way to strengthen our cybersecurity posture and build a collaborative relationship with vendors, discussing incident trends, challenges, action items, performance metrics, threat landscape updates, industry best practices and service feedback.