Sr.Cyber Security
Indexed description
1. การบริหารจัดการบัญชีผู้ใช้และสิทธิ์การเข้าถึง (Identity & Access Management Administration)
- จัดการ Account Lifecycle Management (Provisioning, Deprovisioning, Account Recertification) สำหรับพนักงาน ผู้ใช้งานภายนอก และบัญชี Service Accounts
- บริหารจัดการ Role-Based Access Control (RBAC) และ Least Privilege Access
- ตรวจสอบและบังคับใช้ Multi-Factor Authentication (MFA), Single Sign-On (SSO) และ Password Policy
2. การเฝ้าระวังและตรวจสอบกิจกรรมการเข้าถึง (Access Monitoring & Auditing)
- เฝ้าระวังและวิเคราะห์ Access Logs และ Authentication Events เพื่อระบุความผิดปกติหรือพฤติกรรมที่เสี่ยงต่อความปลอดภัย
- จัดทำ Identity & Access Review (IAR) ตามข้อกำหนดด้าน Compliance เช่น ISO 27001
- วิเคราะห์และจัดทำรายงาน Access Certification และ Privileged Access Management (PAM) Review
3. การรักษาความปลอดภัยของบัญชีผู้ใช้และการเข้าถึง (Identity Security & Risk Management)
- ป้องกันและตรวจจับ Identity Threats เช่น Account Takeover (ATO), Credential Stuffing, และ Insider Threats
- บริหารจัดการ Privileged Access Management (PAM) เช่น CyberArk, BeyondTrust, Delinea, PAM360
- บังคับใช้ Zero Trust Security และ Identity Threat Detection & Response (ITDR)
4. การจัดการและบูรณาการระบบ IAM (IAM Systems & Integration)
- ดูแลและปรับแต่งระบบ IAM Solutions เช่น Microsoft Entra ID (Azure AD), Okta, Ping Identity, One Identity, ForgeRock
- บูรณาการระบบ IAM กับ Cloud (Azure AD), On-Premise AD, HR Systems และ Business Applications
- พัฒนา IAM Automation & Workflows ด้วย API และ Scripting เช่น PowerShell, Python
5. การวิเคราะห์ช่องโหว่และเสริมสร้างความมั่นคงปลอดภัย (IAM Security Assessment & Hardening)
- ตรวจสอบ IAM Misconfigurations และ Excessive Permissions เพื่อลดความเสี่ยง
- ทำ Privilege Escalation Testing และ Identity Threat Hunting เพื่อตรวจจับบัญชีที่อาจถูกแทรกแซง
- บังคับใช้แนวทาง Just-In-Time Access (JIT) และ Passwordless Authentication
6. การปฏิบัติตามข้อกำหนดและมาตรฐานด้านความปลอดภัย (IAM Compliance & Governance)
- ดูแลให้ IAM Policies & Procedures สอดคล้องกับมาตรฐาน เช่น ISO 27001, NIST 800-53, CIS Controls
- จัดทำเอกสาร IAM Risk Assessment และ Audit Report สำหรับทีมบริหารและหน่วยงานกำกับดูแล
- ประสานงานกับทีม Security Engineer, SOC และ Risk Management เพื่อปรับปรุงการจัดการสิทธิ์ให้ปลอดภัยยิ่งขึ้น
7. การพัฒนาและฝึกอบรมทีมงานเกี่ยวกับ IAM (IAM Awareness & Training)
- อบรมพนักงานเกี่ยวกับ Identity Hygiene และ Access Security Best Practices
- พัฒนา IAM Playbook และ Incident Response Procedures สำหรับการบริหารจัดการบัญชีผู้ใช้ที่ถูกบุกรุก
- สนับสนุนและให้คำแนะนำด้าน IAM แก่ทีม IT, HR, และผู้ใช้งานทั่วไป
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search