Banking + 2 more
Description
Education and experience required
- Bachelor’s degree in a Technology Business-related field or any other relevant discipline.
- Formal qualification or studying for: Cybersecurity, CEH, Digital Forensics, ITIL or any other related.
Experience required
- 1–2 years of experience in IT/ICT, Governance and Controls, or Risk Management.
- Strong understanding of cyber risk, control frameworks, and regulatory expectations in banking.
- Excellent analytical, communication, and stakeholder management skills.
Knowledge & Skills
- Understanding of cybersecurity control frameworks.
- Understanding of key risks faced by banks and core control of environment
- Familiarity with IT governance/ banks governance requirements and risk management
- Ability to interpret audit logs and security reports.
- Controls Testing & Monitoring
Cybersecurity Control Reviews & Assurance - 30%
- Lead end-to-end reviews of cybersecurity controls across infrastructure, applications, and cloud environments.
- Evaluate effectiveness of technical and procedural controls against frameworks
- Develop and maintain testing methodologies and review schedules.
- Provide assurance reporting to senior stakeholders.
- Review audit logs to identify anomalies and validate control effectiveness.
- Support activities of IT control owners to ensure compliance with internal policies, procedures, and external regulations.
- Identify thematic control issues within Cyber and recommend suitable solutions.
Cyber Risk Assessment & Advisory - 20%
- Conduct cyber risk assessments for new systems, major changes, and third-party integrations.
- Advise project teams and business units on cyber risk mitigation strategies.
- Collaborate with Enterprise Risk and IT to embed cyber risk considerations into business processes.
- Undertake ad-hoc engagements, due diligence work, and demand initiatives as may be required.
Vulnerability & Threat Management Oversight - 15%
- Review vulnerability scan results and threat intelligence reports.
- Track remediation of critical vulnerabilities and systemic issues. •
- Review and monitor privileged access management, recertification campaigns and identity governance across systems
- Escalate unresolved risks and provide input into risk acceptance decisions.
- Provide assurance regarding the remediation of issues in Cyber and Technology.
Regulatory & Audit Support - 10%
- Coordinate responses to internal and external audits, regulatory inspections, and compliance reviews.
- Facilitate and support internal IT security audits, pre-audit validations, and stakeholder engagements.
- Ensure audit findings are effectively managed, and remediation plans are executed and tracked for closure.
- Track and conduct pre-issue validations on AIA and regulatory observations for the business.
Reporting & Metrics - 5%
- Develop dashboards and reports on cyber control effectiveness, risk posture, and review outcomes.
- Present findings to governance forums and risk committees.
- Track key performance indicators (KPIs) and key risk indicators (KRIs).
- Ensure effective tracking, monitoring, and closure of issue findings arising from ad-hoc reviews.
Stakeholder Engagement & Collaboration - 10%
- Liaise with IT, Risk, Compliance, and Business Units to drive cyber control improvements.
- Participate in cross-functional working groups and incident response simulations.
- Support awareness and training initiatives for control owners.
- Attend and enhance business control meetings to ensure significant control and material issues are managed effectively and efficiently across the cyber support business.
- Undertake control awareness sessions on control management for identified officials across Cyber.
Continuous Improvement & Innovation - 5%
- Identify opportunities to automate or enhance review processes using tools and analytics.
- Stay abreast of emerging threats, technologies, and regulatory developments.
- Contribute to the evolution of the cyber assurance framework.
- Identify operational issues and implement modifications and/or upgrades to increase cyber resilience.
Team Participation (Self- Development) - 5%
- Contribute fully to the team effort
- Facilitate coaching / training of team members in areas of specialist knowledge, or allocated areas of common interest
- Share knowledge, information, ideas and assist in the training of less experienced colleagues.
- Consistently equip oneself with relevant knowledge to the role.
Start hiring with Fuzu
Recruit better talent faster - on your own or with our support.
Explore recruitment platformJob search tips from Fuzu
Selected articles on cover letters, CV structure, and interview preparation.
