Responsibilities- Engineering, implementation, and monitoring of security controls for the protection of network, systems, data and endpoints in an multi-cloud environment, to help mitigate security risks. Work with the IT Infrastructure, IT Applications, IT Compliance and Governance teams to implement these controls.
- Risk assessment of M365 platform, AWS, Azure and third-party SaaS services, make recommendations to mitigate risk.
- Designing enterprise scale Cyber Security Solutions in alignment with Information Security Strategy.
- Identify and define security requirements for Business and IT Projects. Analyze, report, and assist in management of security-related risks, including reporting on outcomes and proposing further security improvements.
- Key member in responding to and triaging security incidents, including guiding security operations and security engineers.
- Perform service management for security platforms, including problem, change, configuration, and asset management.
- Work with third-party security service providers to ensure service delivery objectives are met.
- Prepare and publish standards, processes and operating procedures.
- Uphold the company's core values of Integrity, Innovation, Accountability, and Teamwork.
- Demonstrate behavior consistent with the company's Code of Ethics and Conduct.
- It is the responsibility of every employee to report to their manager or a member of senior management any quality problems or defects in order for corrective action to be implemented and to avoid recurrence of the problem.
- Duties may be modified or assigned at any time to meet the needs of the business.
Qualifications- Bachelor's degree in Computer Science, Information Security, or related field required.
- Must have minimum seven (7) years of work experience in information security with at least five (5) years of work experience in cyber security, in a hybrid cloud computing environment (on-premises, AWS and Azure).
- Must have at least three (3) years of work experience in conducting Risk Assessments of SaaS services.
- Hands-on experience in network security (Firewalls, VPN, Proxys, Web Application Firewall, CASB, etc.), systems security Windows and Linux), cloud security (AWS and Azure), endpoint security and identity and access management is required.
- Hands-on experience in vulnerability management, configuration management, media protection, contingency planning, log management, and data protection methods is desired.
- Experience in M365 E5 Security Suite, AWS and Azure Threat Detection and Response techniques required.
- Must have hands-on experience in implementing NIST 800-171 and ISO 27002 security control frameworks.
- Familiarity with AI and web related technologies (GenAI, Agentic AI, Web applications, API, etc.) and of network/web related protocols needed.
- Must have thorough understanding of the security principles, techniques, and protocols, including defense-in-depth, network segmentation, privileged access management, common application security flaws, and commonly known ports.
- Professional information security-related certifications such as CISSP, GSEC, CCSP is required.
- Familiarity with standards and frameworks such as NIST 800-53, PCI-DSS, HIPAA Security and Privacy Rule, ISO/NIST Risk Management desired.
- Proven ability to lead a project from start to finish from the technical side.
- Previous experience working in a global enterprise environment desired.
- Good verbal and written communication skills in English are essential.
- Must have capability to clearly communicate information security concepts and risks.
- Problem solving skills and ability to work under pressure needed.
- Must be able to work independently as well as in a team structure.
- Willingness to accommodate other time-zones required.
- Off-hours support may be needed.
Please review our benefits here: Life at OSIPay may range from $160,000 to $170,000 annually
The pay range above represents annual base salary only. Final compensation will be determined based on factors such as your job level, geographic location, date of hire, experience, job-related knowledge and skills, and education in conjunction with market and business considerations.
Base salary is one component of your total rewards package. You may be eligible for long-term incentives, potential discretionary bonuses, and the ability to purchase company stock at a discounted rate through the Employee Stock Purchase Program (ESPP). OSI also offers comprehensive benefits including various options for health plans, access to 401(k) retirement plan, health savings account, disability insurance, life insurance, AD&D insurance, leave of absence programs and an array of voluntary benefits. In addition, paid time off is offered to be used for vacation, holidays, bereavement, and jury duty. Full-Time salaried employees are entitled to flexible time-off.