Job Description
GlobeMed Group, the largest Healthcare Benefits Management company in the MENA region is looking for an IT Security Officer who will handle all IT Security related tasks, as well as monitor, review and audit all aspects of the network, including designing, planning, configuration, installation and recovery as per the ISO 27001 and ISO20000 standards in order to maintain the confidentiality, integrity and availability of information.
Main Duties:
- Establishing and maintaining effective documented information security management system as per ISO/ IEC 27001:2022 standard requirement
- Reporting to Manager about the performance of ISMS.
- Assist in evaluating new technology and security products for relevancy to Organization’s overall security strategy and in support of new business requirements/initiatives
- Coordinating and assisting the concerned offices in the implementation of ISMS
- Ensuring corrective and preventive actions against identified or potential non-conformities
- Convening the Management Review at scheduled intervals.
- Scans for, identifies and assesses vulnerabilities in IT systems including computers, networks, software systems, information systems, and applications software.
- Managing the ISMS throughout the PDCA lifecycle.
- Initiating review of the ISMS once in a year or as and when required.
- Coordinating between the management and the certifying authority.
- Managing Web application Firewall, NGFW, IPS, WAF and other Security tools
- Monitor networks and systems for security breaches and anomalies using SIEM and EDR tools
- Investigate and respond to security incidents, including breaches and malware outbreaks.
- Oversee access control, identity and privilege management.
- Coordinate with IT teams to ensure secure system configurations and patch management.
Qualifications
- Bachelor Degree in communication engineering, computer science or Information systems
- 2-5 years of experience in security related field.
- CISSP/CISM security certification
- Ability to handle security incidents
- Knowledge and expertise of security standards, concepts, principles and processes
- Hands on experience of Security Vulnerability Tools such as Qualys Guard, Nessus Accunetics
- Knowledge in DLP, EDR, O365, Email Security