Cyber Security
The IT Security team acts as the first line of defense for the Bauer Group against evolving cyber threats. Its responsibilities are organized across three key service areas:
Security Operations & Monitoring
- Continuous monitoring the infrastructure to identify potential threats, anomalies, and vulnerabilities across the digital landscape.
- Implement and maintain layered technical defences, deploying security tools and protocols to protect critical assets and sensitive data.
- Educate and train employees to recognize security threats, fostering a security-aware culture and reducing human error.
- Collaborate with cross-functional teams to embed security practices and controls organization-wide.
- Monitor emerging cybersecurity threats and adopt industry best practices.
- Operate security monitoring and alerting mechanisms to support timely detection of suspicious activities, unauthorized access attempts, and abnormal system behavior.
- Strengthen identity, access, endpoint, email, and network security controls to reduce exposure to phishing, malware, data leakage, and other cyber risks.
Vulnerability & Patch Management
• Conduct risk assessments and penetration testing to identify and remediate security loopholes proactively.
• Systematically evaluate and prioritize vulnerabilities, devising effective mitigation strategies across all infrastructure layers.
• Maintain comprehensive security documentation, policies, and procedures aligned with evolving threat landscapes.
• Coordinate vulnerability scanning, assessment, and remediation tracking to ensure identified risks are addressed within defined timelines and priorities.
• Support timely deployment of security patches, firmware updates, and configuration hardening across servers and applications.
Incidence response & Business Continuity
- Respond swiftly to security incidents, minimizing impact and restoring operations while keeping stakeholders informed.
- Maintain incident response readiness through defined escalation paths, response procedures, communication protocols, and coordination with relevant internal and external stakeholders.
- Analyze security incidents to identify root causes, implement corrective actions, and prevent recurrence through improved controls and awareness measures.
- Support business continuity and disaster recovery preparedness by aligning cybersecurity response activities with backup, recovery, and operational resilience plans.