Description
Information Security is responsible for preventing IT-based crime, hacking, intentional or inadvertent modification, disclosure, or destruction to the organization's information systems and IT assets and intellectual property. The focus of the role is to ensure highly professional and productive procedures, policies and processes are in place, and aligned and agreed with relevant stakeholders. Roles within Information Security may cover one or more areas of speciality :
- Identity & Access Management (which may include, for example, authentication; access management & control; recertification etc.)
- Information Security (“IS”) Operations (which may for example include, cyber threat operations; cyber forensics, protection against data leakage etc.)
- IS Technology (which may include IS architecture, IS engineering, cryptographic services etc.).
Work includes :
Identifying and evaluating potential areas of Information Security threat by assessing the probability and impact, and implementing associated mitigations Monitoring and contributing to the implementation of the Information Security strategyEvaluating the adequacy and effectiveness of internal controls relating to Information Security risksEnsuring appropriate procedures, policies and processes are in place, and aligned and agreed with relevant stakeholdersDeveloping appropriate, pragmatic strategies to deliver effective controls and Information Security management objectives and implementation across the bankManaging client relationships and ensuring management focus on the Information Security agendaWhat we’ll offer you
As part of our flexible scheme, here are just some of the benefits that you’ll enjoy
Best in class leave policyGender neutral parental leaves100% reimbursement under childcare assistance benefit (gender neutral)Sponsorship for Industry relevant certifications and educationEmployee Assistance Program for you and your family membersComprehensive Hospitalization Insurance for you and your dependentsAccident and Term life InsuranceComplementary Health screening for 35 yrs. and aboveYour key responsibilities
Conduct thorough security assessments of existing vendors such as Google, DXC and KyndrylMonitor and manage vendor compliance with security policies and standards and related contractual SLAsIdentify and mitigate risks associated with third-party vendors.Maintain a vendor risk register and track remediation efforts.Provide guidance and support to vendors on improving their security posture.Stay informed about the latest security threats and trends affecting third-party services.Conduct regular reviews and audits of vendor security practices.Report on vendor security performance to senior management.Partner with the Delivery, Tech operations and infrastructure teams to deliver operational excellenceInternally assess, evaluate, and make recommendations to management regarding the adequacy of the security controls for the Company's information and technology systemsPresent assessment results and options to the DB stakeholder and discuss steps for resolutionSupport the Audits / resolution as it relates to issues that address information security in their areas’ processes and projects.Your skills and experience
Proven experience in information security, vendor management, or a similar role.Strong knowledge of information security principles, practices, and technologies especially on Mainframe, DB2, AIX, Tandem, AS400Experience with security frameworks and standards such as ISO 27001, NIST, and GDPR.Excellent problem-solving and analytical skills.Relevant certifications such as CISM, or CISA are preferredAnalytical skills to evaluate risks and control processesStrong communication skills both verbal (incl. presentation skills) or written and ability to deal with people at all levels in a global matrix organizationWork Experience
~12-15 years’ experience in IT Infrastructure support and service deliveryAt least ~5 years of experience in information security on Mainframe, AS400, AIX, Tandem and broader Technology InfrastructureHow we’ll support you
Training and development to help you excel in your careerCoaching and support from experts in your teamA culture of continuous learning to aid progressionA range of flexible benefits that you can tailor to suit your needs