Assistant Manager Cyber Security (Web Apps Sec)

K-Electric


Date: 6 days ago
City: Karachi
Contract type: Full time
Our employees are our company's greatest asset - they are our real competitive advantage. We possesse immense power of innovation, immagination and a desire to attract and retain the best; provide them with encouragement, stimulus, and make them feel that they are an integral part of the company's mission.

Purpose

AM Cybersecurity (Apps Security and Data Protection) will provide security advice, tools, solutioning, etc related to various internal and external web applications like KE Live, KE Website, K-Solar and various 3rd party software integrations via APIs. The professional will be expected to participate in project planning, designing, capacity projections, hands-on implementation, complex integration work, security assessment, hardening of configurations, trouble shooting, maintaining, upgrading, and defining policy/procedure for all IT-infrastructure in use. This role will work in close collaboration with internal/external stakeholders to review, detect, report and triage with findings against cyber threats and breaches.

Education

Experience of at least 1-2 years in field of cybersecurity, out of which 1 year experience in VAPT. A bachelor’s degree in Computer Science, Cyber Security, or a related technical field. Certifications like CEH, CC, CCNA shall be preferred.

Areas Of Responsibility

Security Assessment:

Security assessment of the company wide projects

Including organizational wide changes in platforms, software, hardware, or appliance-based solutions related to network and communication technologies that are implemented on any infrastructure level

Review of design and workflows/Ensure end to end secure workflows

Performs vulnerability assessments, risk, business impact, reputation impact, controls, and suggests treatment strategies

Threats and vulnerability identification in the project/requested change

Ensuring all vulnerabilities/critical findings should be patched/fixed before going on production/Live

Review and approve requests for changes, Service requests, special service requests considering Governance policies

Threat Management /Threat and Risk Assessment

Responsible for handling Vulnerability management & pen-testing of the entire infrastructure including but not limited to vulnerability assessment of various web apps within IT and OT Landscapes.

Assist in security upgrades and patch installation for all low to critical Findings

Hunt for threats from inside and outside KE

Communicate cyber events to internal and external stakeholders

Suggests fixation or remediation of detected vulnerabilities to maintain a high-security standard

Perform tests and uncover network vulnerabilities with security teams

Assists in OTVA activities

Tools: Nipper, Metasploit, Netsparker, Nessus professional, Tenable SC and other open source tools for VAPT

Stake Holder Management

Lead the creation and procurement of awareness deliverables and learning content, leveraging various channels for effective delivery, measures the usage of the content and its effectiveness, and develops metrics

Establish a security awareness network with key stakeholders throughout the organization to understand risks and business objectives including Legal, Governance, ETS, EBS, Generation, Transmission, Distribution

Owns and manages relationships with security education and awareness related vendors

KE provides equal employment opportunity (EEO) to all persons regardless of age, color, origin, physical or mental disability, race, religion, creed, gender, marital status, status with regard to public assistance or any other characteristic protected by federal, state or local laws.

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

Medical Scientific Liaison

GSK, Karachi
3 days ago
Site Name: Pakistan - Sindh - KarachiPosted Date: Nov 17 2024Job PurposeThe MSL is the field-based scientific expert on their assigned therapy area, disease area, clinical practice and competitor landscape. Through their expertise and external interactions they will develop insights which will assist in the development and execution of innovative Medical Affairs strategies and plans that clearly support GSK development...

Documentation Officer

Human Resource Solutions International - HRSI, Karachi
3 days ago
Job Summary:The Documentation Officer is responsible for handling, organizing, and verifying all logistics and freight forwarding documentation to ensure efficient and compliant movement of goods. This role requires close coordination with operations, customs, and clients to maintain accurate records and facilitate the smooth transit of goods across borders.Key Responsibilities:Documentation Preparation and VerificationPrepare, verify, and process all required shipping documents, including...

MEA Regional Finance HUB EHS & EHW Lead

GSK, Karachi
6 days ago
Site Name: Karachi Sky TowerPosted Date: Nov 14 2024Job PurposeWe are seeking a highly organized and proactive individual to join our team as the Site EHS & EHW Manager, focusing on Environment, Health & Safety (EHS) and Employee Health and Wellbeing (EHW). This role is crucial in ensuring our site operations run smoothly and in full compliance with EHS regulatory...