<p><strong>Job Purpose and Background</strong> </p><p>With the successful launch of CDP’s new digital disclosure platform and the expansion of our technological capabilities, ensuring we have robust and dependable security infrastructure and practices that protect the data of our disclosers, and wider ecosystem, is essential to CDP’s long-term future. </p><p>We are now embarking on an effort to build a new in-house Cybersecurity team, including a Senior Security Engineer who will play a key role in contributing to and implementing the new global security roadmap, encompassing infrastructure, tooling, policies, procedures, certifications, and training. This is an exciting greenfield opportunity to contribute to shaping and developing a new Security function, leveraging the latest Azure technologies, with a vision of attaining ISO27001 certification in the near-future. </p><p><strong>About CDP</strong> </p><p>CDP is a not-for-profit charity that runs the global disclosure system for investors, companies, cities, states and regions to manage their environmental impacts. The world’s economy looks to CDP as the gold standard of environmental reporting with the richest and most comprehensive dataset on corporate and city action. In 2021 we launched our new five-year strategy: Accelerating the Rate of Change - <a href="https://www.cdp.net/en/info/about-us/our-five-year-strategy" target="_blank"><strong>find out more here</strong></a>. Visit <a href="https://cdp.net/en" target="_blank"> </a><a href="https://cdp.net/en" target="_blank"><strong>https://cdp.net/en</strong></a> or follow us @CDP to find out more. </p><p><strong>Key responsibilities include:</strong> </p><ul><li>Supporting internal IT staff with security matters and reinforcing key security principals </li></ul><ul><li>Providing cyber security support for IT infrastructure. </li></ul><ul><li>Provide Security analysis and risk assessment, as well as remediate and track results </li></ul><ul><li>Contributing to the maintenance of cyber security plans, policies and processes, and implementing initiatives to ensure compliant. </li></ul><ul><li>Leading internal and external cyber security audits and pen testing all infrastructure, reporting and remediating issues. </li></ul><ul><li>Managing MFA, firewalls, web filtering solutions, antivirus and anti-malware software. </li></ul><ul><li>Evaluating new software and hardware for security vulnerabilities and risks. </li></ul><ul><li>Performing regular monitoring for intrusions / unusual activity and investigating and responding to any threats. </li></ul><ul><li>Performing internal and perimeter firewall configurations and changes. </li></ul><ul><li>Assist with the management and administration of Azure security, Microsoft Sentinel, Defender, and Defender for Cloud </li></ul><ul><li>Assist in the implementation, deployment, management and monitoring of CDP’s security catalogue. </li></ul><p>Tech-stack: Azure Sentinel, Azure Log Analytics, Azure Defender and Azure Defender For Cloud, AppCheck, Azure Security, Microsoft Intune, Forcepoint, Cisco Meraki </p><p><strong>You will bring the following:</strong> </p><ul><li>At least 2 years of relevant working experience in cybersecurity, with a focus on implementing across platforms including security, performance, and reliability. </li></ul><ul><li>Excellent knowledge and experience in public, private and hybrid cloud solutions; Microsoft Azure essential, as well as current trends </li></ul><ul><li>Good knowledge of core infrastructure, designing, engineering, and implementing across platforms including, Wintel, Linux Storage, backups, IaaS (Infrastructure as a Service), and PaaS (Platform as a Service). </li></ul><ul><li>Excellent of knowledge of cybersecurity SaaS providers </li></ul><ul><li>Understanding “Infrastructure as Code”, Terraform, Json, Jenkins and Azure DevOps. </li></ul><ul><li>Understanding of networks, both cloud native and within on-premises data centres. </li></ul><ul><li>Excellent skills in Azure Security </li></ul><ul><li>Excellent interpersonal and client-handling skills, with the ability to manage expectations and simplify detail to key principles and decisions </li></ul><ul><li>Excellent written, verbal and presentation skills in English to properly articulate complicated security requirements to management, key partners and other stakeholders </li></ul><ul><li>Demonstrable ability for a high attention to detail and capacity to be flexible in both process and problem solving. </li></ul><ul><li>Business and organisational awareness, agility to learn, and willingness to challenge and improve </li></ul><ul><li>A positive team player with a high level of self-motivation and drive, committed to achieving high standards, even with challenging deadlines </li></ul><p><strong>Preferable:</strong> </p><ul><li>Knowledge of infrastructure monitoring/logging, performance and capacity management, automation, and application toolchain (CI/CD) is an advantage </li></ul><p><strong>Salary and benefits</strong>: </p><ul><li>Competitive NGO salary and 8% Company Pension Program; </li></ul><ul><li>30 days annual holidays (with purchased leave options); </li></ul><ul><li>Flexible working hours (with option to take flex-days) </li></ul><ul><li>Up to 6 months remote work anywhere in the world </li></ul><ul><li>Paid sabbaticals, enhanced maternity/paternity/adoption leave </li></ul><ul><li>Office offering prayer room and breastfeeding facilities </li></ul><p><strong>Before you apply</strong> </p><p>We’ll only use the information you provide to process your application. For more details on how we use your information, see our <a href="https://cdpworldwide.teamtailor.com/privacy-policy" target="_blank"><strong>applicant’s privacy notice</strong></a>. By uploading your CV and covering letter, you are permitting CDP to use the information you have provided for recruitment purposes. </p><p><strong>How to apply:</strong> </p><p>Please upload your CV in the application form. </p> •
Last updated on Sep 4, 2024