Security Specialist

hace 18 horas


Bogotá, Bogotá D.E., Colombia GSB A tiempo completo
About GSB

GSB is a leading company committed to delivering top-notch services to its clients, driven by a vision to expand its global presence continuously.

About the Role

We are seeking a highly skilled Security Specialist to join our team. As a key member of our security team, you will be responsible for ensuring the security and integrity of our applications and systems.

Main Responsibilities:
  1. Threat Modeling and Security Analysis: Conduct thorough threat modeling analysis, security requirements, and abuse cases for all developments carried out in ADC.
  2. Security Risk Assessment: Analyze changes to existing software to identify potential security risks that can be implemented in the coding process.
  3. Vulnerability Identification: Identify vulnerabilities in the source code and runtime application.
  4. Security Controls and Remediation: Determine and advise on the recommended security controls required to remediate findings and issues in an efficient and concise manner.
  5. Awareness and Training: Generate awareness campaigns to all stakeholders of the software process.
  6. Secure Coding Practices: Help developers use secure coding practices and resolve specific doubts about vulnerabilities identified in different testing scenarios.
  7. Security Solutions and Standards: Align security solutions to Holcim methodologies and standards.
  8. Security Model Design and Implementation: Design, implement, and support the security model for general security solutions.
  9. Security Best Practices and Standards: Develop and drive the implementation of security best practices and standards.
  10. Security Audits and Compliance: Review requests for new systems or changes to existing systems and evaluate the impact to security. Conduct pre-audits on security issues of concern, work with the user community on remediation, and conduct spot checks of user security to ensure compliance.
  11. Technical Support: Provide technical support for security issues related to in-scope applications, infrastructure as code, and cloud services.
  12. Collaboration and Expertise: Provide support to other colleagues in terms of technical/functional expertise with the assigned business processes.
  13. Vulnerability Management Tools: Expert in Vulnerability Management tools like Qualys or Nessus.
Requirements:
  1. Education: Bachelor's degree in Computer Science, Engineering, or related discipline with an IT focus.
  2. Certifications: CISSP, CISM, CISA, CRISC ITIL, CMMI, ISO 27001, GSEC, CSSLP.
  3. Desired Certifications: Ethical Hacking certifications and Secure coding certifications.
  4. Experience: At least 4 years of experience in IT Security and development, delivering applications with a secure focus, assessments, and audits.
  5. Desired Experience: Experience in full-stack development, object-oriented programming, microservices-oriented architecture, with knowledge in agile methodologies and DevOps model.
Desired Skills:
  1. Secure Development and Ethical Hacking: Experience on secure development and ethical hacking.
  2. Vulnerabilities and Fixes: Experience with vulnerabilities and fixes for different languages (C, C#, Java, Javascript).
Soft Skills:
  1. Coordination and Time Management: Experience coordinating and completing multiple tasks within established and changing deadlines.
  2. Communication and Problem-Solving: Excellent oral and written communication skills necessary to interact effectively with colleagues and users of varying technological skill levels.
  3. Customer Service Orientation: Strong customer/end-user/client service orientation.
  4. Teamwork and Self-Motivation: Thrives working in a highly collaborative and team environment.
  5. Attention to Detail: Keen attention to detail.
  6. Problem-Solving and Decision-Making: Capability for problem-solving, decision-making, sound judgment, assertiveness.
  7. Stakeholder Management: Ability to deal with difficult situations, unclear priorities, and blocking stakeholders.
  8. Workload Management: Ability to work decisively under heavy workload considering the criticality, urgency, and extended work hours required to ensure availability of the service in accordance with service level commitments.
  9. Cultural Competence: Ability to manage multi-cultural and multi-located teams.
Leadership Skills:
  1. Leadership by Example: Lead by example on values and culture.
  2. Communication and Credibility: A natural leader whose personality and communication skills instill a sense of credibility and trust.
  3. Stakeholder Engagement: Able to coherently explain the proposed design and gain stakeholder buy-in to the proposed solution.
  4. Cost Consciousness: Cost conscious and keeps a big picture perspective.
Required Skills:
  1. Authentication and Access Control: Authentication and Access Control Tools, Management and Administration.
  2. Application Security Architecture: Application Security Architecture & Cloud Computing Concepts.
  3. Change and Security Configuration: Change & Security Configuration Audit and Control.
  4. Encryption: Encryption Processes, Management and Administration.
  5. Static and Dynamic Security Testing: Experience in static and dynamic security testing (code review, vulnerability analysis, Ethical Hacking).
  6. Offensive Security Methodologies: Knowledge in offensive security methodologies (OWASP, MASVS, OPENSAMM, CKC, etc). Knowledge in tools such as OwaspZap, Burpsuite, Nessus, Service Manager, Git, Fortify, Codacy, Sonarqube.
Desired Skills:
  1. AWS Cloud Security: Knowledge in AWS cloud security.
Languages:
  1. English: English desired (written & spoken).
  2. Spanish: Spanish required (written & spoken).
Benefits:
  1. Law Benefits: Law benefits.
  2. Courses and Certifications: Courses and certifications.


