Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Security Framework Alignment: Oversee the definition and maintenance of the Bank’s technical security standards, ensuring strict alignment with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Guide the review and updating of technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, Network Access Control (NAC) systems (Cisco ISE), and related perimeter devices.
Audit & Compliance Remediation: Lead technical readiness for internal, external, and regulatory audits. Drive team execution to track, prioritize, and validate the remediation of security findings and vulnerabilities across business units.
...
Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Perform detailed investigative works into all traffic anomalies against established, historical baselines of individual agencies. Reviewing and profiling the events of all monitored clients
...
Typically uses Scrum/Agile development techniques and tools for team collaboration, issue tracking and backlog management
Has working knowledge and experience in own discipline. Continues to build knowledge of the organization, processes and customers. Performs a range of mainly straightforward assignments. Typically follows prescribed guidelines or procedures to resolve problem. May train new team members and provide input to employee performance evaluations. Works with a moderate level of guidance.
Solution Advisory: Provide hands-on security architecture guidance to project delivery teams from project inception through post-implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high-severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root-Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
...
Identifies and addresses legal and customer security requirements within the region
Supports the implementation of the global Information Security Management System (ISMS) and global business continuity standards within the region
Implements the global risk-based approach to protecting information and other assets within his/her region and performs vulnerability management related tasks
...
Solution Advisory: Provide hands-on security architecture guidance to project delivery teams from project inception through post-implementation review.
Major Incident Oversight: Act as the senior technical escalation lead for high-severity (P1/P2) security incidents, breach responses, threat hunting escalations, and operational outages.
Root-Cause Analysis (RCA): Direct structural RCAs following critical incidents and conduct analyses on recurring operational bottlenecks, legacy technical debt, and friction points.
...