Job Summary
The job holder will have responsibility for ensuring that all key risks facing the banks enterprise business applications and
databases are proactively managed in line with best practices. This involves conducting risk assessments developing and
implementing appropriate risk treatment plans developing and implementing security policies and standards.
Duties And Responsibilities
Support the development update and implementation of effective IT security standards policies procedures and guidelines on
the management of the Banks business applications and databases in line with best practices.
Evaluate software asset management practices to ensure proper accountability for all business applications and databases.
Conduct comprehensive risk assessments covering the solution design implementation and operation of the Banks enterprise
business applications to ensure that all key risks are identified/assessed and appropriate controls recommended and implemented
in line with best practice.
Conduct access control and security reviews for all enterprise business applications.
Participate and sign off on security assessments involving additions and enhancements to enterprise business applications and
databases.
Investigation of reported security incidents involving enterprise business applications
Participate in the execution of Information security projects for the Bank.
Requirements
Job Requirement
Good technologyrelated university degree preferably in Computer Science/Electrical Electronics Engineering or Numeric /Social Science.
Security CEH eCPPT OSCP CISSP and CISA are highly desirable.
Minimum of 15 years cognate IT/IT Security experience
Knowledge
Required knowledge and interest in IT Governance Practice
Sound knowledge of Application Security Architecture.
Proven experience in application and database security preferably in the banking or financial industry.
Proven experience in administering Database Activity Monitoring (DAM) tools.
Deep understanding of database management systems (e.g. Oracle SQL Server MySQL) and application security frameworks.
Proficiency in conducting security assessments vulnerability testing and penetration testing on enterprise applications and databases.
Strong knowledge of security protocols encryption techniques access controls and authentication methods.
Experience with security tools such as SAST DAST SIEM IDS/IPS DLP and DAM solutions.