Own the ICT change, release and configuration management processes for infrastructure, applications, equipment and facilities to minimise service disruption and operational risk.
Establish and maintain resilient ICT architecture with appropriate capacity, redundancy, high availability, disaster recovery and business continuity arrangements.
Ensure compliance with applicable laws, regulatory requirements, contractual obligations and internal governance standards relating to ICT, cybersecurity and data protection.
...
Create, edit, and track physical records in IRM, the firm’s records management system. Provide training to end users to facilitate label creation and the proper maintenance and disposition of physical records.
Identify needed reports and submit requests to ES for custom reports from iRM to capture metrics on core records management functions such as file creation, requests, re-files, transfers, and destruction.
Support the Manager of Information Governance in managing the off-site storage relationship with international regional records management vendors and assist with invoice tracking and payment and budgeting, as needed.
...
Conduct regular assessment on application security
Familiar with security testing tools e.g. Fortify, AppScan and Open Source Scanning tools, technologies on DevSecOps and industry good practice OWASP is preferable
Research and evaluate latest trend & technologies on information security and fintech area, such as FinTech, Artificial Intelligence, Big Data, Cloud Computing etc.
...
Develop and implement automation scripts and tools using Python/Go to streamline application security processes, such as vulnerability scanning orchestration, security control validation, and security metric reporting.
Explore and pilot the use of Generative AI tools and techniques to enhance security testing, code analysis, threat modeling, and vulnerability remediation efforts.
Contribute to the continuous improvement of the secure SDLC framework, security standards, and application security policies.
...
Conduct regular assessment on application security
Familiar with security testing tools e.g. Fortify, AppScan and Open Source Scanning tools, technologies on DevSecOps and industry good practice OWASP is preferable
Research and evaluate latest trend & technologies on information security and fintech area, such as FinTech, Artificial Intelligence, Big Data, Cloud Computing etc.
...