Cybersecurity Operations
Current• Security and IT regulation Governance and Risk Management • Maintain HQ and regional office network security implementation.• Routine security monitoring, enforcement, and implement company system patching strategy.• Audit, maintain, and secure on-prem and cloud user access security audits.• SIEM Security Onion 2 deployment, implementation, tuning, and overseeing the SOC operations.• Email header analysis for email security filtering spam and deep analysis for phishing and threats. • Mitigate threats using Microsoft 365 Products (Defender, Sentinel, Attack Surface Reduction rules, Device control, and Conditional Access Policies).• Malware analysis and Incident handling and reporting • Manage annual external security audit and any other security vendor engagements including penetration testing, and external monitoring tools.• Develop and maintain an IT security risk register, and use it to guide continuous improvements.• Reduce risk by directly implementing fixes to remediate issues found by any source (audit, external monitoring, internal monitoring, etc.).• AWS, GCP, and Azure cloud IAM, cost and usage management.• Support customer questionnaires and legal contracts relating to IT security.• Manage internal employee security policies, training, and any other efforts to minimize risk caused by employee behavior.• Ensure compliance with PCI and other established data security and privacy controls (GDPR, etc.)• Develop and maintain a security incident response plan and coordinate the response to any breach.