Detailed JD (Roles and Responsibilities) Responsibilities · Development and execution of the enterprise-wide application and data security program and associated performance metrics. · Review design documents, identify and communicate potential cybersecurity gaps to project teams for remediation · Apply cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). · Lead risk identification efforts and communication of the risks and mitigating controls to stakeholders to manage cybersecurity risks within the organisation · Research industry’s best practice and vendor’s cybersecurity capabilities to mitigate emerging threats · Provide application security services including application security scans and cloud asset vulnerability management · Development and maintenance of the Cloud Security Posture Management capability for secure hosting of applications. · Act as an escalation point for the first level SOC and Cloud Security Governance teams About You As the successful candidate you will possess the following: · Good experience in the industry (Mining, Resources, Banking or Telco), domain areas (Secure-by-Design Application Development, DevSecOps, Application Security, Cloud Security). · Certified as a Cyber Security Professional (CISSP, CISM preferred or equivalent) · Cloud Cybersecurity certifications (Azure preferred or AWS equivalent) · Understanding of industry regulatory and compliance requirements like ISM, NIST and ISO27001 · Expert level in configuring and utilizing computer protection components (e.g., hardware firewalls, servers, routers, as appropriate) in general but also in particular for applications, M365 and Azure/AWS cloud environments · Prior experience as cloud engineer or architect building and implementing cloud technology in large scale environments favourable