Functionally accountable to Team Lead, Global Access Administration or Regional Manager, Global Access Administration (AMER, APAC, EMEA)
Responsible for providing support to all clients which includes employees, contractors and business partners which requires working with Abbott personnel at all levels.
The Global Access Administration organization has a global charter that is principally responsible for ensuring proper control of access to Abbott IT and data assets for enterprise computer platforms and applications on a global, regional, divisional and local basis.
...
Monitor, review and respond to alerts generated from the various security detection tools and case management systems in accordance with established service level agreements and objectives (SLA & SLO) .
Recommend triage actions and maintenance of runbooks and playbooks.
Investigate and escalate security incidents based on the severity level for each event/incident within SLA & SLO.
...
Experience: 8+ years in cybersecurity, technical risk, or IT audit, with 2+ years of direct team leadership, supervisory, or line management experience in a complex enterprise environment.
If you are looking to excel and make a difference, take a closer look at us…
Experience: 8+ years in cybersecurity, technical risk, or IT audit, with 2+ years of direct team leadership, supervisory, or line management experience in a complex enterprise environment.
...
Team Leadership & Development: Lead, mentor, and build a high-performing team of Security Governance specialists. Manage resource allocation, performance evaluations, professional development, and day-to-day work prioritization.
Strategic Roadmap Execution: Establish operational goals, key performance indicators (KPIs), and long-term roadmap initiatives for the Network Security Governance team aligned with overall enterprise risk management strategies.
Cross-Functional Stakeholder Management: Act as the primary escalation point and bridge between governance, network engineering, Security Operations Center (SOC), enterprise risk, and external regulatory auditors
...
Security Framework Alignment: Define and maintain the Bank’s technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
...
Manage the daily operations of all security appliances and equipment, including Firewalls, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR) solutions (e.g., FireEye), Intrusion Prevention Systems (IPS), and Network Access Control (NAC) systems.
Ensure optimal performance, availability, and configuration for all managed security components.
Ensure adherence to internal policies, industry best practices, and regulatory guidelines, such as Bank Negara Malaysia's RMiT.
...
Hold the board-appointed responsibility for day-to-day technology risk oversight and for delivering the board's cyber security strategy.
Build the technology risk and cyber security frameworks, the risk appetite statement and the policy set beneath them, and keep them approved and current.
Run security operations across monitoring, vulnerability and patch management, access control, data protection, cryptography and secure development.
...
Establish, maintain, and enforce cloud security policies, standards, and governance frameworks to ensure secure cloud adoption across the organization.
The Active Defense Center is responsible for the early and effective detection and prevention of attacks on the bank's data integrity and information security in the exciting environment of Cyber Security. We achieve this together with our 3 existing ADC locations in Singapore, Frankfurt and New York together with our new 24/7 first level SOC in KL. We are responsible for the detection and proactive defense against cyber-attack scenarios and actively define and manage the implementation and configuration of appropriate security measures.
In the first level SOC you will be responsible for monitoring our core SIEM tool Google Chronicle as well as MS-Defender and VectraAI. Based on pre-defined playbooks you will initiate response measures as well as document and track incidents in ServiceNowSecOps. In addition, you will provide comprehensive reports on Cyber incidents. Further you will monitor external information sources on upcoming vulnerabilities and available patches and create internal patch advisories for distribution into the Bank. You are characterized by a high level of flexibility and commitment and a basic understanding of Cyber security topics.The role also includes the participation in task forces to respond to cyber threats.
Studies or equivalent training with a focus on information and Cyber security
...
You will manage one of the EIS sub-services workstreams: Endpoint Security, Internet Security, Corporate Data Loss Prevention, and Enterprise Application Security.
You will lead and collaborate on cross-functional projects including vulnerability management, shadow IT, data leakage prevention etc.
You will enforce security policy and controls to protect our corporate environment, yet enabling business by triaging exceptions via balancing the benefit and trade-offs between security and operations.
...