Information Security Lead
You are responsible to:
- Develop and implement comprehensive OT security strategies that align with industry best practices and regulatory requirements.
- Identify OT vulnerabilities and perform remediation without causing system unavailability.
- Deploy Firewalls to segment OT systems from other standard IT environments.
- Define Security Policy Framework customized for Supply Chain Technologies
- Identify appropriate tools/solutions in the areas of inventory collection, vulnerability management, antivirus, endpoint detection and response
- Develop and maintain robust ISC security controls to protect Philips's business from security breaches/ incidents.
- Hands-on experience in designing and deploying multiple OT IDS solutions
- Experience with handling well-known OT technologies - Nozomi Guardian, Armis, Claroty and Microsoft Defender for IoT (CyberX)
- Experience in conducting risk assessments, and maturity assessment for OT systems and products to identify and prioritize security threats and weaknesses
- Evaluate new cybersecurity threats and IT trends and develop effective security controls.
- Establish regular governance with service owners to review security control status
- Liaison with Philips Information Security Office in driving the security Improvement Program
- Define and report on information security KPIs.
- Analyze application end to end, prepare threat modelling (STRIDE, PASTA & DREAD) based on different risk scenarios and drive to fix those risks
- Prepare security use cases / functional requirements that new solutions need to meet. Validate those requirements are met when the solution is delivered
- Perform Defensive / Offensive assessment on IT environment/applications to simulate attacks from real threat actors.
- Perform attack pattern analysis based on MITRE Attack framework, support solution development to address the pattern
To succeed in this role, you should have the following skills and experience
Soft Skills
- Excellent English language communication skills, both verbal and written. Cross-cultural etiquettes, customer centric and collaborative mindset.
- Works autonomously within established procedures and practices.
- Good command on stakeholder management, judgement, conflict resolution, risk & mitigations.
- Provides leadership to the global team at strategic, tactical, and operational level
- Maintains current knowledge of industry and regulatory trends and developments for the enterprise technology.
- Specialized in a number of Security domains such as incident response, operational assessment of security posture, general security management.
- Thourough understanding of Security Management principles, Security governance principles
- Good knowledge of MITRE Framework, IEC 62443/NIST 800:23/
- Understanding of SOC operations and Splunk is preferred
Qualification
- Bachelor’s or Master’s degree in Information Technology and or commensurate experience in delivering security solutions.
- Overall Enterprise IT Security experience of 10 yrs or more.
- Security Certifications such as CISSP, CISM, CISA, CIPP etc. preferred.