Responsibilities
- Implement and manage cyber security measures to safeguard the information systems and data of the oil and gas company.
- Conduct regular security assessments, vulnerability scans, and penetration testing to identify and address potential risks.
- Monitor network traffic, system logs, and security alerts to detect and respond to security breaches and threats.
- Develop and maintain security policies, procedures, and guidelines in alignment with industry standards.
- Collaborate with cross-functional teams to implement and maintain security solutions, including firewalls, intrusion detection systems, and encryption tools.
- Stay updated on emerging cyber security threats, attack vectors, and mitigation strategies.
- Investigate security incidents, analyze root causes, and implement corrective actions.
- Provide training and awareness programs to educate employees on cyber security best practices.
- Prepare and present cyber security reports, metrics, and recommendations to management.
- Develop and implement disaster recovery and incident response plans.
- Ensure compliance with relevant regulations, laws, and industry standards.
Requirements
- Bachelor’s degree in computer science, information technology, or a related field. Cyber security certifications (CISSP, CISM, etc.) are preferred.
- Minimum of 5 years of experience in cyber security, preferably in the oil and gas industry.
- Strong understanding of cyber security principles, best practices, and technologies.
- Proficiency in network security, vulnerability assessment, and risk management.
- Knowledge of security frameworks and standards (ISO 27001, NIST, etc.).
- Experience with security tools and technologies such as firewalls, intrusion detection systems, SIEM solutions, etc.
- Excellent problem-solving skills and the ability to analyze complex security incidents.
- Effective communication skills for collaborating with technical and non-technical stakeholders.
- Ability to stay current with evolving cyber threats and security trends.
- Ethical conduct, integrity, and confidentiality in handling sensitive information.
- Experience with security audits, compliance, and regulatory requirements.
- Knowledge of the oil and gas industry’s IT infrastructure and cyber security challenges is a plus.