Design and Implement Security Infrastructure: Engineer secure and scalable systems, covering firewalls, antivirus, cryptographic systems (e.g., HSM), VPNs, intrusion detection systems (IDS), and other critical tools.
Stay Current and Improve Continuously: Recommend and implement security upgrades based on evolving technologies and threat landscapes.
Collaborate Across Teams: Work closely with architects, engineers, and data scientists to align security measures with enterprise goals.
Serve as Subject Matter Expert (SME): Advise on security architecture across bank-wide projects and initiatives.
Identify and Fix Security Gaps: Review existing and proposed architectures and recommend improvements.
Secure Cloud & On-Prem Environments: Analyze and secure hybrid environments, enhancing protection across platforms.
Develop Baseline Security Standards: Establish, monitor, and ensure compliance with baseline standards across OS, databases, network devices, and security systems.
Lead Network and System Security Architecture: Align infrastructure designs with the bank’s information security strategy.
Incident Preparedness & Response: Ensure disaster recovery processes for security systems are documented, tested, and effective.
Cost-Benefit Analysis & Business Cases: Assess ROI and risk impact for all security infrastructure projects; draft business cases for strategic investments.
Implementation Oversight: Approve and review the installation and configuration of security tools and devices.
Documentation: Maintain detailed records of security implementations and configurations.
Governance & Compliance: Support the SAID Head in enforcing security governance, risk, and compliance programs.
Support and Perform GRC Tasks: Execute other governance, risk, and compliance-related responsibilities as assigned.
Qualifications
Bachelor’s degree in Computer Science, Information Security, or a related field
Minimum 8 years of experience in:
Security architecture and infrastructure
Network, server, application, and cloud security
IT risk assessments, vulnerability testing, and security operations
Strong knowledge in:
Cryptography, authentication protocols, and secure architecture design
Cloud and on-premise security tools and strategies
Multi-factor authentication, identity access management, and endpoint protection
Certifications preferred: CISSP, CEH, GIAC, GSEC, or equivalent
Ability to think like a hacker and proactively defend the organization
Excellent project management, communication, and collaboration skills
Experience in banking or financial services is a plus