Technology Risk Vice President
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, IT Consultant
Lesha Bank is searching for the greatest talent and brightest minds to contribute to the current growth phase at our bank. We are looking for top-tier individuals who are passionate and hungry to add value from day one. Every day at Lesha is different, presenting a new challenge with the opportunity to contribute and grow. We are looking for an Vice President
- Technology Risk
We are seeking an experienced Technology Risk Vice President to strengthen and enhance Lesha Group's cybersecurity risk management and assurance capabilities across its business entities and technology environments.
The role will be responsible for conducting and overseeing cybersecurity risk assessments, evaluating the effectiveness of security controls, performing cybersecurity assurance and compliance reviews, monitoring technology and cyber risk exposure, and supporting the remediation of identified vulnerabilities, control deficiencies, and emerging threats. The position will also contribute to the ongoing enhancement of the Group's cybersecurity governance, risk management, and regulatory compliance framework.
The successful candidate will possess a strong blend of cybersecurity risk management, security assurance, and technical security expertise, with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, project managers, third-party service providers, auditors, and regulatory authorities to strengthen the Group's overall cyber resilience and risk posture.
Key Responsibilities Security Architecture & Technology Risk- Conduct security reviews of enterprise infrastructure, applications, cloud environments, networks, databases, middleware, and security solutions.
- Review proposed technology solutions and architectures to ensure security requirements are incorporated by design.
- Perform threat modelling and security risk assessments for new technologies and business initiatives.
- Define and assess security baselines and configuration standards.
- Provide security recommendations for enterprise architecture and technology transformation initiatives.
- Assess and strengthen security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure environments.
- Conduct cloud security assessments covering identity, network security, workloads, containers, data protection, logging, and monitoring.
- Support security governance for container environments.
- Conduct security and risk assessments of AI, Generative AI, Machine Learning, and emerging technology solutions.
- Assess security controls and compliance requirements for AI-powered applications and third-party AI service providers.
- Establish appropriate security controls for cloud-native, AI-enabled, and emerging technology environments.
- Lead application security assessments throughout the software development lifecycle.
- Establish and enhance secure SDLC and Dev Sec Ops practices.
- Integrate security testing and controls into CI/CD pipelines.
- Oversee SAST, DAST, SCA, penetration testing, and application security reviews.
- Work closely with development teams to identify and remediate application security vulnerabilities.
- Promote security-by-design principles across application development and technology projects.
- Oversee enterprise vulnerability management and risk-based vulnerability remediation.
- Manage penetration testing activities for applications, infrastructure, and external-facing systems.
- Coordinate internal and external penetration testing engagements and track remediation.
- Establish vulnerability management KPIs, KRIs, risk acceptance processes, and remediation timelines.
- Chair or facilitate vulnerability remediation governance forums where required.
- Identify recurring vulnerabilities and drive improvements to the organization's overall security posture.
- Provide governance and oversight of security monitoring and incident response capabilities.
- Work with SOC and security operations teams to improve detection, response, and remediation processes.
- Review SIEM use cases, security monitoring requirements, and incident management processes.
- Support major cybersecurity incident investigations and post-incident improvement activities.
- Ensure lessons learned from incidents are incorporated into security controls and risk management processes.
- Act as a deputy to the Information Security Officer when required, ensuring business continuity and ongoing execution of cybersecurity governance, risk management, compliance, and assurance activities.
- Provide analytical and administrative support to cybersecurity governance forums, risk committees, and management review meetings, including the preparation of presentations, reports, and action tracking.
- Support internal, external, and regulatory audits through evidence collection, stakeholder…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).