Required Skills: Candidate must have demonstrated architecture and control experience working with Amazon Web Services (AWS), to secure workloads.;Candidate must have an understanding of OWASP Top 10 and SANS 25 vulnerabilities and how to mitigate these vulnerabilities and an architecture/coding standpoint.;Mobile security architecture experience a plus;Candidate must have an understanding of the Cloud Security Alliance (CSA), Cloud Controls Matrix and how it can be leveraged for reviews of cloud solutions. Position Overview:
Essential Job Functions:
The contractor will have responsibilities for specific individual tasks and for working as an integral part of the team in executing ITSSR's work program. The primary responsibilities will include, but are not limited to, a combination of the following:
Work with project teams to define security requirements for new systems in line with the enterprise information security architecture;
Provide security design recommendations based on enterprise information security architecture and solution patterns.
Provide guidance and assist in the development of security standards for IT platforms in line with the information security architecture;
Maintain an up-to-date understanding of emerging trends in information security architecture; apply new techniques and trends, in-line with overall information security objectives and risk tolerance of the WBG, to the WBG's information security architecture;
Perform controls reviews and system assessments to develop risk profiles for IT systems and evaluate the efficiency and effectiveness of the IT control environment;
Maintain impartiality around IT systems to produce unbiased reports on information security risk;
Provide business units with recommendations to reduce information security risk within their areas;
Identify efficiencies to improve the performance and responsiveness of the ITSSR information security architecture function;
Prepare and present security design and architectural review reports to system owners, business units and other;
Evaluate WBG current software security posture and propose mitigation and remediation plans to meet software security assurance requirements;
Translate technical security deficiencies into business risks that are understandable by business stakeholders in order to get buy-in for security investments;
Education: Bachelor's degree in Computer Science, Information Systems or a related technical field.
Role Specific Experience: Minimum two (2 or 2+) years of experience working in an information security, software development, and information risk management related field. Certification Requirements:
Demonstrated experience enterprise security architecture design and implementation for a financial services organization or other organizations with similar information security needs and requirements.
Extensive knowledge of IT, enterprise architecture, software development life cycle, and information security platforms and applications;
Ability to work well under pressure and to meet tight deadlines. Demonstrates a high level of motivation, confidence, integrity and responsibility.
Knowledge of best practices and standards for enterprise security architecture specifically in the field of Identity & Access Management, Enterprise Content Management, Collaboration Tools, Service-Oriented Architecture, Cloud, Mobility, Data Analytics, and Web 2.0 related services.
Experience providing guidance for data protection based on data sensitivity and associated business risk.
Practical knowledge of common Web vulnerabilities as per SANS 25 or OWASP Top 10 specifications, and experience guiding project team remediating such vulnerabilities.
Industry certifications highly preferred including, but not limited to, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Global Information Assurance Certification (GIAC), and Information Systems Security Management Professional (ISSMP).
Demonstrate excellent interpersonal skills; including the ability to work independently, effectively in a team/task force as a team member or leader, and with senior staff and managers in the unit and elsewhere in the WBG.
Ability to collaborate with senior management stakeholders to identify requirements and drive compliance with approved standards.
Desired Skills/Abilities (not required but a plus)
Level III - 7+ years of experience "
Play a role of Security Architect and drive the initiative from Cognizant perspective
Architecture Design and Propose various solution options to the customer for a problem statement.