Minimum 5 years of experience in technology risk management, preferably within a Licensed Commercial Bank (LCB), Licensed Specialized Bank (LSB), Licensed Finance Company (LFC), or a Global auditing firm handling financial sector clients. Please refer to the job advert for further information.
Senior Engineer - IT Security and Compliance
With an enduring vision of being the most technologically advanced, innovative and customer friendly financial organization, we, the Most Awarded Bank in Sri Lanka, continue to progress steadily while being the first Sri Lankan bank to be listed amongst the Top 1000 Banks in the World. Our unparalleled record of success is supported by an unmatched suite of digital offerings and superior standards in service, stability and performance. We are poised to ascend to even greater heights in the near future.
JOB PROFILE
- Deploy, and continuously improve the enterprise IT Governance Framework for overseas operations, and subsidiaries aligned with regulatory requirements and global standards (e.g., COBIT, ITIL, ISO/IEC 27001, PCI DSS).
- Conduct annual gap assessments of the IT Governance Framework to identify and remediate compliance deficiencies.
- Map governance controls to regulatory requirements and to COBIT/ ISO 27001 / NIST CSF, and maintain a control-to-regulation traceability matrix.
- Formulate, review, and maintain comprehensive IT policies, standard operating procedures (SOPs), and guidelines.
- Execute end-to-end technology risk assessments across Critical Information Systems (CIS), cloud deployments, and third-party vendor integrations.
- Ensure stringent organizational adherence to the CBSL Regulatory Framework on Technology Risk Management and Resilience and the Personal Data Protection Act (PDPA) No. 9 of 2022.
- Maintain and update the IT Asset and IT Risk Register, facilitating regular Risk Control Assessments with cross-functional IT teams.
- Support compliance with information security controls: user access management and privilege reviews, data encryption, and governance.
- Track audit findings, vulnerabilities, and regulatory gaps, driving mitigation plans to closure within agreed SLAs.
- Maintain an accurate, up-to-date software license inventory and proactively remediate any compliance deviations.
- Manage and fulfill information security due diligence inquiries and questionnaires from clients and third parties.
APPLICANT'S PROFILE
- Bachelor's degree in Information Security, or Computer Science/ Information Technology specializing in fields such as Information/Cyber Security.
- Minimum 5 years of experience in technology risk management, preferably within a Licensed Commercial Bank (LCB), Licensed Specialized Bank (LSB), Licensed Finance Company (LFC), or a Global auditing firm handling financial sector clients.
- Proven experience directly engaging with CBSL regulatory frameworks is preferred.
- Additional professional qualifications such as CISA, CompTIA Security+, ISO27001 Lead Auditor/Implementor, ITIL Foundation, would be an added advantage.
- Advanced knowledge of compliance requirements including PCI DSS, ISO 27001, NIST CSF, CBSL Guidelines and frameworks, and SWIFT security framework.
- Advise and guide IT Operations teams to ensure day-to-day activities align with Governance, Risk, and Compliance (GRC) standards.
Successful candidate will be provided with an attractive remuneration package, commensurate with benchmarked financial institutions.
PLEASE CLICK THE APPLY BUTTON TO SEND YOUR CV VIA XPRESSJOBS