The Security Engineering Team is responsible for the overall vulnerability management of critical systems across different segments (e.g., GCS, GMS) as well as remote sites. The team continuously monitors the threat landscape to identify vulnerabilities applicable to operational systems and ensures timely remediation through patching, mitigation measures, and risk management activities.
This role requires a strong technical and engineering background combined with a deep understanding of modern cyber threats and attacker capabilities, including emerging risks driven by advancements in Artificial Intelligence.
Key Responsibilities
- Monitor, assess, and manage vulnerabilities affecting operational systems and remote sites.
- Perform vulnerability analysis and risk assessment using industry-standard methodologies, including CVSS.
- Review and analyze security procedures and applications used in daily operations, including access control, encryption mechanisms, configuration management, vulnerability assessment, malware detection, and database security activities.
- Ensure prompt remediation of identified vulnerabilities through patching, mitigation measures, or compensating controls.
- Identify, investigate, and classify system anomalies within the local security environment and develop corrective actions and solution concepts.
- Identify potential threats to information and communication systems, define response plans, review implementation of security measures, and develop operational solutions ready for approval and deployment.
- Escalate security incidents, policy violations, and critical vulnerabilities when required.
- Maintain and continuously update the Security Risk Register through the identification of new cyber security risks and threats.
- Conduct regular reviews of systems against customer-defined security requirements, document compliance status, and develop corrective action plans for identified deviations.
- Provide regular reporting to the Cyber Security Manager and System Evolution & Security Manager, ensuring rapid escalation of critical security situations.
- Support the preparation of security training materials and conduct regular cyber security awareness sessions for project personnel.
- Define, implement, and support new cyber security projects and technical solutions.
- Contribute to the continuous improvement of security monitoring, analysis, and reporting tools.
- Support secure engineering practices throughout the system lifecycle and collaborate with multidisciplinary teams to enhance the overall security posture.