jobs in AmBank Group

Kerja Sepenuh Masa, SE, Infrastructure - Group Tech Risk di AmBank Group Federal Territory - Maukerja

SE, Infrastructure - Group Tech Risk

KL City, Federal Territory

Kongsi
Simpan

Lokasi Kerja

  • Jalan Sultan Mizan Zainal Abidin, Kompleks Kerajaan Kuala Lumpur Federal Territory Malaysia

Penerangan Kerja

Tanggungjawab

Purpose

The expectation of this role - requires knowledge and understanding of domains of infrastructure security (data protection, identity access management, security patch management etc) to ensure that AmBank's IT infrastructure is secure, protected and up-to-date in the face of known and emerging cyber threats and "fit for purpose"; providing technology risks advisory support for projects and business functions and recommendations on mitigating cyber risk.


In addition, this person should also be able to collaborate and collate with stakeholders to support in advisory, oversight and assisting on managing cyber risks and ensuring alignment to technology risks objectives are achieved.


Under Technology Risk(2nd line defense), this role will be required to perform an oversight function of IT infrastructure team. Validations must be performed on ‘IT/Security Operation’ as per BNM RMiT requirement, industry best practices, relevant regulatory guidelines and/or Risk and Control Self-Assessment (RCSA) to ensure it is aligned with CISO’s cyber risk strategy, reflecting the ‘Bank’ cyber security maturity level on each control to the desired stage of control.


Responsibilities:

  • Support Infrastructure Security Risk lead in oversight functions of technology risk management, and as a liaison with regulatory bodies and stakeholders (working level) to ensure they are kept abreast with the evolving threat landscape.
  • Responsible for compliance with regulatory requirements such as BNM RMiT, PCI DSS and Security Commission Technology Guideline on Infrastructure Security items
  • Providing IT Infrastructure/cyber security advisory support for projects and business functions and recommendations on mitigating cyber risk.
  • Ensure the IT Infrastructure, its data, files and applications are protected against known threats and attacks and reacting to emerging threats to minimize any risk of comprise of the IT Infrastructure.
  • Support technology risk assessments for infrastructure related projects and work in alignment with 1st line to ensure data security, infra security and cyber security risk elements addressed.
  • Review and make recommendations to provide adequate levels of IT security in line with best industry practice and/or in response to new cyber threats.
  • Coordinate remediation efforts for risk and control issues and support issue closure or risk acceptances, as needed. Work with action owners to collect and evaluate appropriateness of evidence.
  • Ability to identify emerging risks, summarize issues and explain risk trends.


Requirements:

  • Bachelor’s Degree in Computers or Information Technology.
  • Minimum 3-5 Years of Experience in years of Information Technology experience in areas of technology governance, risk management, operational/technology risk and control management.
  • Deep security understanding in IT Infrastructure Security or Cybersecurity.
  • Experience in hands on understanding of security solutions (DLP, IAM, EDR etc)
  • Ability to multi-task, prioritize and work with minimum supervision.
  • Pro-active self-starter demonstrates initiative and works independently with minimum supervision.
  • Strong problem solving, analytical capability and ability to provide insight in a range of situations.
  • Strong collaborative and interpersonal skills as well as an ability to communicate (verbal, written and presentation) across all levels within the organization.
  • Passion and energy combined with a constant desire to challenge the status quo and to drive operational excellence.
  • Excellent reporting skills from understanding the technical perspective (i.e. Security Operation/Engineering, technology Assessment) and articulate into technology/cyber risk to enable stakeholder making risk-based decision.
  • Professional Certifications eg:CEH, CISM, CRISC or ISO 27001 recommended.


Peringatan Penting

Jangan pernah kongsikan maklumat bank atau kad kredit anda semasa memohon pekerjaan. Elakkan membuat sebarang pembayaran atau mengisi survey yang tidak berkaitan. Jika ada yang mencurigakan, sila laporkan iklan pekerjaan ini segera.

Lebih Lanjut