Job Summary
Ensure the implementation and maintenance of information security policies and controls aligned with branch requirements, perform risk assessments, and support IT security projects to protect critical systems and data.
Responsibilities
- Implement and maintain information security policies, controls, and processes to meet branch requirements and update related documentation and manuals
- Conduct security risk assessments and third-party risk assessments in compliance with MAS Technology Risk Management guidelines
- Enforce data protection principles by ensuring confidentiality, integrity, and availability of systems through regular system reviews, security patching, and hardening practices
- Review security and access logs to detect and respond to security incidents
- Lead or support project initiatives related to information security to enhance organizational security posture
- Plan and coordinate remediation efforts for identified security vulnerabilities
- Perform gap analysis on MAS advisories and monthly FINTEL notifications to ensure compliance
- Coordinate with internal and external auditors on IT security reviews and follow up with stakeholders for required artefacts
- Provide on-call support 24x7x365 for critical applications, infrastructure, and network components such as FAST payment applications and gateways
Preferred competencies and qualifications
- Bachelor's degree or diploma in Information Technology or related discipline from a recognized university or polytechnic
- Minimum of 3 years hands-on experience in IT Security, preferably within banking or vendor environments
- Strong knowledge of IT Security tools and platforms including MASTERSAM, Cyberark, Morphisec, Trend Micro, Symantec, M365 security, Firewalls, Proxy, Tenable Nessus, and Network Segmentation
- Technical expertise in IT infrastructure systems such as Windows Server OS, Red Hat Linux OS, Active Directory, Microsoft Exchange, VMware, network switches and routers, and AS400 systems
- Solid understanding of cybersecurity practices including system hardening, vulnerability management, and implementation of security controls aligned with industry standards
- Experience in project management methodologies to lead and deliver IT security projects effectively
- Expertise in vendor management including evaluating, onboarding, and managing third-party service providers to ensure compliance and performance
- Relevant certifications such as CISSP, CISM, CISA, and M365 security are highly desirable and demonstrate technical competency