GLOBAL IT SENIOR SECURITY ANALYST
The Global IT Senior Security Analyst will work closely with the entire Global IT Team and all levels of management to ensure that cyber security services are provided as outlined. The role will also work closely with the Portfolio Management teams, partners and customers as needed. This role reports to the Global IT Security Manager and will be located in Glen Mills, PA.
Essential Job Functions
• Conduct internal, external and 3 rd party IT audits, risk assessments, and vulnerability scans.
• Liaise with other governance functions such as physical Security/Facilities, Internal Audit, IT, HR, Legal, and Compliance.
• Respond to computer security incidents, in-depth computer and network investigations. Assist in or lead incident response to a successful completion.
• Oversee installation, upgrades, and configuration of Information Security software. Make sure issues are properly coordinated, tracked, monitored and resolved globally.
• Be an Information Security subject matter expert (SME) that's part of an information security center of excellence; offering internal management consultancy advice and practical assistance on information security risk and control matters.
• Drive for consistent deployment of information security policies, standards, procedures, guidelines and training.
• Assess Information Technology technical controls, policies and procedures for control gaps. Recommend and support deployment of mitigations design on business need and risk.
• Develop new and improve existing technical documentation.
• Work as a team player.
• Perform Security Risk Assessments, identifying gaps and recommending mitigating controls.
• Develop and present project related material (e.g. to key stakeholders, peers, etc.).
• Support an Application Security program working closely with the DevOps, application development and QA teams.
• Maintain documentation related to the Application Security program including the development of secure coding policies, procedures and standards, modification of the Software Development Life Cycle (SDLC) to include necessary security checkpoints, code review methodologies, etc.
• Pursue understanding of application security requirements early-on and incorporate into secure code development practices.
• Maintain knowledge of new security trends and technologies.
• Support the assessment and acquisition of application security tools and technologies.
• Attend design and application architectural reviews to establish expertise and assimilate knowledge of the environment.
(INDHP)
Qualifications
• Bachelor's degree in Computer Science / Information Security or related field.
• CISSP or Associate certification required, CISA, CRISC a plus.
• A minimum of (8+) eight plus years' experience in Information Security and/or Technical projects, including experience leading large global projects.
• Experience with Cyber Security related technologies and large enterprise implementations.
• Practical knowledge of Information Security Management Systems and compliance standards as ISO 27000, SOX and PCI.
• Understanding of key security services, such as Internet Content Filtering, Remote Access, Firewalls, IDS/IPS, Virus Protection, AAA (including 2Factor), Digital Certificates and PKI.
• Understanding of Public Cloud services.
• Must possess strong and demonstrated organizational, communication, and negotiation skills.
• Must be able to lead multi-disciplined project teams through project lifecycle (planning-development-implementation-closeout).
• Demonstrated knowledge in project packages, detailed project plans, project risk identification and mitigating strategies.
• Must be able to demonstrate field presence during the planning and installation phases of the project.
• Must have experience with multi-national corporations.
• Must be able to travel internationally periodically.
• Must understand the concepts of Authentication, Authorization and Accounting.
• Technical knowledge of Microsoft Windows environments (Windows 7-10.x, Server Platform) as must, MacOS a plus.
• Understanding of Risk and the need for risk based reviews and controls.
• Understanding TCPIP and basic network technologies, advanced knowledge is a plus.
Our Company:
Axalta has remained at the forefront of the coatings industry by continually investing in innovative solutions. We engineer technologies that protect customers' products - whether they are battling heat, light, corrosion, abrasion, moisture, or chemicals - and add dimension and beauty with colorful finishes. We have a vast and ever-evolving portfolio of brands primed to play an important part in everything from modernizing infrastructure around the world to enabling the next generation of electric and autonomous vehicles.
Axalta operates its business in two segments: Performance Coatings and Mobility Coatings, which serve four end markets, including Refinish, Industrial, Light Vehicle and Commercial Vehicle, across North America, EMEA, Latin America and Asia-Pacific. Our diverse global footprint allows us to deliver solutions in over 140+ countries and coat 30 million vehicles per year. We've recently set an exciting 2040 carbon neutrality goal, in addition to 10 other sustainability initiatives, and we take pride in working with our customers to optimize their businesses and achieve their goals.