MÔ TẢ CÔNG VIỆC
*Job Summary:
The role requires the leadership and management of technical security, identify trends and drive security improvements across Technology.
Ensure that we have the correct IT policies, procedures, standards, RACI charts and practices for conformance with the IT Governance Framework and mandatory legislation and regulations.
You will be the primary point of contact for audits and risk assessments of the process whether regulatory, external or internal, and to implement and maintain Process Controls
*Key Accountabilities:
− Achieves system security operational objectives by overseeing, contributing information and recommendations to strategic plans and reviews; preparing and completing action plans; implementing production, productivity, quality, and customer-service standards; resolving problems; completing audits; identifying trends; determining system improvements; implementing change.
− Advises senior management by identifying critical security issues; recommending risk-reduction solutions.
− Development, managing and ensuring that the respective functional managers have the correct IT policies, procedures, standards, and practices for conformance with the IT Governance Framework and mandatory legislation and regulations, in place, as defined by Group Compliance. Maintenance across the documentation management lifecycle.
− Define IT RACI charts the acceptance of responsibilities in respect of the supply and demand for IT.
− Manage day-to-day activities related to developing, advising, operations on the IT Functional Area to ensure those follow policies, standards, procedures. Recognize and identify potential areas where existing policies, standards and procedures require change.
− Perform regular IT Governance Maturity Assessments for the respective IT Functional Areas.
− Develop a training plan aligned to the IT Governance for all IT Functional Areas, based on the defined current Skills Matrix.
− Work directly with technical and business leadership across the organization to select, deploy and validate security controls to ensure security and compliance requirements are maintained.
− Conducting internal assessments of IT Policies, Standards and Process compliance to IT Audit standards.
− Manage relationships and interactions with internal and external auditors and risk management bodies, and reviewing, reporting on open issues both prior to and subsequent to issuance.
− Discuss the IT Audit Plan. Collaborate with Group IT to define audit scope.
− Facilitate all requests for information from Group IT for audits.
− Follow-up and provide feedback on all IT Audit findings by collaboration with IT Management.
− Lead and manage the process of self-assessment as part of the overall IT Governance Framework.
− Performs other related duties as required.
YÊU CẦU
Kinh nghiệm
Không yêu cầu
1. Education Background:
− Bachelor of IT.
2. Minimum Experience
− Minimum 4 years’ experience as technical lead in IT security of financial industry;
− Advanced knowledge of Cyber/IT/Information Security practices and methodologies, controls frameworks, risk management and audit methodologies
− Advantage will be COBIT, ISO2700x, PCI-DSS, and ITIL;
3. Other requirements
− Being able to use English at work, fluent English speaking is highly valued;
− Relationship management, negotiation, leadership, teamwork;
− Being creative in work and having good attitude at workplace;
− Being able to work under pressure;
− Knowledge about system, network design; Window, Unix/Linux Operating system;
− Application development methodologies and delivery lifecycle processes
− Project management skill.
*Others:
− To get deep understanding and fully comply with (1) Corporate Integrity Policies (including: policies of Conflict of Interest, Anti-Fraud, Anti-Bribery & Corruption (Gift &Entertainment register), (2) Anti-Money Laundering Policy & Countering Terrorism Financing; (3) and regulation on your roles and responsibilities in operational manual.
− To be responsible for reporting suspected incidents of fraud.
− This job description is reviewed on annually basis and subject to change upon business requirement.
Chia sẻ
Bình luận