Чем предстоит заниматься
Conduct regulatory compliance audits and assessments utilizing frameworks like CMMC, NIST, CSF, ISO, PCI, HIPAA, etc
Create and update cybersecurity related policies and procedures
Participate in the creation of cybersecurity awareness training programs, materials and conduct training sessions
Perform scripted penetration testing and vulnerability scanning utilizing tools like Clone Systems
Review and deliver penetration testing and vulnerability scanning reports to clients
Participate in the on-boarding of clients into GRC tools like Apptega
Provide training and support to clients for our GRC tools
Participate in activities related to phishingsocial engineering testing, physical security assessments, and tabletop exercises
Participate in activities related to our advisory services offerings including planning, budgeting, presentation building, crisis management, etc
Participate in activities related to cybersecurity incident response and remediation
Keep abreast of emerging technologies related to cybersecurity and communicate findings to the team
Keep abreast of emerging cybersecurity vulnerabilities and help develop notifications and action plans for our clients