I am planning to apply under NOC 2171 but I'm a bit confused. My JD is:
1. Work closely with business managers, technical team members, software architects and other senior team members to identify requirements related to information systems security and map those requirements to current security projects.
2. Develop and ensure the compliance of all the applicable policies, procedures and controls of Information Security Management System.
3. Coordinate with all departments to Identify and assess the risk associated with current and new information assets, information systems and business processes.
4. Perform penetration testing and vulnerability assessment. Develop appropriate criteria needed to assess the level of new/existing applications and/or technology infrastructure elements for compliance with enterprise security standards.
5. Facilitate all the departments in the development, maintenance and testing of Business Continuity and Disaster Recovery Plans and suggest areas of improvement.
6. Ensure unauthorized intrusion, access and tampering is prevented. Track and manage Information Security incidents, lead their investigations and recommend corrective actions.
7. Monitor IT infrastructure for stability, operability and growth to ensure optimal system performance and availability. Monitoring includes automated alerts and/or notifications to provide timely resolution for any potential outage or service disruptions.
8. Proactively plan and deploy security patches and ensure systems maintenance.
9. Responsible for automating and implementing Information Security tool(s) or application(s) independently or with the team.
10. Conduct quarterly Information Security Audits and be part of Information Security Forum meetings.
11. Develop policies, procedures, templates and other relevant information security management system documentation.
12. Act as Management’s representative in external/third party audits.
The problem is that the lead statement for Systems Security Analyst under NOC 2171 says that they 'confer with clients' and in my job I don't confer with any external clients as i'm not working in a consultancy firm. Rather I perform these tasks for other departments within the company. Is this JD good to go?