Job Description
Description
Security Infrastructure Design and Implementation:
- Design and implement security measures and controls to protect information systems and networks.
- Deploy and manage security tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), and encryption solutions.
Application Security:
- Conduct thorough security assessments and code reviews to identify and mitigate vulnerabilities in Renmoney’s applications.
- Integrate security best practices into the software development lifecycle (SDLC) to ensure secure application architectures.
- Collaborate with architects and engineers to design secure system architectures.
- Ensure security is integrated into the system development lifecycle (SDLC).
Security Monitoring and Incident Response:
- Monitor security systems and analyze security logs to detect and respond to security incidents.
- Conduct incident response activities, including investigation, containment, eradication, and recovery.
Vulnerability Management:
- Conduct regular vulnerability assessments and penetration testing to identify security weaknesses.
- Work with IT and development teams to remediate vulnerabilities and improve security posture.
Security Policies and Compliance:
- Develop, implement, and enforce security policies, standards, and procedures.
- Ensure compliance with relevant security regulations and frameworks (e.g., ISO 27001, PCI DSS, CBN Cybersecurity Framework).
Security Awareness and Training:
- Provide security awareness training and guidance to employees and stakeholders.
- Promote a culture of security awareness within the organization.
Risk Assessment and Management:
- Conduct security risk assessments to identify and evaluate potential security risks.
- Develop and implement risk mitigation strategies and controls.
Requirements
- Education: Bachelor’s degree in any numerate or related field.
- Experience:
- Minimum of 3-5 years of experience in a security engineering role.
- Proven experience with security technologies and tools (e.g., Burp Suite, OWASP ZAP, Nessus, Metasploit, Kali).
- Certifications: Relevant certifications such as CEH, OSCP, Sec+, or GIAC are highly desirable.
- Technical Skills:
- Strong understanding of network and system security principles and technologies.
- Strong understanding of application security vulnerabilities (e.g., SQL injection, XSS, CSRF, SSRF).
- Familiarity with DevSecOps practices and tools.
- Experience with security frameworks and standards (e.g., OWASP, ISO 27001, PCI DSS).