Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...
Establishment of related cyber risk management framework/policy to meet internal and regulator’s requirement.
Provide cyber risk advisory services and cyber security awareness training where required.
Aware and take appropriate measures of current and emerging technology risks affecting the industry, which could potentially affect the Bank’s risk profile.
...
Identify malicious activities from legitimate file, email, user, or network activity, distinguishing between benign and harmful elements with precision.
Conduct manual research to gather threat intelligence and analyze attack vectors. Identify potential threats, study their behavior and techniques, and assess the methods used by attackers to provide actionable insights.
Assess and categorize events that have been manually reported. Review the details of each event thoroughly to determine its significance and severity, classifying it according to predefined criteria to ensure accurate prioritization and responses.
...