Job Purpose
The role will be serving as Security Operations Lead Expert – focusing on infrastructure and applications. This role involves conducting routine evaluations of infrastructure and application vulnerabilities, continuous monitoring, gathering and examining vulnerability data, and providing vulnerability mitigation strategies and recommendations to the IT Teams.
For the Security Operations Lead Expert role, the sources of information may encompass, but are not limited to, security alerts, vulnerability scanning reports, security testing activities, vendor-published vulnerabilities, and internal/external threat intelligence sources. Moreover, the position may necessitate the candidate to assist incident handlers during major application-related security incidents.
Responsibilities
- Join and lead the vulnerability management team based in Asia, collaborating closely with global domain teams located worldwide.
- Serve as the Subject Matter Expert in the field of vulnerability management within the infrastructure and application security domain.
- Utilize various automated tools, such as Qualys (DAST), BurpSuite, and Checkmarx, to detect vulnerability issues in infrastructures and applications.
- Evaluate the impact of vendor security advisory notifications and communicate findings to relevant stakeholders to devise solutions.
- Prioritize active critical vulnerabilities for remediation based on a risk-based approach and/or the organization's risk appetite.
- Monitor, track, and document all vulnerability status updates in the registry.
- Oversee and coordinate all work related to application vulnerability management in Asia.
- Coordinate with the local Entity Security team to address vulnerabilities detected through the vulnerability management process.
- Analyze structured and unstructured datasets from various sources to identify vulnerabilities and provide remediation recommendations.
- Provide technical guidance to IT Production or Development Teams to effectively remediate vulnerabilities.
- Ensure timely follow-up for vulnerability remediation and assess the risk impact according to internal risk methodologies and frameworks.
- Recommend compensatory measures when remediation is not possible and ensure that the risk acceptance process is followed.
- Own and continuously optimize the application vulnerability management process.
- Assist in investigating security issues by reviewing vulnerability identification results.
- Assist in incident handling, including implementing containment, protection, and remediation activities.
- Perform manual security testing using tools such as BurpSuite and other open-source tools.
- Be flexible in supporting the streamlining of the application security process and SDLC.
- Support initiatives for improving the overall application security maturity framework and process.
- Support Cloud migration projects from a threat and vulnerability management perspective and establish new processes.
Your ProfileProfile and Qualifications
- Minimum of 10-12 years of experience in Vulnerability Management and Assessment, specifically related to Infrastructure and Application.
- Overall experience of at least 15+ years
- Bachelor's degree in IT/Computer Science, Engineering, or a related field.
- Proven experience in implementing SDLC and Application Security for enterprise products/applications.
- Extensive experience in SAST/DAST onboarding and rollout.
- Strong understanding of vulnerability assessments, including vulnerability scanning and security testing, as well as infrastructure security reviews for servers, web, and mobile applications.
- Hands-on experience working with Qualys, BurpSuite, and other application vulnerability scanning/penetration testing tools.
- Assist in challenging vulnerability findings from penetration testing activities conducted by independent third-party assessors.
- Strong technical understanding of threat and vulnerability assessment activities, processes, and systems.
- Extensive experience in manual testing methodologies for web/mobile applications, including penetration testing, and tools such as BurpSuite (OSCP skill set preferred).
- Familiarity with the OWASP framework and secure development of applications.
- Security certifications such as GWAPT, CISSP, CEH, CHFI, or equivalent are highly desirable.
- Strong knowledge of patch management, network security, end-point security, secure access management, server system administration, system hardening, secure coding, and application security design.
- In-depth knowledge of applying security controls to technology operational services.
- Excellent communication skills, both written and verbal (English), to communicate effectively with a wide range of stakeholders. Proven ability to explain security issues in business language and business issues in security language.
- Ability to produce high-quality output with a strong focus on attention to detail, while following design and delivery methods, tools, and standards.
Domain Knowledges Reference -
- Penetration testing of web applications (preferred).
- Threat and vulnerability assessment (preferred).
- Application security, including DevSecOps, SAST/DAST, and manual testing (preferred).
- Infrastructure security, including system and operating system hardening (preferred).
- Knowledge of data security, specifically encryption (bonus).
- Familiarity in Network Security (WAF, DDOS, Proxy, IPS), End-point Security (Anti-Virus, EDR, DLP), Access Management, SOC, and Security Incident Management (bonus)
- Knowledge of cloud security, including IaaS, PaaS, and SaaS (bonus).
About AXAAs a world-leading insurance company, we act for human progress by protecting what matters. With 153,000 employees in 54 countries working with 105 million customers, we’ve created a truly dynamic and vibrant community. Inclusion and diversity link closely with our values, and together we’re nurturing a culture of
respect, for each other, for our customers and the communities around us. Join AXA and you’ll feel like you belong, are included and can thrive. You’ll be able to shape the way you work and truly grow your potential as you seek out new opportunities, push boundaries and benefit people in critical moments of their lives. This is your chance to build the tomorrow you want. Know you can.
About the EntityAXA is becoming a sustainable tech-led company and at AXA Group Operations we are one of the major catalysts for this transformation.
We set the tone by triggering and empowering the evolution of our insurance business model through technology and innovation, driving its concrete implementation globally at speed, with a high quality of advisory and execution.
We are present across 17 countries with committed, highly qualified teams. We leverage technology, data, sourcing, security and investment allocation in a global way, but also achieve economies of scale and synergies when necessary.
At AXA Group Operations, we want to be recognized in three fields of action:
- State-of-the-art Data Technology to drive customer experience
- State-of-the-art Procurement & Sourcing to drive efficiency and better manage risks
- High-Performing Global Team for stronger partnerships with AXA entities
What We OfferWe bring together the expertise, cultural diversity and creativity of over 8,000 employees worldwide and we’re committed to equal opportunities in all aspects of employment (gender, LGBT+, disabled persons, or people of different origins) and to promoting Diversity & Inclusion by creating a work environment where all employees are treated with dignity and respect, and where individual differences are valued.