Security Framework Alignment: Oversee the definition and maintenance of the Bank’s technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
...
Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...