• Risks and vulnerabilities assessments with commercial tools and techniques and regular follow up with stakeholders for remediation.
• Reviewing client issues and taking steps to remediate security threats and incidents.
• Management of escalation process, incident response, review of incident reports, and conduct Root Cause Analysis (RAC).
• Familiar with PortScan, Firewall Feature & Rules Assessment, Webservices assessment, WAF, Exploits Scanning.
• Familiar with PCIDSS, PDPA or OWASP.
• Assist SOC response (such as EDR/DLP/SIEM detection) and of any IT Security Incidents, Forensic and
remediating gaps.
• Oversee the company vulnerability management program and follow up on remediation (patching or hardening)
• IT Security Audits - Security risk assessment and key control testing such as BrokenAUTH and Session, Insecure Cryptography, hash, 2FA access, account hygiene issue, AAA issue.
• To conduct Awareness program and presentation on rotational basis.
• Hands on experience working with cloud technology AWS, Azure, GCP, GitHub, Kubernetes and native security tools.
[工作內容 ]
Company Works 公司相關
-Corporate Infrastructure
1.) Information system 資訊系統
2.) Network architecture 網路架構
3.) Security System 安全系統
4.) Cloud solution and service maintain 雲端解決方案及服務維護
Department Works 部門相關
1.) Project Service 專案服務
2.) Solution Service 解決方案服務
3.) Maintain system 系統維護
4.) Technical Support 技術支援
Employee Works Detail 員工相關
-System & Server 系統與伺服器
1.) AD
2.) DNS
3.) Microsoft 365
4.) Hyper-V virtual technology
5.) Web
6.) SQL
7.) Backup solution
8.) AntiVirus Security
9.) ERP
10.) Azure/AWS
*須配合輪值on call, 津貼另計.