Scope of Work
Vulnerabilities Management
- Arrange Bi-weekly vulnerability review meeting with application team.
- Consolidate the results from the various vulnerabilities platform (i.e. AppScan, SonarQube and Nexus Scanning)
- Perform quarterly result consolidating and seek risk acceptance for extension of vulnerability remediation timeline.
- Perform result consolidating and tracking of risks and timeline from other sources.
Security Testing
- Prepare all the pre-requisite (e.g. software installation, firewall request, laptop request) to ensure security testing can be started timely.
- Perform technical resolution for AppScan, SonarQube, Nexus and SHIP-HATS or any other security tools when required.
- Conduct network vulnerability scan (Nmap scanning).
Security Training
1. Administer the Secure Code Warrior training
Other Security Related Task
- Track and coordinate the regular review activities of all IT systems
- Track and coordinate the regular review activities for all SaaS