  • Bogotá, Bogotá D.E., Colombia Amadeus A tiempo completo

    About the RoleWe are seeking a highly skilled Cyber Security Specialist to join our team at Amadeus. As a key member of our Security Operations Center (SOC), you will play a critical role in protecting our organization from cyber threats.Key ResponsibilitiesMonitor and Analyze Security Events: Utilize advanced tools and techniques to monitor and analyze...


  • Bogotá, Bogotá D.E., Colombia Universidad Católica de Oriente A tiempo completo

    Job DescriptionThe Universidad Católica de Oriente is seeking a highly skilled Cloud Security Specialist to join our team. As a key member of our security team, you will be responsible for implementing and maintaining security controls across our cloud and on-premises infrastructure.Key ResponsibilitiesInfrastructure Security: Implement and manage security...

  • Security Specialist

    hace 2 días


    Bogotá, Bogotá D.E., Colombia GSB A tiempo completo

    About the RoleWe are seeking a highly skilled Security Specialist to join our team at GSB. As a key member of our security team, you will be responsible for ensuring the security and integrity of our applications and systems.Main ResponsibilitiesConduct threat modeling analysis, security requirements, and abuse cases for all developments carried out in...

  • Cloud Security Specialist

    hace 2 semanas


    Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    General Overview The Cloud Security Specialist plays a crucial role in the development and implementation of secure cloud solutions, ensuring that all necessary security measures and requirements are integrated into the cloud architecture. Key Responsibilities Safeguard the organization's cloud assets in accordance with applicable governance laws,...

  • Cloud Security Specialist

    hace 2 semanas


    Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    General Overview The Cloud Security Specialist plays a pivotal role in the design and engineering of secure cloud environments, ensuring that all necessary security controls and requirements are integrated into cloud solutions. Key Responsibilities Safeguard the organization's cloud assets in accordance with governance laws, regulatory compliance, and...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Job SummaryWe are seeking a highly skilled Cyber Security Specialist to join our team at Scotiabank. As a key member of our Cyber Problem Management team, you will play a critical role in ensuring the overall success of our operations.Key ResponsibilitiesConduct Post-Incident Response: Lead the post-incident response process for cyber incidents globally,...


  • Bogotá, Bogotá D.E., Colombia Pinkerton A tiempo completo

    Job Summary:The Security Coordinator assigned to a specific client will be responsible for developing all security programs, personnel, contractors, and consultants. The coordinator will be responsible for the strategic identification of security risks, threats, and vulnerabilities as well as the prevention and protection of the client's employees, assets,...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Job SummaryWe are seeking a highly skilled Web Application Security Specialist to join our team at ScotiaTech. As a key member of our Cybersecurity Program, you will play a critical role in monitoring and reporting vulnerabilities found on Scotiabank web applications.About the RoleThe Web Application Security Program's main objective is to provide monitoring...


  • Bogotá, Bogotá D.E., Colombia Michael Page Colombia A tiempo completo

    About Our ClientOur client is a leading IT consulting firm, providing expert services to businesses across various industries.Job DescriptionThe successful candidate will report to the Management team and be responsible for:Managing and maintaining network infrastructure, including implementation and delivery of IT security projects, assessments, and...


