AI Match Level: High

Cybersecurity Specialist

Techvetra (Pvt) Ltd Colombo, Sri Lanka

Scan to view on mobile
Scan to view

Job Overview

The Cybersecurity Specialist plays a critical role in safeguarding the organization’s digital assets and infrastructure against an evolving landscape of cyber threats. This position is instrumental in developing, implementing, and managing security protocols to protect sensitive information and ensure compliance with regulatory requirements. By aligning cybersecurity strategies with business objectives, the specialist enhances organizational resilience and supports operational efficiency.

Key Responsibilities:
- Conduct comprehensive risk assessments and vulnerability analyses to identify potential threats and mitigate risks.
- Design, implement, and maintain security standards, policies, and procedures to protect organizational data.
- Monitor and analyze security events and incidents through security information and event management systems (SIEM) and respond effectively to security breaches.
- Collaborate with IT teams to secure network and system architecture through robust access control measures and encryption technologies.
- Lead the incident response process, including investigation, documentation, and reporting of security events to ensure swift resolution.
- Develop and deliver training programs to staff regarding cybersecurity awareness and best practices to foster a culture of security.
- Evaluate new security solutions and technology trends, making recommendations for enhancements or upgrades to existing systems.
- Work closely with regulatory bodies to ensure compliance with relevant laws and standards, such as GDPR, HIPAA, and NIST.
- Prepare and present detailed reports on security incidents, vulnerabilities, and risk management initiatives to senior management.
- Maintain up-to-date knowledge of cybersecurity trends and emerging threats, integrating findings into strategic planning.
- Liaise with external auditors and regulatory agencies during security assessments and audits.
- Assist in the development and testing of business continuity and disaster recovery plans to ensure operational readiness.

Objectives:
- Achieve a 25% reduction in security incidents year-over-year through proactive threat monitoring and mitigation strategies.
- Complete quarterly security audits and maintain compliance with at least 95% of regulatory standards.
- Enhance employee cybersecurity training completion rate to over 90% within one year.
- Decrease the average response time to security incidents by 30% through optimized incident response protocols.

Required Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 5 years of experience in cybersecurity, information security, or a related discipline.
- Strong proficiency in security technologies, including firewalls, intrusion detection/prevention systems, and anti-virus solutions.
- Relevant certifications such as CISSP, CISM, CEH, or equivalent, demonstrating advanced knowledge in cybersecurity practices.
- Familiarity with regulatory requirements and compliance frameworks affecting security measures, such as ISO 27001 or PCI-DSS.
- Excellent analytical and problem-solving skills, demonstrated through real-world application in a complex environment.

Key Responsibilities

The Cybersecurity Specialist is responsible for protecting an organization's information systems by identifying vulnerabilities, implementing security measures, and responding to incidents. This role involves conducting risk assessments, monitoring networks for security breaches, and ensuring compliance with regulations to safeguard sensitive data. By mitigating cyber threats, the specialist plays a vital role in maintaining business continuity and protecting the organization's reputation.

Pre-screening Questions

The following questions will be asked during the application process to evaluate your fit for this role:

Question 1
What is the primary purpose of a firewall?
Question 2
Which of the following is a common type of phishing attack?
Question 3
What is the purpose of multifactor authentication (MFA)?
Question 4
Which of the following tools is typically used for network vulnerability assessment?
Question 5
What does 'social engineering' refer to in cybersecurity?