Fox Department
25/07/2024
Project-based
On behalf of our client, an international financial service provider located in Prague, we are looking for an external resource with skills and abilities as stated below: IT Security Technical Expert CNAPP - Vulnerability Management (m/f/x) financial area Prague Tasks and responsibilities: In your position in the Group Security department you will directly contribute to the execution of our client's information security strategy. As a central service provider, Group Security is responsible to protect information assets, incl. suppliers, in terms of safety, integrity, confidentiality, authenticity and availability by enforcing information security controls based on the relevant regulatory requirements and follows the international standard ISO/IEC 2700-series on the Information Security Management System. In your position, you will provide IT security expertise in support to the business and in line with the key responsibilities: Lead our clients System Security initiatives (Vulnerability and Compliance checks for system hardening, Vulnerability Notification, Source Code Scan, quality checks of reported results, Tracking and Monitoring of remediation of open findings in IT and regular Reporting). Lead, Advice and support the IT Support Groups for the understanding of vulnerabilities and by acting as expert/specialist. Provide guidance to the IT for re-engineering of processes and procedures required for remediation, recommend, and track corresponding actions. Cooperate at the resolution of critical audit findings. Ensure daily operational duties relating to security management in compliance with relevant policies and industry best practices. Develop Information Security Guidelines, Processes and Procedures , Baselines in line with our clients Policies and Standards and international standards of quality management. Expertise in Cloud principles and risks associated with Public and Hybrid cloud . Perform Risk Assessments of Security Architecture and solution mitigation of identified risks. Developing expertise in Cloud through CNAPP solution for GS Conduct training sessions for Legal entities on new upcoming technology changes Mandatory skills and experiences: 10+ years of proven professional experience for IT Security, It Risk and Compliance Management with at least 2 year working exp in Multi-cloud environment Very good understanding of Infrastructure, Platform and Application security concepts & threats (Network Infrastructure, Operating Systems, Database, Middleware and Web applications hardening measures). Capable of creating custom checks for tools like Rapid 7, Semantec CCS, Prisma Cloud, etc. CNAPP experience with any vendors. Knows CNAPP capabilities (CIEM, Code Security, Workload protection) and its integration with Enterprise landscape (asset inventory, Ticketing tool, DevSecOps). GCP, Azure or AWS fundamental knowledge (eg VM, Containers GKE and AKS ). Recommend appropriate controls to maintain confidentiality, integrity and availability of systems/services and to fulfil the requirements of regulators. Very good communication skills in in written and spoken English (German/Czech is a plus). Optional Skills: Security-related certification (CCSP, CISSP, CISM) or willing to acquire one major certification within one (or two) year. Good ITIL knowledge (ITIL certification). Experience with System security tools/solutions (CNAPP, Aquasec, Rapid7 ). Effective organizational skills to maintain a consistently high standard of operations in a business-critical financial environment. Additional Information: Start date of assignment: ASAP Initial contract duration: 31.12.2024 Degree of project work: Full-time Location: Prague Please let us know if this position is of interest to you. We will be happy to send you further information and look forward to hearing from you! Best regards, Andy GDPR: You are interested in this project and would like to send us your CV? Due to the General Data Protection Regulation (GDPR), we would like to ask you to give us your written consent to the permanent storage of your data in your email. We use your data exclusively for the purpose of our staffing activities. Of course, you have the right to information, correction, blocking or deletion of your data at any time. Template: I agree to the permanent storage of my data. I know that I have the right to information, correction, blocking or deletion and can revoke this consent at any time".