Requirements
Requires a BSC in Communication Engineering or Computer Science, with 8+ years of IT & Information Security experience. Demonstrated leadership in vulnerability management, application security, and security assurance programmes is essential. Preferred qualifications include CISSP, CEH, OSCP, GIAC certifications, and a Master's degree in Information Security. Job-specific skills include extensive experience with enterprise vulnerability management tools, application security testing tools, penetration testing methodologies, security compliance monitoring, DevSecOps integration, network security management, and audit evidence preparation.
Description
Summary of Duties:Responsible for managing and implementing the cybersecurity assurance programme. including vulnerability management, application security testing, penetration testing, and security compliance monitoring to protect enterprise systems and applications from security threats.Manage vulnerability management programme using Scanners for comprehensive vulnerability scanning, assessment, remediation tracking, and reporting ensuring effective vulnerability management across the enterprise.Manage and oversee FIM, DAM and firewall assurance operations, coordinating teams, tracking remediation, and ensuring timely closure of identified security gaps.Lead application security testing (SAST) , dynamic application security testing (DAST), software composition analysis (SCA), and secure coding practices ensuring secure application development.Oversee ATM security programme for ATMs including vulnerability assessment, penetration testing, security hardening, and compliance monitoring ensuring ATM security resilience.Coordinate security compliance monitoring including baseline compliance scanning for security baselines, configuration compliance, and regulatory compliance with automated scanning and compliance reporting.Lead IT Security assessment practice for multiple technologies including WAF, NGFW, IPS, ISE, Device Control, MFA, Web Proxy, Mail Proxy, EDR, Application Control, Sandbox, Routers, Switches, SD-WAN .. etc to Validate control effectiveness through configuration reviews, threat-based testing, rule analysis, logging verification, and use-case validation as per standards and industry best practice.Integrate security into DevSecOps pipeline including automated security testing (SAST, DAST, SCA), security gates, and pipeline automation ensuring secure CI/CD.Develop security assurance reports and metrics, prepare evidence for audits, and ensure audit readiness.Minimum QualificationsBSC in Communication Engineering or computer scienceCISSP (Certified Information Systems Security Professional) certificate is preferred.CEH (Certified Ethical Hacking) or OSCP preferredGIAC certifications (GWAPT, GPEN) preferredMaster's degree in Information Security or related field preferredMinimum Experience:8+ Years of IT & Information Security experience with demonstrated leadership in vulnerability management, application security, and security assurance programmesJob Specific SkillsVulnerability Management experience with enterprise tools (Tenable, Nessus, Qualys)Application Security Testing (SAST, DAST, SCA) experience with Fortify and similar toolsPenetration testing methodologies and frameworks (OWASP, PTES)Security compliance monitoring and baseline managementDevSecOps integration and CI/CD securityNetwork security (Firewalls, IPS, WAF) managementSecurity reporting and metrics developmentAudit evidence preparation and regulatory compliance (CBE, PCI, ISO 27001)Banking environment experienceRisk ManagementStrategic planning and programme managementTeam leadership and mentoringStakeholder management at executive level