Industry: Insurance
Job Type: Permanent
Job Location: BGC - Taguig
Work Setup: On-Site
Experience Level: Manager
Responsibilities
- Ensure compliance with local technology related regulatory requirements and GGM policies
- Execute self-assessments and provide attestation of compliance to technology related GGM policies
- Manages technology and cybersecurity incidents
- Manages technology and cybersecurity RCSA for and scenario analysis as first line owner
- Prepare and submit technology and security update for management reporting
- Review BISG metrics and address any control gap identified
- Facilitate GISP solution implementation within LBU
- Facilitate technology and security related audit
- Conduct technology and cyber security training to relevant stakeholders
- Reviews enhances access (e.g., Cloud Storage, SFTP, RMD, etc.)
- Prepares and completes regulatory required documentations – e.g., Risk and Materiality Assessment, Critical System Assessment, Cloud Risk Assessment, Cloud Consultation Presentation, Internet Insurance Attestation, etc.
- Perform the remediation of security-related issues raised by GISP teams.
- Perform analysis and necessary coordination with relevant teams on the timely remediation of security related KRIs that falls below acceptable threshold.
- Review requests related to Email and Website access whitelisting.
- Review and release approved valid quarantined emails.
- Review and execute security-related dispensations.
- Review and execute Security Design Checkpoint (SDC) related requests
- Conduct Third Party Security Assessment
Requirements
- Bachelor’s degree in information technology, Computer Science or other related courses with 7 years minimum work experienced as Business Information Security Officer. Insurance background is added advantage
- At least 7 years minimum overall related experience to IT Security, Cybersecurity, Operations Risks Management. Reports to BISO
- Experience in one or more of the following:
- Agile Strategy / Agile Transformation / Agile Operating Model
- Lean Software Development Lifecycle
- Problem Solving and Decision Making
- Cybersecurity management
- Agile Methodology
- End-to-end Software Development Lifecycle experience
- Certifications (CISSP, CCSP, Project Management, CRISC, CISM, Security+)