Senior Associate
• Member of ITCT (Infosec Technology and Cybersecurity Testing) team and performed mainstream testing and ad-hoc testing to evaluate risk and control effectiveness across various Technology, Information Security and Cybersecurity policies.
• Ensuring there is adequate processes, procedures and operational management associated with system security and disaster recovery planning in place to mitigate the risk.
• Ensure preventive and recovery process are place, minimize the risk of internal and external security threats.
• Evaluated the processes that access and control’s identity and Access Management System to ensure accurate provisioning of access.
• Perform audit/testing to ensure risks are appropriately identified, associated audit procedures are applied, and related controls are designed and operating effectively to mitigate the identified risks.
• Performed testing over the processed that anticipate plausible cybersecurity risks, persistent threat actors and events that could arise in the due course of the business process, strategies, and ongoing activities.
• Review of processes and controls that mitigate Information Security risks:
• Vulnerability management processes that support the confidentiality, integrity, and availability of the information.
• Performing the business evaluation tests to evaluate the urgent defects to be fixed before monthly client check.
• Prepare and report control deficiencies, provide recommendations to address the root cause of issues and report on the status of implementation of management remedial actions.
• Follow-up on remediation activities for deficiencies identified to ensure control gaps are successfully resolved.
• Performed testing over Cybersecurity controls that:
• Monitor cybersecurity events in a timely manner with a focus on systematic deduction, vulnerability remediation and response from cybersecurity attacks.
• Liaising with the application owners on the support codes made available to the end users along with enhancing the global support roles for the support team in Installing and maintaining software security applications.