1. IT Audit
Supports the Lead Auditor’s activities.
Prepare check list for various audits
Performs the audit using the consolidated audit checklist.
Reports the non-conformities and recommends suggestions for improvement
2. ITSM related
Support organization in developing process and procedures as per ITIL /ISO 20000 standard
Support ISO 20000 certification activities
3. Vulnerability Assessment
Identify the vulnerabilities using available Vulnerability assessment tools
Systematically Analyze and priorities RISK and prepare report
Liaise with the Implementation team for the closure of identified vulnerabilities
4. Threat Management
Monitor Security website on a daily basis and analyze threat to ICT infrastructure
Alert the concerned SME (subject matter Experts) of these Emerging Threats in advance
Liaise with the Implementation team for the closure of identified vulnerabilities
5. Security Testing:
Carry out security testing from the perspective of a potential attacker by active exploitations of identified security vulnerabilities, in a controlled manner
6. ISO 27001 Maintenance
Support ISO 27001 implementation and maintenance activities like, Security process monitoring, measurement and reporting.
Total 7 years of IT experience
for BE and 10 years for MSC; out of which minimum 5 years of security control
implementation in Network, windows and Unix platforms and 2 years of process
& Information Security Audit experience.
Experience in Implementing
and administrating Firewalls , IDS/IPS
Experience in Windows /Unix
administration and Operating system hardening
Monitoring various security
event logs and reporting
Implementing and managing
Antivirus /proxy servers etc.
Implementing ID management
Experience in Vulnerability
Assessment tools (preferably IBM ISS ) and security testing tools
Conducting technical and
process Audits and creating check lists for audit
Coordinating external audits
and penetration test.
Experience in handling
Security incidents.
Conducting Information
security awareness trainings.
Implementing ISO 27001/ISO
20000