
Search by job, company or skills
SKILLS:
. The successful candidate is expected to support CSAD's new Security Exposure and Third-Party Cyber Assurance Centre of Excellence during its build phase.
. The role provides the hands-on technical and operational backbone across two tracks- Security Exposure Management (SEM), an outside-in, continuous view of the organization and its portfolio companies internet-facing attack surface, and Third-Party Cyber Assurance (TPCA), end-to-end due diligence and continuous assurance across third parties and the supply chain.
. Responsible to operate the always-on monitoring platforms, run third-party assurance, validate clear-and-present-danger threats, and drive remediation - narrowing the window between exposure and exploitation across organization, its portfolio companies, and third parties.
Key Responsibilities:
. Minimum 3 years of hands-on experience in cybersecurity operations, attack surface/exposure management, third-party cyber risk assessment, or data lake platforms.
. Strong practical experience in running third-party/vendor security assessments and questionnaires (VDD/ODD, SIG) and control frameworks (NIST, ISO 27001, CIS Controls).
. Hands-on experience with ASM/EASM, cyber exposure, or digital risk/dark-web monitoring platforms, and Cyber Threat Intelligence (CTI).
. Advanced scripting knowledge (e.g. Python, PowerShell, or Bash) to automate tasks and build reporting dashboards on data lake platforms.
. Solid understanding of TCP/IP, DNS, HTTP/S, common cloud exposures (AWS, Azure, GCP), and how third-/fourth-party risk propagates.
. Strong analytical, documentation, and communication skills, with discretion to handle sensitive findings.
. Good communication skill, with the ability to document processes clearly and liaise with technical and business stakeholders.
. Good team player, agile, fast learner, and able to adapt to changes
Good to have:
. Professional certifications: Security+, CEH, GIAC (GSEC, GCIH), CompTIA CySA+, or equivalent.
. CISSP Associate/CISM candidature.
. Experience in building operational dashboards and cyber posture scorecards.
. Familiarity with tuning detection logic and refining control baselines as a capability matures.
Job ID: 153750499
Skills:
Vulnerability Management, PowerShell, Bash, Dns, Http, Https, Iso 27001, Gcp, Threat Intelligence, Azure, Python, AWS, Third-Party Cyber Risk, CIS Controls, nist, Security Operations, Security Exposure Management
Skills:
Dns, Iso 27001, Gcp, Asm, Azure, AWS, cybersecurity operations, digital risk, attack surface exposure management, dark-web monitoring platforms, CIS Controls, data lake platforms, cyber exposure, ODD, third-party cyber risk assessment, third-party vendor security assessments, SIG, VDD, EASM, nist
Skills:
PowerShell, Gcp, Splunk, Azure, Python, AWS, EDRs, KQL, MITRE ATT CK, Elastic, SIEM platforms, SPL, YARA, Jupyter Notebooks, Sigma, Cyber Kill Chain, nist