Security Framework Alignment: Define and maintain the Bank’s technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
...
Security Framework Alignment: Define and maintain the Bank’s technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
Policy & Standard Engineering: Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
...
Team Leadership & Development: Lead, mentor, and build a high-performing team of Security Governance specialists. Manage resource allocation, performance evaluations, professional development, and day-to-day work prioritization.
Strategic Roadmap Execution: Establish operational goals, key performance indicators (KPIs), and long-term roadmap initiatives for the Network Security Governance team aligned with overall enterprise risk management strategies.
Cross-Functional Stakeholder Management: Act as the primary escalation point and bridge between governance, network engineering, Security Operations Center (SOC), enterprise risk, and external regulatory auditors
...
Manage the daily operations of all security appliances and equipment, including Firewalls, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR) solutions (e.g., FireEye), Intrusion Prevention Systems (IPS), and Network Access Control (NAC) systems.
Ensure optimal performance, availability, and configuration for all managed security components.
Ensure adherence to internal policies, industry best practices, and regulatory guidelines, such as Bank Negara Malaysia's RMiT.
...
Manage the daily operations of all security appliances and equipment, including Firewalls, Web Application Firewalls (WAF), Endpoint Detection and Response (EDR) solutions (e.g., FireEye), Intrusion Prevention Systems (IPS), and Network Access Control (NAC) systems.
Ensure optimal performance, availability, and configuration for all managed security components.
Ensure adherence to internal policies, industry best practices, and regulatory guidelines, such as Bank Negara Malaysia's RMiT.
...
Security Maturity & Roadmaps: Evaluate organizational security maturity, compliance gaps and threat models to deliver actionable, business-aligned security roadmaps.
Architecture & Secure Design: Assess and guide secure architecture patterns across cloud, hybrid environments, zero-trust frameworks, network defense, and IAM systems.
Architecture Review Board (ARB) Alignment: Serve as the primary security engineering liaison to the ARB, ensuring proposed solutions align smoothly with enterprise architecture standards.
...
Security Maturity & Roadmaps: Evaluate organizational security maturity, compliance gaps and threat models to deliver actionable, business-aligned security roadmaps.
Architecture & Secure Design: Assess and guide secure architecture patterns across cloud, hybrid environments, zero-trust frameworks, network defense, and IAM systems.
Architecture Review Board (ARB) Alignment: Serve as the primary security engineering liaison to the ARB, ensuring proposed solutions align smoothly with enterprise architecture standards.
...