Sobre esta vaga de Network & Information Security Officer na GSSTech Group
We are looking for a Network & Information Security Officer to support day-to-day network operations and cybersecurity activities, ensuring a secure, reliable, and resilient IT infrastructure.
The role will support network monitoring, security event monitoring, firewall and VPN administration, endpoint security, vulnerability management, incident response, security controls, and information security compliance activities.
The ideal candidate will have a solid foundation in networking and cybersecurity, hands-on exposure to security tools and SIEM platforms, and the ability to work collaboratively with infrastructure, applications, information security, risk, compliance, audit, and external technology partners.
Requirements
Key Responsibilities
- Monitor network performance, availability, and security events to identify potential issues, threats, and anomalies.
- Monitor and respond to cybersecurity incidents, alerts, and security events in accordance with defined procedures and SLAs.
- Assist with the administration and management of firewalls, VPNs, network devices, and other network security controls.
- Support the implementation, maintenance, and monitoring of information security controls, policies, and procedures.
- Conduct basic vulnerability assessments and support vulnerability remediation and patch tracking activities.
- Support endpoint security, antivirus, and endpoint protection solutions.
- Monitor and maintain security logs, reports, and relevant operational documentation.
- Assist with security investigations, incident analysis, escalation, and resolution.
- Support network and security troubleshooting and coordinate with relevant infrastructure and application teams when required.
- Assist with cybersecurity risk management activities and implementation of security controls.
- Support information security audits, compliance activities, and evidence collection.
- Contribute to compliance with ISO 27001, internal security policies, standards, and procedures.
- Maintain accurate security documentation, incident records, reports, and operational procedures.
- Work closely with internal IT infrastructure, network, application, information security, risk, compliance, and audit teams.
- Coordinate with external cybersecurity vendors, managed security service providers, firewall/SIEM/endpoint security vendors, and IT infrastructure partners where required.
- Support continuous improvement of network security, cybersecurity monitoring, incident response, and operational processes.
Required Technical Skills
Networking
- Basic to intermediate understanding of networking concepts.
- Strong understanding of TCP/IP, routing, and switching.
- Familiarity with network devices and network infrastructure.
- Understanding of network availability and performance monitoring.
- Familiarity with firewalls and VPN technologies.
Cybersecurity
- Understanding of fundamental cybersecurity principles.
- Basic knowledge of cybersecurity risk management.
- Basic understanding of security architecture.
- Basic understanding of threat analysis.
- Basic understanding of security incident management and incident response.
- Familiarity with endpoint security and antivirus solutions.
- Exposure to vulnerability assessment, vulnerability tracking, and patch management.
- Experience or exposure to security monitoring and security event analysis.
- Experience with SIEM tools.
- Familiarity with security tools and security monitoring platforms.
Security Compliance & Frameworks
- Understanding of information security frameworks, standards, and controls.
- Exposure to ISO 27001 and information security compliance activities.
- Understanding of internal security policies and procedures.
- Exposure to cybersecurity audits, compliance requirements, and security documentation.
Operating Systems & Productivity Tools
- Good working knowledge of Windows OS.
- Good knowledge of Microsoft Office applications.
Education
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Security, or a related field.
Certifications
Candidates with one or more of the following certifications are preferred:
- CCNA
- CompTIA Security+
- CEH – Certified Ethical Hacker (basic/intermediate level)
Experience
- Minimum 2 years of professional experience in networking and/or information security.
- Practical exposure to network operations, cybersecurity monitoring, or infrastructure security.
- Experience working with SIEM tools and security monitoring solutions.
- Experience or exposure to firewalls, VPNs, endpoint security, vulnerability management, and security controls.
Key Competencies
Technical Competencies
- Cybersecurity Risk Management – Basic
- Security Architecture – Basic
- Threat Analysis – Basic
- Incident Management – Basic
- Cybersecurity Audit & Compliance – Basic
Behavioral Competencies
- Stakeholder Engagement
- Results Orientation
- Collaboration
- Effective Communication
- Adaptability
- Professionalism
Candidates should demonstrate the ability to communicate clearly with both technical and non-technical stakeholders, work collaboratively across teams, adapt to changing priorities, and maintain a strong level of professionalism and accountability.
Key Stakeholders
Internal
- IT Infrastructure & Network Team
- Applications / Systems Teams
- Information Security, Risk & Compliance Teams
- Internal Audit
- Business departments
- Employees requiring security awareness and incident support
External
- Cybersecurity technology vendors
- Firewall, SIEM, and endpoint security vendors
- Managed Security Service Providers (MSSPs), where applicable
- IT infrastructure vendors and support partners
- Regulatory and compliance entities, where required
Performance Expectations
Success in this role will be measured through:
- Timely identification, escalation, and response to security incidents within defined SLAs.
- Effective resolution of security incidents with minimal operational impact.
- Maintaining high network availability and supporting reliable network operations.
- Timely identification and escalation of network performance issues.
- Vulnerabilities being assessed, tracked, and remediated within defined timelines.
- High patch compliance across supported systems.
- Adherence to security controls, policies, standards, and procedures.
- Accurate and complete security logs, incident records, and reports.
- Effective support of endpoint protection and security tools.
- Accurate and up-to-date security documentation and process adherence.
- Minimal major security or compliance findings.