Vulnerability Management Officer
Full Time Phnom Penh Posted 2 weeks ago
Technology
JOB RESPONSIBILITIES
- 100% is to focus on security scanning, vulnerability assessment.
- Work with offensive team to plan for security scanning, audit configuration settings
- Support and assist in vulnerability management program
- Setup, implement, develop and troubleshooting vulnerability management tools and technology
- Test, research and recommend vulnerability management tools
- Conduct security scanning, configuration scanning based on compliance requirements, projects and prepare remediation report, dashboard.
- Provide recommendation, and work with infrastructure and development team to fix all vulnerability findings
- Provides analysis and validation post remediation, opportunities for improvements and out of the box thinking for optimizations and solving roadblocks.
- Work with third-party vendors and other security teams in improving the overall security threats and security scanning process.
- Stay current with vulnerability information and threats across all the products and technology in Wing Bank
- Inform, track, follow up all security findings that reported.
- Work and verifying the security of third-party vendors and collaborating with them to improve security requirements.
- Coordinate between internal and external firm Audit, BNC and other
- Coordinate between internal and external vulnerability assessment or Penetration Tester firm
- Coordinate between internal and external PCI-DSS or ISO standard firms to completed project
JOB REQUIREMENTS
- Graduated bachelor degree of Information Technology, preferably in the field of Computer Science.
- Self-learning any security related course or own lab development is advantaged
- Fresh graduate or first year experience in IT related work.
- Basic knowledge of security hacking and security tools
- Basic knowledge of security framework such as OWASP
- Basic knowledge or experience in working with OS: Windows Server, Linux (red hat/CentOS), container and VMware.
- Basic knowledge or experience in networking and understanding of OSI/TCP-IP model.
- Basic knowledge or experience with applications/service like web server, DNS, mail server, database, etc.
- Knowledge or experience in vulnerability management tools setup, implement and use.
- Knowledge or experience in security scanning/vulnerability scanning
- Knowledge or experience in configuration management.