Information Security Analyst
Position Purpose
Preventing, mitigating, and responding to major information and cyber security events, security incidents, and security breaches. This includes researching, recommending, implementing, and operating technologies, controls, and processes that will effectively protect and defend the information systems in use across our portfolio of brands. Ensuring minimal system downtime and reducing the impact of attacks and operational outages through enhanced cybersecurity defence strategies and processes.
This is a global role that will require work with all regions in which our brands operate. Successful applicant will oversee security events across more than 2,000 IT assets; help to secure our more than 400 applications and IT systems; and educate and interface with 5,000 employees across our global enterprise.
This role requires continuous upskilling in information and cyber security defence strategies, techniques, and technologies to align with industry, threat, and attacker trends, as well as the demands of the role. Successful applicant will generate and implement recommendations for measurably improving security across the brands.
Role Accountabilities
Accountability: Security Engineering and Architecting
- Participate in complex, global IT projects across Applications, Infrastructure, Security, and wider business initiatives to provide security engineering, solution implementation, and to ensure that best-practice security controls are implemented and tested. Examples include consulting on security considerations when the business is implementing a new ERP system, designing SIEM use cases and onboarding event sources, participating in secure network / zero trust redesigns, uplifting our filtering technology stack, enhancing our patching and vulnerability management tooling and process, and more.
- Research and assess new threats, security patches, and alerts, and recommend or implement remedial actions.
- Research, evaluate, design, test, recommend, plan, and help to implement new and existing information security technologies, including creating the business case for security investments.
- Review and implement security policies, principles, and standards and recommend updates as appropriate.
- Other security architecture and engineering objectives as required.
Accountability: Incident Detection and Response
- As a key member of the Computer Security Incident Response Team (CSIRT), successful applicant will respond to Major Incidents. This includes ransomware events, data exfiltration, security detections and incidents, and privacy breaches using the business’s Incident Response Plan, including the occasional out-of-hours response for high priority or urgent incidents.
- Stay up to date on the latest threat intelligence and countermeasures, including attacker methodologies and emerging security technologies.
- Engage in proactive threat-hunting and reactive response using the various technologies leveraged by the business, including our EDR/XDR, SSE, SIEM, vulnerability management toolset, email and web filters, and other technologies.
- Provide incident investigation and reporting, and security awareness training for those involved in incidents.
- Assist the relevant IT stakeholders in the resolution of reported security incidents.
- Monitor event-based or scheduled alerts, reports, and logs for potential threats and aberrative events.
Accountability: Strategy & Interfacing with Senior Management
- Interface with Senior Management, as well as Rip Curl, Kathmandu, and Oboz IT & Systems Departments to develop and implement the business’s risk-based security program and projects, security awareness training, and technological uplifts to address identified risks and business security requirements.
- Create regular high-level reports and deliverables based on security metrics.
- Manage the process of gathering, analysing, and assessing the current and future threat landscape, as well as provid