Ensures that all regulatory (BSP Circulars, NPC) and compliance (NIST, ISO 2700, CIS) are in place, adopted, enforced and monitored
Approves proposed information security control testing activities, including scoping, facilitation of testing, and reporting of findings
Assesses and approves the effectiveness of security controls implemented in the Bank's applications, systems, platform, software, operating systems, firmware and IT infrastructure
Evaluates and approves assessment of evidence of control effectiveness across the Bank, and recommending control improvements
Attest the security of applications, systems, platform, software, operating systems, firmware are secure before putting them into production
Develops and recommends security assurance policies/procedures that must be adopted, enforced and monitored for all Bank's Information Security system
Ensures the accuracy of security assessments- 3rd party or internal conducted on the Bank's IT assets
Recommends and enforces security hardening of applications, operating system, hosts, data and user access.
Supports the Cyber Defense Center and Security Architecture teams on their day-to-day activities relating to information and cyber security incidents or events
Leads collaboration with the Cyber Defense Center and the Security Governance team to enhance the provision of information security related assurances across the Bank
Facilitates and provide assistance on the investigation of malicious and threats against the Banks IT assets
Facilitates and provide guidance and recommendation of vulnerability assessment test result and how to remediate findings
Leads the simulation on impact of vulnerabilities on the Bank's IT systems
Provides guidance on adopting information security best practices
Qualifications
At least 3 years of solid experience in system, network, applications and endpoint security assurance
Strong understanding of Cybersecurity Frameworks - NIST, ISO 2700, CIS
Understanding of web application firewalls, intrusion prevention system, and software development security practices (i.e., OWASP) is an advantage
Detailed knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
Has experience working as an information security specialist, or external auditor