Responsibilities:
a. Identify and assess security risks in Authority's Info-Communication Technology and Smart Systems (“ICT&SS”); and

b. Recommend treatment actions for security risks identified.

c. Define the scope of the risk assessment for agreement.

d. Identify risks scenarios which includes threats and vulnerabilities that are relevant to system.

e. Develop risk scenarios based on a library of common risk events.

f. Analyse the risks statements identified in terms of impact if the risks were realised and the likelihood that the risks will occur; and

g. Evaluate the risk level for the risk scenario.

h. Assess the identified risk statement and determine the residual risk based on the proposed risk treatment option.

Requirements:
The appointed CSP shall mínimally conduct one or more types of security risk assessments listed below:
a. System Applications

b. Development Environment (DevOps, CI/CD)

c. Infrastructure

d. Internet of Things (loT)

e. Operational Technology (OT)

f. Cloud Computing Environment and Service and

g. Business Process & Security Services operated by third-party vendors

The appointed CSP shall deliver mínimally the following deliverables in a pre
- agreed timeframe as part of the security risk assessment:
1. Risk Assessment Report,

  1. Security Risk Register

  2. Develop and review security documentations and security designs

  3. Conduct Application Security (AppSec) assessment that align with Government security policies or industry best practices.

  4. Conduct Vulnerability Assessment (VA) review

  5. Threat Hunting

  6. Threat Intelligence

  7. Incident Response and

  8. Cloud Security


Salary: $4,000.00 - $6,500.00 per month

Work Location: In person