Risk Exception Processing: Review, evaluate, and track Digital Security Policy exception requests (DTAP/policy waivers), ensuring business justifications are valid and compensating controls are properly established.
Compensating Controls Validation: Collaborate with engineering and operations teams to define, validate, and monitor effective compensating controls for accepted risks and policy deviations.
Risk Mapping & Register Maintenance: Feed risk analysis findings and approved risk exceptions into the enterprise D&IT risk register, ensuring visibility and periodic re-evaluation.
...
Prepare project documentation such as Project Plan, Technical Document, Material Document Submission, drawings and OMM.
Participate in the regular meeting of the project, allocate, arrange and complete the relevant work on time according to the meeting requirements and report daily or weekly progress at site.
Manage/Monitor/Track project and control cost to ensure project is completed on time within budget, contractual and safety standard
...
Identify cleanup activities within Air Liquide IoT/OT legacy security issues and achieve pragmatic and measurable objectives.
Coordinate Penetration Testing activities on critical sites. Responsible to track and monitor those identified gaps till closure
Socialize security policy and standards across relevant areas of the OT organization - empowering and educating people to build secure and compliant systems.
...
We seek to strike a balance between diversity, inclusion and merit to achieve our mission of infusing diversity in thinking and skillsets into our organisation. Candidates are assessed based on merit and potential, in line with our mission to attract and recruit the best talent available. Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...
Establishment of related cyber risk management framework/policy to meet internal and regulator’s requirement.
Provide cyber risk advisory services and cyber security awareness training where required.
Aware and take appropriate measures of current and emerging technology risks affecting the industry, which could potentially affect the Bank’s risk profile.
...