Develop and maintain playbooks which provide an investigation guideline.
Assist in the development, documentation and maintenance of new Alert and Detection Strategies (ADS) focused on tactics, techniques and procedures (TTP).
Maintain the cyber risk register — identifying, assessing, tracking, and reporting on cyber risks in line with the bank's enterprise risk management framework.
Produce KRI/KPI dashboards and governance reports for the Head of Cyber Security, Board Risk Committee, and BNM — including periodic cyber risk reporting required under RMIT.
...
Manage and continuously enhance the Information Security Management System (ISMS), including maintaining ISO/IEC 27001 certification, coordinating internal and external audits, overseeing corrective actions, and ensuring ongoing compliance with certification requirements.
Own and administer the Digital Risk Register and Information Security Risk Register, including facilitating risk identification, assessment, treatment, monitoring, reporting, and periodic review in alignment with enterprise risk management requirements.
Conduct and facilitate information security risk assessments, including the evaluation of proposed deviations from security standards, policies, and control requirements.
...
Partner with project, infrastructure, cloud, network, and application teams to embed security requirements into solution design, implementation, and change activities.
Coordinate the implementation of security controls, technologies, and remediation activities across enterprise and operational technology environments.
Support the adoption of security-by-design principles across technology initiatives.
...
Collaborate with internal stakeholders and third-party service providers to establish remediation plans, monitor progress, and ensure delivery within agreed SLAs.
Analyze vulnerability findings and engage Technology and Business teams to drive timely remediation of identified security issues.
Validate remediation effectiveness by reviewing vulnerability scan results and confirming closure of identified risks.
...
To lead the management, development, implementation and governance of cyber security policies, standards, guidelines and controls of IT and OT across 13 countries for the client including affiliates.
To support implementation and maintenance of cybersecurity related policies, standards, guidelines, controls, and governance.
To coach and provide expert guidance to IT practitioners, OT Practitioners, and Cybersecurity Practitioners in understanding cybersecurity policies, standards, guidelines, controls, and governance.
...
Develop and maintain playbooks which provide an investigation guideline.
Assist in the development, documentation and maintenance of new Alert and Detection Strategies (ADS) focused on tactics, techniques and procedures (TTP).
Lead and govern the development, maintenance and execution of cyber defence frameworks, technologies, processes and procedures to ensure effective security monitoring, incident handling, response coordination and recovery.
Lead the organisation, execution, tracking and reporting of the Cyber Security Incident Response Plan (CSIRP), playbooks, runbooks and cyber drill exercises, ensuring operational readiness and alignment with regulatory and management expectations.
Provide senior technical leadership and subject matter expertise for cyber defence planning, including evaluation, deployment and enhancement of cyber security technologies, and implementation of continuous improvement initiatives to address identified gaps and risks.
...
Manage and continuously enhance the Information Security Management System (ISMS), including maintaining ISO/IEC 27001 certification, coordinating internal and external audits, overseeing corrective actions, and ensuring ongoing compliance with certification requirements.
Own and administer the Digital Risk Register and Information Security Risk Register, including facilitating risk identification, assessment, treatment, monitoring, reporting, and periodic review in alignment with enterprise risk management requirements.
Conduct and facilitate information security risk assessments, including the evaluation of proposed deviations from security standards, policies, and control requirements.
...
Working with the engagement manager you will assist with the planning and delivery phases of engagements
Contributing to the creation of proposals and marketing material
Perform security risk and controls assessments and/or penetration testing to evaluate and analyze threat, vulnerability, impact, risk and security issues to Business.
...