Job Description
Key Duties / Responsibilities
- Support in the development and management of programmes and initiatives meant to keep the group secure.
- Support in the development and oversight of tools to control the flow of information within and outside the Bank.
- Perform analysis on IT procedures/processes by reviewing the departmental working manual to identify process gaps and provide value adding recommendations.
- Manage logical access on the Group’s applications, i.e creation of users’ account, role modification, disabling of users’ account and password reset.
- Conduct investigations in the event of a security breach such as cyber-attacks, virus infestations etc. and report the outcome and learning points.
- Perform servers, database and operating system reviews.
- Perform periodic review and monitoring of endpoint security i.e. antivirus, data leakage prevention etc.
- Ensuring compliance with security standards, audits and regulatory requirements.
Required Skills, Knowledge & Attributes
- Solid knowledge of Information Technology processes including system development life cycle; change management; network controls.
- Excellent communication, report writing, presentation and interpersonal skills.
- Possess personal qualities of integrity, credibility, and commitment to corporate mission.
- Problem solving ability and ability to work well under pressure.
- High sense of responsibility, accountability and dependability
- Flexible and able to multitask; can work within an ambiguous, fast-moving environment, and is action oriented.
- In-depth knowledge of security systems, information risk, principles and policies, and their application
Requirements
- Bachelor’s degree in Computer Science, Information Security, Engineering or related field
- Minimum of 2 years of financial services experience focused on information control
- Possession of relevant certifications such as CISA, CISM etc.
- Prior experience in the financial services industry with thorough knowledge of Group’s products, services and capabilities.
- Familiarity with Information Security industry standards/best practices and relevant laws and regulation