Job Description & How to Apply Below
Job Purpose
The Head of Security Assurance will be responsible for enabling the security of Digital products and services by design and default. He/She ensures that Mashreq’s ICT (Information and communications technology) assets’ vulnerabilities are identified, risk assessed, reported and tracked for effective remediation by the IT asset owner. The scope of the IT assets includes, but is not limited to, Mashreq’s developed code, IT applications and products, IT infrastructure and network.
The Head of Security Assurance will conduct technical risk and exposure assessments, validate security control design and operational effectiveness, provide subject matter expertise on vulnerability management, confirm that IT assets vulnerabilities have been remediated.
The Head of Security Assurance will manage an annual offensive security agenda for the bank. Perform or coordinate penetration tests.
Key Result Areas
Governance
Develop and manage a rolling 3-year Security Assurance roadmap. Update roadmap annually based on changes in business priorities and evolving threat and risk universe.
Develop, implement, and maintain comprehensive policies and procedures related to Security Assurance in alignment with regulatory standards and best practices.
Regularly review and update policies to adapt to evolving security threats and technological advancements.
Engage and Influence Technology departments to ensure they maintain the appropriate tools and environment to optimise security testing and outcomes.
Leadership and Team Management
Lead and manage the Information Security Assurance team, fostering a culture of continuous learning and improvement, and promoting the highest standards of professional conduct and ethical behavior.
Risk management
Identify, assess, report and drive mitigation of security risks associated with code, application and infrastructure assets.
Ensuring compliance with regulatory requirements and internal security standards.
Code, Application, and Infrastructure Vulnerability Management:
Introduce and drive the Secure Software development lifecycle program in the bank by ensuring security by design is embedded in all new development projects, including but not limited to secure code, applications, API and emerging technologies practices and trainings, with expanded Dev Sec Ops , Security Champion and CI/CD focus.
Oversee the identification, assessment, and remediation of vulnerabilities in the bank’s code, applications, and infrastructure. This includes conducting regular vulnerability assessments and penetration tests and working closely with IT and development teams to ensure timely remediation of identified vulnerabilities.
Aid in the automation of implementing security controls within development lifecycle.
Promote and develop vulnerability assurance initiatives work to improve existing security services, including the continuous enhancement of existing methodology material and supporting assets.
Create threat modeling standards and practices based on best standards to ensure vulnerabilities being identified capture the risks and severities agreeable with all teams.
Ensure effective reporting of open risks and vulnerabilities to different teams, business groups, country CISO’s and management committees.
Identify and highlight the obsolescence in the bank’s infrastructure as reported through vulnerability tools.
Ensure effective encryption and key management standards are adopted across Mashreq’s ICT to assure data and encryption keys are secured from unauthorized access.
Red Team Operations
Lead the bank’s red team operations, simulating cyber-attacks to test the effectiveness of the bank’s security measures. This includes planning and executing red team exercises, analyzing the results, and making recommendations for improving the bank’s security posture.
Calendarize and track tasks such as penetration testing, vulnerability management, secure application development and remediation for identified vulnerabilities.
Manage periodic security testing program for the existing and new production systems.
Security Assurance
Provide assurance on the effectiveness of the bank’s information security controls. This…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×