Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...
Establishment of related cyber risk management framework/policy to meet internal and regulator’s requirement.
Provide cyber risk advisory services and cyber security awareness training where required.
Aware and take appropriate measures of current and emerging technology risks affecting the industry, which could potentially affect the Bank’s risk profile.
...