Identifies and addresses legal and customer security requirements within the region
Supports the implementation of the global Information Security Management System (ISMS) and global business continuity standards within the region
Implements the global risk-based approach to protecting information and other assets within his/her region and performs vulnerability management related tasks
...
Solution Advisory: Provide hands-on security architecture guidance to project delivery teams from project inception through post-implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high-severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root-Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
...
Security Framework Alignment: Oversee the definition and maintenance of the Bank’s technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
...