Home / Jobs / Job Details

Security Architecture Analyst

Bruhat Insights
Location: Chennai, Experience: 10 years - 11 years
Posted On: 20-Oct-2020 | Last Date to Apply: 21-Jul-2021 | No: of Vacancies : 1 | CTC: 6 to 13 Lacs

Company Profile:

A client of Bruhat

Job description:

Support the Office of Information Securitys DevSecOps projects SDLC documentation, support securing Project approvals from various control boards, support generating documentation for operations and service management. Work with project teams to define security requirements for new systems in line with the enterprise information security architecture Provide security design recommendations based on enterprise information security architecture and solution patterns Provide guidance and assist in the development of security standards for IT platforms in line with the information security architecture Maintain an up-to-date understanding of emerging trends in information security architecture and apply new techniques and trends (in-line with overall information security objectives and risk tolerance of the WBG) to the WBGs information security architecture Perform controls reviews and system assessments to develop risk profiles for IT systems and evaluate the efficiency and effectiveness of the IT control environment Maintain impartiality around IT systems to produce unbiased reports on information security risk Provide business units with recommendations to reduce information security risk within their areas Identify efficiencies to improve the performance and responsiveness of the ITSSR information security architecture function Prepare and present security design and architectural review reports to system owners, business units, and other Evaluate WBG current software security posture and propose mitigation and remediation plans to meet software security assurance requirements Translate technical security deficiencies into business risks that are understandable by business stakeholders in order to get buy-in for security investments Educational Qualifications and Experience: Education: Bachelors degree in Computer Science, Information Systems, or a related technical field Role Specific Experience: 2+ years of experience in Azure Cloud development with DevOps methodologies. Experience in providing guidance for data protection based on data sensitivity and associated business risk Experience with enterprise security architecture design and implementation for a financial services organization or other organizations with similar information security needs and requirements Experience guiding project team remediating such vulnerabilities Certification Requirements: Certified Information Systems Security 5 (CISSP), Certified Information Security Manager (CISM), Global Information Assurance Certification (GIAC), and Information Systems Security Management 5 (ISSMP) Required Skills/Abilities: Extensive knowledge of IT, enterprise architecture, software development life cycle, and information security platforms and applications Ability to work well under pressure and meet tight deadlines High level of motivation, confidence, integrity, and responsibility Knowledge of best practices and standards for enterprise security architecture, specifically in the field of Identity & Access Management, Enterprise Content Management, Collaboration Tools, Service-Oriented Architecture, Cloud, Mobility, Data Analytics, and Web 2.0 related services Practical knowledge of common Web vulnerabilities as per SANS 25 or OWASP Top 10 specifications Excellent interpersonal skills including the ability to work independently and effectively in a team/task force as a team member or leader, and with senior staff and managers in the unit and elsewhere in the WBG Ability to collaborate with senior management stakeholders to identify requirements and drive compliance with approved standards Requirements phase: Develop Business Requirements (BRD) Architecture phase: Develop Functional Specifications (FSD) Design phase: Develop High Level Design (HLD) + Low Level Design (LLD) Development phase: Code Repo + Developer Comments Documents Testing phase: Develop Test Plan + Test cases Deployment phase: Develop Deployment Document (Pre-check, Cutover + Warranty) Client onboarding phase: Develop Onboarding document for services and/or applications Administration and Maintenance phase: Develop Installation and Setup guide (ISG) + Maintenance and Operation guide (MOG) Reporting and Dashboards for ongoing Governance: Develop Dashboard document or has built a dashboard Strong verbal, presentation, written, and interpersonal skills. Good understanding of DevOps tools and automation framework. Desired Skills/Abilities (not required but a plus): Security SDLC experience in two or more of the following phases is a plus: o Secure Software Concepts o Secure Software Requirements o Secure Software Design o Secure Software Implementation/Programming o Secure Software Testing o Secure Lifecycle Management o Software Deployment, Operations, and Maintenance o Supply Chain and Software Acquisition Security experience in two or more of the following security domains is a plus: o Identity and Access Management Architecture o Security Operations Architecture o Infrastructure Security o Architect for Governance, Compliance, and Risk Management o Security Architecture Modeling o Architect for Application Security Pluses for Levels: (level II, III):

Key Qualifications

Bachelors

Education

B.E

Industry

IT-Software- Software services

Gender Preference:

Any

Job Type:

Full Time

Diversity Tags:

Not Applicable