Job Description
JOB OBJECTIVES
- Information/Cybersecurity risk and governance team that is responsible for development and enforcement of policies and guidelines that is aligned to business requirements and processes.
- Implement and Maintain Security Compliance Standards and regulatory requirements – ISO27001, PCI DSS, Cybersecurity etc.
DUTIES & RESPONSIBILITIES
- Perform security requirement validation and documentation reviews to ensure they are performed
- efficiently and effectively.
- Plan and coordinate independent Vulnerability Assessment and Penetration Test (VAPT).
- Monitors compliance with Information/Cybersecurity policies, baselines, guidelines and procedures.
- Assesses threats and vulnerabilities in the Banks electronic products and related technology platforms and provide information/cybersecurity risk guidance.
- Assesses threats and vulnerabilities regarding information assets and recommends the appropriate information security controls and measures.
- Ensure timely and effective corrective actions are taken to correct deficiencies and provide status reporting.
- Manage Internal and External Security Audit.
- Develop metrics and monitoring processes to assess the effectiveness of the Bank’s overall information and cyber security risk management and measure its performance and efficiency.
- Obtain and review periodic PCI DSS compliance report from stakeholders in support of security requirements and report on any identified gaps for remedial action.
JOB REQUIREMENTS
Education
- Minimum Education: First Degree in computer science/Engineering.
- Professional Certifications: CISM, CISSP, ISO27001 Lead Implementer, ISO27032 Cyber Security Lead Manager or any Cybersecurity Professional Certifications.
Experience
- Minimum experience – 5 years’ experience in facilitating and conducting security assessment and compliance related to PCI-DSS, ISO 27001, and Cybersecurity Framework.
KEY COMPETENCY REQUIREMENTS
Knowledge
- Banking structure, policies and procedures.
- Banking services/products and operational risk
- Deep knowledge of Information Security
- Management frameworks and practices (ISOD7001, PCI DSS, NIST)
- Enterprise security risk management frameworks and processes
- Software Development Lifecycle (SDLC)
- Vulnerability Assessment & Penetration Test Techniques
Skill/Competencies
- Communications skills (written and oral)
- Must be self-solution driven, proactive and have acceptable knowledge of the business environment
- Reasoning and Analytical
- Interpersonal and leadership skills
- Good presentation skills