Governance, Risk and Compliance
- Security programme documentation: policies, procedures, standards and guidelines; programme management with training, communication, reporting and a RACI matrix
- Frameworks such as COBIT and ITIL, configuration management with asset lifecycle and CMDB, GRC tools for mapping, automation and compliance tracking, data governance
- Risk management: impact analysis, quantitative and qualitative risk assessment, third-party risk
- Threat modelling: adversary characteristics, attack patterns and frameworks such as ATT&CK, CAPEC and STRIDE; attack surface using architecture reviews, data flows and trust boundaries
- Compliance strategies: industry-specific standards such as PCI DSS and ISO/IEC 27000, security frameworks such as NIST CSF and CSA
- Security challenges when adopting artificial intelligence
Security Architecture
- Implement cloud capabilities securely: CASB (API-based and proxy-based), shadow IT detection, the shared responsibility model, CI/CD pipelines, Terraform and Ansible, containers, orchestration and serverless
- Data security in the cloud: data exposure and exfiltration, data remanence, insecure storage, encryption keys
- Control strategies in the cloud: proactive, detective and preventive controls, cloud connectivity, service integration, continuous authorization
- Network architecture: segmentation and microsegmentation, VPN and always-on VPN, API integration
- Security boundaries: identify, manage and attest assets, data perimeters and secure zones; deperimeterisation with SASE, SD-WAN and software-defined networking
- Zero trust: define subject-object relationships and integrate them into the architecture design
Security Engineering
- Secure identity and access management, endpoints and servers, network infrastructure, hardware security, and specialised and legacy systems
- Automation: scripts in PowerShell, Bash and Python, event triggers, infrastructure as code, cloud APIs, generative AI, containers, patching, SOAR and workflow automation
- Vulnerability management: scanning, reporting and SCAP (OVAL, XCCDF, CPE, CVE, CVSS)
- Advanced cryptography: post-quantum cryptography, key stretching, homomorphic encryption, forward secrecy, hardware acceleration
- Cryptographic use cases: data at rest, in transit and in use, secure email, blockchain, privacy, compliance, certificate-based authentication
- Cryptographic techniques: tokenisation, code signing, cryptographic erasure, digital signatures, hashing, symmetric and asymmetric methods
Security Operations
- Monitoring and data analysis: SIEM (event parsing, retention, false positives and false negatives), correlation, prioritisation and trends, behavioural baselines for network, systems and users
- Vulnerabilities and attack surface: injection, XSS, insecure configurations, outdated software, weak ciphers; countermeasures such as input validation, patching, encryption and defence in depth
- Threat hunting: internal sources such as honeypots and UBA, external sources such as OSINT, the dark web and ISACs, threat intelligence platforms, IoC sharing with STIX and TAXII, rule languages such as Sigma, YARA and Snort
- Incident response: malware analysis (sandboxing, IoC extraction, code stylometry), reverse engineering, metadata analysis, data recovery and root cause analysis