Cybersecurity Project Manager
About Capgemini
Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. The Group reported 2024 global revenues of €22.1 billion.
This will be a 1 year contract role.
Responsibilities
Cybersecurity Threat Monitoring, Incident Response & Forensics
- Oversee day-to-day security monitoring and effective use of SIEM, and endpoint protection
- Lead incident response, containment, eradication and root cause analysis for any Cybersecurity event
- Ensure clear incident security classification, escalation workflows and communication protocols with the client and with Authority
Vulnerability and Patch Management
- Lead the vulnerability assessment and penetration testing programme (annual)
- Lead the quarterly vulnerability assessment
- Track and manage the remediation of vulnerabilities across endpoints (servers, network devices, appliances, middleware and containers)
- Ensure patching cycles across the various platforms (the client, Authority, and Disaster Recovery)
Security Infrastructure Management
- Implement, configure, troubleshoot and maintain security technologies such as firewall, intrusion detection / prevention systems, HSM, PAM)
- Understand the usage of Active Directory for identity, authentication and access control
- Implement Privileged Access Management policies and procedure
- Implement TLS 1.2/1.3 configuration
- Implement SSL certificate rotation, and HSM integration
Secure System Hardening & Architecture
- Oversee OS, application and network hardening (RHEL, Windows Server, Kubernetes, database and network devices)
- Review and approve security architecture designs such as token management, secrets management, encryption models
- Ensure compliance of security design for new system components, functions and projects
Privileged Access Management & Control
- Lead and govern the privileged access management across active directory domains
- Oversee break-glass emergency access procedure, and segregation of duties
- Ensure periodic access reviews, and compliance reporting
Cybersecurity (IM8) Governance & Compliance
- Define and enforce compliance with Cybersecurity IM8 policies, standards and procedures across all environments
- Drive audit compliance, coordinate audit engagements and provision of evidence to auditors
- Maintain the risk register, track remediation progress and ensure risks are effectively managed
Cybersecurity Operations Leadership and Management
- Lead a team of two cybersecurity engineers, ensuring high competency in mission critical operations
- Work closely with SDM, Cybersecurity engineers, Level 1 engineers and Level 2 engineers to maintain a secure operational environment
- Ensure clear documentation, SOP, runboks and knowledge transfer for all security-related activities
- Drive continuous training, skill improvement and certification for the Cybersecurity team
Education and Experience
- Bachelor Degree in Information Security, Computer Science, Engineering, or a closely related discipline
- At least 5 years of proven experience in Cybersecurity or information security roles for mission critical 24x7 production support, preferably in public sector
- Strong competency in operating system security (RHEL, Windows Server), network security and Kubernetes security
- Hands-on experience with following tools such as SIEM (LogRhythm), Vulnerability Scanner (Nessus), IAM/PAM (Beyond Trust / CyberArk), HSM, TLS/PKI, Firewall (Check Point, Palo Alto), IDS/IPS
- Certification is preferred, such as CISSP, CISM and CEH
Knowledge/ Skills
- Security Principles such as CIA, non-repudiation, defense in depth, segregation of duties, least privilege
- Networking Fundamentals
- Operating System Fundamentals
- Identity & Access Management
- Cryptographics Basics
- Application Security Fundamentals, such as Common vulnerabilities, OWASP Top 10, secure coding principles
- Incident Response Fundamentals
- IM8 Governance, Compliance and Security Policies
Let's talk about what's in it for you!
Passionate people are Capgemini's Ace of Spades - join us to discover a career that will challenge, support and inspire you. Working at Capgemini you'll find the rewards are more than just financial. You will work alongside some very smart and inspiring people on exciting projects and you will also enjoy incredible benefits. We offer flexible work practices and 40 hours of self-development every year with a huge selection of learning opportunities to choose from.
As "Architects of Positive Futures", Capgemini actively supports the community in 3 ways:
Diversity and Inclusion - we believe diversity of thought fuels excellence and innovation, which is why we positively encourage applications from suitably qualified candidates regardless of their gender identity, ethnicity, sexual orientation, religion, ability, intersex status or age. To support our commitment to diversity and inclusion, we celebrate special events and days of significance that are important to our employees such as Diwali, Bastille Day, Pride, IDAHOBIT, IWD and International day of people with Disabilities. Our Employee Resource Groups Women@Capgemini and OutFront support the grassroots passion of employees to drive our diversity agenda and effect change.
Digital inclusion - at Capgemini we are using our skills to drive social impact initiatives focusing on helping society address the impact of the digital and automation revolution. We also provide employees with opportunities to give back to the community through charity projects and volunteer days.
Environmental Sustainability - Capgemini joined the CDP's (Carbon Disclosure Project) prestigious "A list" for its commitment to the Net-Zero economy. We are focusing on helping our clients transform towards more sustainable business models and committing to reduce our own carbon emissions (GHG) by 20% per employee by 2020.
Recognized by Ethisphere as one of the World's Most Ethical Companies for the last 8 years in a row, ethics and values are at the heart of Capgemini's corporate culture and business. Embedded in our DNA, our seven values - Honesty, Boldness, Trust, Team Spirit, Freedom, Fun and Modesty - have remained the same since company inception in 1967. To see how we bring these values to life, click here to listen to some of our employee’s stories.
Come join us, bring your whole self to work, create new possibilities for you, your customers and your community and help us to be Architects of Positive Futures.
Singapore, SG