You recognize cyber security is the management of cyber risk associated with people, process, technology and data. You understand the risks businesses face and how to use the Microsoft Ecosystem to design “Zero Trust - Identity and Data Centric” solutions that will mitigate these risks and ensure compliance. You’re an astute advisor on Security Transformation, Security Strategy and Security Operations (SOC). As a Cyber Security Manager, you can effectively lead technical and non-technical teams.
Day to day, your work is to:
- Advise clients on the security implications of compliance and regulations such as OSFI, ISO, NIST, PCI, PIPEDA, GDPR etc.
- Carry out threat and risk assessments (TRAs) and develop security architecture to mitigate threats
- Lead and conduct threat modeling activities during Secure Development Lifecycle (SDL)
- Be the “Trusted Advisor” on best practices to protect information
- Actively lead multiple engagements simultaneously and seamlessly
- Mentor junior consultants
- Actively seek and nurture opportunities for business development.
- Lead response to RFPs, scope security programs and assist in closing sales opportunities.
- Actively participate in development of cyber security offerings.
You’re passionate about understanding or discovering security vulnerabilities and aspire to be the “Trusted Advisor.” You know all about identifying, providing and validating security requirements of IT solutions, and you’ve done this in a consulting environment. You’re a skilled communicator who can effectively articulate cyber security risks to technical and non-technical audiences.
You probably have a Bachelor’s degree in technical discipline such as (Computer Science, Engineering, Applied Mathematics etc.) and preferably, a Master’s degree in Science, Engineering or Business. You have several years (7 plus) of consulting experience in systems and infrastructure engineering, focused on Cyber security.
Your skills and experience include:
- Methods and identification tools for risks and security threats
- Knowledge of information security standards (OSFI, ISO, NIST, PCI, PIPEDA, GDPR etc.)
- Proficiency in operating systems, database platforms, web technologies, firewalls and programming languages
- Excellent communication skills in written and oral English
- Giving effective advice in large-scale technology projects while working at all levels - with clients and your team.
Strong technical skills to design and implement Azure Security services with hands on experience on several of the items outlined below:
- Security Operations
- Azure Monitor
- Azure Log Analytics
- Diagnostic logging & log retention
- Vulnerability scanning and policies
- Azure Sentinel
- Azure Security Center
- Microsoft Cloud App Security
- Platform Protection
- Azure Networking
- Virtual networks
- Application Gateways
- Traffic Manager
- Network Security Groups
- Azure Firewall
- Force tunneling
- Azure DDoS protection
- Host Security
- VM Hardening
- Azure Update Management
- Serverless Computing (Kubernetes)
- Subscription Security
- Azure resource locks
- Subscription policies
- Resource policies
- Secure Data & Applications
- Protect data at Rest (Azure disk encryption)
- Azure Information Protection
- Protect Data in transit (Azure VPN gateway, SSL/TLS and HTTPS)
- SQL Database (Discovery, classification, labeling, immutable storage, data retention, legal holds, and data sovereignty
- SQL Database firewall
- SQL Database authentication
- Cosmos DB authentication
- Azure HDInsight DB authentication
- Azure AD authentication for SQL DB
- Database auditing policy
- SQL DB threat detection
- Access control for storage accounts
- Key management for storage accounts
One or more of the following:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Cloud Security Professional (CCSP)
- GIAC Certified
- Azure Security Engineer (AZ-500)