Interfaces and collaborate with other teams for incident escalations and resolution
Work closely with SOC Head to better security operations and address identified deficiencies
Perform due diligence and in-depth analysis on escalated security alert from Level-1 analyst and escalate to respective team for further action in timely manner
...
Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
...
Coaches and guides Security teams by modelling professional conduct and adhering to security policies and safety regulations at the assigned work sites
Guides team members on how to fulfil the special / unique requirements for NTT GDC clients, and ensures requirements are met; includes maintaining a positive and professional demeanour, proper engagement, and establishing client relationships.
Remains alert and monitors security operations at all times during shift to ensure data centre and surrounding property is secure and not accessed by unauthorized personnel, or open to sabotage, vandalism or theft.
...
Prepare project documentation such as Project Plan, Technical Document, Material Document Submission, drawings and OMM.
Participate in the regular meeting of the project, allocate, arrange and complete the relevant work on time according to the meeting requirements and report daily or weekly progress at site.
Manage/Monitor/Track project and control cost to ensure project is completed on time within budget, contractual and safety standard
...
Conduct threat modeling and design reviews for features, APIs, third-party integrations, and major changes.
Coordinate with mobile engineers on cross-platform findings and backend controls protecting native iOS and Android clients.
Own application security implementation for SC TRM and BNM RMiT, including secure SDLC evidence, vulnerability management, testing, and audit remediation.
...
Study, identify, and evaluate emerging security threats and risks, and develop effective mitigation strategies, tools, and systems to manage those threats and risks.
Implement vulnerability assessment and penetrations tests on communications & digital products, services, systems, and organizations to identify security vulnerabilities, and pursue corrective action to address them.
Undertake threat-intelligence gathering and horizon–scanning activities to increase situational awareness and preparedness against arising security threats and risks.
...
Document investigations, findings, and remediation actions accurately within case management systems.
Contribute to security use-case tuning and continuous detection improvement. Support automation initiatives through SOAR playbooks and workflow optimization.
Demonstrate ability to perform event analysis and tools utilization (identification, response, escalation)
...
Document investigations, findings, and remediation actions accurately within case management systems.
Contribute to security use-case tuning and continuous detection improvement. Support automation initiatives through SOAR playbooks and workflow optimization.
Demonstrate ability to perform event analysis and tools utilization (identification, response, escalation)
...
Basic understanding of cyber-attack scenarios, information security and cyber defense
Experience with at least some of the relevant tools and applications - in particular SIEM (preferrable Chronicle), IDS/IPS, Web Application Firewalls, Defender)
Basic understanding of relevant infrastructure architecture and systems in the bank (firewall, proxy, logging & monitoring, MS-Defender, Office 365, Exchange Online, Cloud, Active Directory, etc.)
...