  • Bogotá, Bogotá D.E., Colombia Universidad Católica de Oriente A tiempo completo

    About the RoleThis position involves utilizing a risk-based methodology to conduct in-depth technical analysis of cybersecurity threats, implementing security requirements for integrated systems, and advising stakeholders on defense-in-depth strategies. The Cyber Security Specialist will lead large-scale security projects, conduct urgent security testing and...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleThe Team Lead is responsible for leading a group of cybersecurity analysts, reviewing, assessing, and developing their analytical and technical skills. This role requires a strong desire to develop and train security analysts, investigators, and responders to fortify Scotiabank's controls.Key AccountabilitiesChampion a customer-focused culture...


  • Bogotá, Bogotá D.E., Colombia Johnson Controls A tiempo completo

    Job DescriptionJob Title: Technical ConsultantJob Summary:We are seeking a highly skilled Technical Consultant to join our team at Johnson Controls. As a Technical Consultant, you will be responsible for providing expert advice and support to clients regarding the implementation, optimization, and maintenance of electronic security systems.Key...


  • Bogotá, Bogotá D.E., Colombia Radware A tiempo completo

    Key Responsibilities: Act as a senior technical point of contact and escalation leader for the Security Operations Center (SOC), collaborating with various teams within Radware Cloud to deliver exceptional service. Oversee, mentor, and guide security analysts in their efforts to protect global clients from cyber threats and attacks. Conduct risk assessments...


  • Bogotá, Bogotá D.E., Colombia Twilio A tiempo completo

    About the RoleWe are seeking a highly skilled Cloud Security Data Engineer to join our team at Twilio. As a key member of our Information Security Team, you will play a critical role in building and maintaining our Security DataLake, a centralized platform for security data from various sources across our vast portfolio of security tooling.Key...


  • Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    About the RoleSOS Trabajo is seeking a highly skilled AWS Cloud Security Engineer to join our team. As a key member of our security team, you will be responsible for ensuring the security and compliance of our cloud-based platforms.Key ResponsibilitiesCloud Security Architecture: Design and implement secure cloud architectures and designs, identifying...


  • Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    About the RoleSOS Trabajo is seeking a highly skilled Cybersecurity Specialist to join our team. As an Incident Response Specialist, you will be responsible for providing technical leadership in the creation, establishment, and maintenance of the information technology/security risk framework, processes, and controls.Key ResponsibilitiesLead Security...


  • Bogotá, Bogotá D.E., Colombia Twilio A tiempo completo

    About the RoleWe are seeking a highly skilled Cloud Security Data Engineer to join our team at Twilio. As a key member of our Information Security Team, you will play a critical role in building and maintaining our Security DataLake, a centralized platform for security data from various sources across our vast portfolio of security tooling.Key...


  • Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    About the RoleSOS Trabajo is seeking a highly skilled AWS Cybersecurity Engineer to join our team. As a key member of our organization, you will be responsible for ensuring the security of our cloud-based platforms and implementing secure cloud technical solutions.Key ResponsibilitiesCloud Security StrategyDevelop and implement cloud security strategies to...

  • Identity Access Manager

    hace 19 horas


    Bogotá, Bogotá D.E., Colombia Alexandra Lozano Immigration Law PLLC A tiempo completo

    About Alexandra Lozano Immigration Law PLLCWe are a dynamic and mission-driven company dedicated to changing the lives of the Latino immigrant community through zealous advocacy, finding creative solutions and aggressive legal strategies.Job SummaryWe are seeking a detail-oriented and experienced Identity Access Manager to join our team. As an Identity...


  • Bogotá, Bogotá D.E., Colombia Convatec A tiempo completo

    About ConvatecConvatec is a leading global medical products and technologies company, dedicated to delivering innovative solutions for the management of chronic conditions. Our mission is to improve the lives we touch through pioneering trusted medical solutions.Key ResponsibilitiesInformation Security Management: Develop and implement a robust information...