Provide advisory on application security tools and processes, including but not limited to SAST, DAST, IAST, SCA and secure coding guidelines.
Drive the integration of security activities into the Software Development Life Cycle (SDLC), promoting secure design principles, secure coding practices, and security testing methodologies.
Participate and execute vulnerability analysis and root cause investigations for identified security findings.
...
Design, build, test, operate, and continuously improve enterprise security solutions for IAM involving secrets management (namely API and SSH keys, SSL/TLS certificates etc) across various application deployment environments.
Engineer and operate highly available, resilient, and secure application-focused platforms for secrets management, workload identity and service-to-service authentication.
Configure, manage, and support secrets management solutions and related technologies for applications, including authentication methods, secret engines, policy management, audit logging, replication, backup, disaster recovery, and platform upgrades.
...
Provides vision for privileged access management, enables innovation, and aligns with industry trends and continuous improvements that enhances the security posture of the bank with regards to privileged access.
Responsible for budgeting, project management, deployment and operations support of new initiatives in the privileged access management space.
Drive the automation and integration of privileged access management infrastructure to other systems to achieve straight through processing and reduce manual work.
...
Provides vision for privileged access management, enables innovation, and aligns with industry trends and continuous improvements that enhances the security posture of the bank with regards to privileged access.
Responsible for budgeting, project management, deployment and operations support of new initiatives in the privileged access management space.
Drive the automation and integration of privileged access management infrastructure to other systems to achieve straight through processing and reduce manual work.
...
Serve as a trusted advisor to stakeholders, translating business goals into security solutions, and collaborating with CTOs and CISO to design and implement a technology security roadmap that aligns with the bank’s strategic objectives.
Fortify enterprise security architecture, including cloud platforms, ensuring alignment with financial regulatory requirements, business goals, and industry best practices. Define and maintain reference architectures and technical standards across infrastructure, applications, and data environments.
Lead the evaluation and implementation of security tools, technologies, and services to enhance the bank's security posture.
...
Develops software solutions by studying information needs; conferring with users; studying systems flow, data usage, and work processes; investigating problem areas; following the software development lifecycle.
Determines operational feasibility by evaluating analysis, problem definition, requirements, solution development, and proposed solutions.
Documents and demonstrates solutions by developing documentation, flowcharts, layouts, diagrams, charts, code comments and clear code.
...
Define, champion and oversee enterprise-wide data security governance standards and frameworks that enable secure data usage and mitigate associated risks across the end-to-end data lifecycle.
Ensure data security governance standards and frameworks holistically address the unique challenges of agentic AI, real-time and unstructured data use.
Drive communication, messaging and alignment on data security governance standards and outcomes, at all organisational level.
...
IAM: Design, implement, and maintain IAM solutions, including identity lifecycle management (onboarding, offboarding, access reviews), RBAC, least privilege principles, and integration with diverse application environments (cloud/on premises).
This includes developing Angular-based self-service IAM applications, implementing secure authentication/authorization, and ensuring compliance.
The role also involves monitoring and responding to IAM-related security incidents.
...