Point your AI agent at freehire and let it find you a job.

Get the CLI →

Equity Group Holdings

NewBe an early applicant

Assistant Manager, IS Technical Assurance Specialist

Posted Updated 5 views
Discussion

Assistant Manager, IS Technical Assurance Specialist
Job Summary
The role holder will be responsible for overseeing the security framework to ensure security controls are in place in
the bank, direct the cyber security strategy, identify threat scenarios, quantify risks, and work with stakeholders to
ensure effective mitigation controls are in place and ensure compliance with all relevant regulatory requirements.
Additionally, he/she will be responsible for overseeing the Bank’s vulnerability posture (vulnerability management),
performing Risk Control Assessments, and designing cybersecurity controls.
Key Responsibilities and Accountability
• Overseeing and implementing the Bank’s cybersecurity program and enforcing the cybersecurity
policy/framework and ensuring up-to-date information security policies and standards are in place,
including the cyber risk management plan.
• Ensure the Bank maintains a current enterprise -wide knowledge base of its users, devices, applications
and their relationships
• Keep up to date with the latest security and technology developments, research/ evaluate emerging
security threats and ways to manage them.
• Ensuring that Equity maintains a current and comprehensive cyber asset and user register. Risk
identification should be forward-looking and include security incident handling.
• Ensuring that information systems meet the needs of the bank, particularly that information system
development strategies comply with the overall business strategies, ERM framework, risk appetite and
ICT policies.
• Design cybersecurity controls with consideration of users at all levels of the organization, including
internal (i.e., management and staff) and external users (i.e., contractors/consultants, business partners
and service providers).
• Organizing professional cyber-related training to improve the technical proficiency of staff and user
awareness training for improved cyber hygiene.
• Detailed exceptions to the approved cybersecurity policies and procedures.
• Assessment of the effectiveness of the approved cybersecurity program.
• All material cybersecurity events that affected the Bank during the period.
• Reporting to the Board, at least quarterly, on EQUITY’S capability to manage cybersecurity and progress
in implementation of the cybersecurity strategy and goals.
• Ensure timely update of the incident response mechanism and Business Continuity Plan (BCP) based on
the latest cyber threat intelligence gathered.
• Incorporate the utilization of scenario analysis to consider a material cyber-attack, mitigating actions,
and identify potential control gaps.
• Ensure adequate backups of critical IT systems and data in line with predetermined recovery objectives
(e.g., real-time backup of changes made to critical data) are carried out to a site that is unlikely to be
affected by a disaster event at the main processing site.
• Ensure the roles and responsibilities of managing cyber risks, including in emergency or crisis decision
making, are clearly defined, documented and communicated to relevant staff.
• Put in place BCP and disaster recovery test plans to ensure that the Bank can continue to function and
meet its regulatory obligations in the event of an unforeseen attack through cybercrime.
• Assess the overall effectiveness of Equity's cybersecurity program.
• Quarterly reporting on the organization’s cybersecurity posture to senior management
• Conduct oversight over and provide directions to any third-party service provider contracted to perform
operational security functions such as information security monitoring, testing, and threat intelligence.
• Use advanced analytic tools to determine emerging threat patterns and vulnerabilities.
• Drive implementation of capabilities to enable an optimal Information Security control environment;
directly responsible for significantly contributing to the overall security posture, stability, and resiliency
of the EQUITY environment and security solutions
• Create and maintain security roadmap requirements by monitoring the control environment; identifying
security gaps; evaluating and implementing enhancements.
• Evaluate and manage outsourced/third-party technologies and hosting environments to ensure they
provide adequate protection for the processing, transmission, and storage of EQUITY’s information;
validate that security controls are designed properly, perform effectively, and align with Group Information
Security
• Work with the application functions, network teams, and IT infrastructure teams to identify and assist
with the implementation of Security policy, process, people, and technology improvements.
• Analyze and provide remediation guidance for identified weaknesses or vulnerabilities; validate and
verify appropriate remediation
• Work closely with the various business and Technology teams to identify and select the right security
controls to protect EQUITY’s network & IT infrastructure, cloud and IoT solutions;
• Drive assessments of security risk and audits; work with Technology Assurance, EQUITY Risk, Audit
and Group teams to review compliance and audit requirements for Information
• Security and ensure they are addressed; Report any residual risk or security exposures against the security
standards, policies, and noncompliance. Provide actionable recommendations
• Ensure that benchmarking is conducted with other companies and organizations within and outside the
industry
• Group and manage the actionable outcomes related to security

Skills

See also

Management jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available