The primary responsibilities Of Security & Governance Analyst are to manage the application security in conjunction with the application and digital team, continuously monitor systems for security breaches, monitor application access, respond to incidents, assess vulnerabilities, conduct audits and assessments, document compliance with security frameworks, and preparing for external audits. Ensure that security practices align with industry regulations and internal policies.
Collaborate with development teams to ensure secure coding practices and conduct security assessments throughout the software development lifecycle.
Continuously monitor systems for security breaches and respond quickly to investigate and mitigate incidents.
Manage and review user access permissions to ensure compliance with the least-privilege principle and prevent unauthorized access.
Conduct regular vulnerability scans and collaborate with technical teams to remediate security weaknesses in applications and infrastructure.
Ensure adherence to security frameworks and regulations and maintain proper documentation for compliance and audit purposes.
Perform internal security audits to assess compliance with policies and identify areas for improvement in security controls.
Support the development of security awareness training for staff and provide guidance on secure practices and incident reporting.
Assist in preparing for external security audits and provide necessary documentation to auditors for compliance verification.
Contribute to the creation and maintenance of security policies and procedures to align with industry standards and business goals.
Help define and implement security strategies that enhance the organization’s security posture and continuously improve security processes.
Strong understanding of security governance, risk management, and compliance requirements.
In-depth knowledge of application security practices and secure development lifecycles (SDLC).
Familiarity with identity and access management (IAM) best practices and tools.
Proficiency in security tools and technologies such as vulnerability scanners, penetration testing tools, and security information and event management (SIEM) platforms.
ERP Knowledge preferably SAP functional skills are a requirement to be successful in this role.
Minimum 5 years working experience, 3 years relevant working experience, 2 years GCC experience is a plus.