CORPORATE IT SECURITY MANAGER

Il y a 1 jour

MolenbeekSaintJean SintJansMolenbeek, Brussels-Capital, Belgique First BanCorp Temps plein
CORPORATE IT SECURITY MANAGER Our Company At FirstBank PR, we strive to be trusted advisors to our clients, and our employees are the ones that ensure we deliver on our promise of excellence in personalized customer service. Our more than 3,100 employees in Puerto Rico, the Virgin Islands and Florida share a passion for excellent customer service. We are proud of our team because they are continuously surpassing our client’s expectations. Do you have a passion for helping customers, building relationships, and delivering extraordinary, personalized customer service? If your answer is yes, FirstBank is the number one place for you. A Brief Overview The IT Security Manager leads the Corporation’s cyber-defense program and is accountable for security monitoring, detection and response, incident management, vulnerability and exposure management, endpoint, email, network, application, data-loss prevention, and managed security service oversight. The role translates cyber risk into prioritized operational action and provides timely reporting and recommendations to the CSO Management and governance committees. What you’ll do Cyber Security Operations
· Lead Cyber Defense strategy, operating procedures, staffing, service delivery, technology administration, and continuous improvement.
· Oversee SOC/MDR performance, security monitoring, alert triage, investigation quality, escalation, threat hunting, and incident closure.
· Own the Information Security Incident Response Plan and coordinate preparation, response, containment, recovery, communications, evidence preservation, and lessons learned.
· Oversee vulnerability, configuration-hardening, penetration-testing, patch, and exposure-management activities using risk-based prioritization.
· Chair or support the Patch Management Board and related governance, ensuring material vulnerabilities, exceptions, mitigating controls, and overdue remediation are escalated.
· Oversee endpoint, email, network, WAF, DLP, vulnerability-scanning, and other cyber-defense capabilities and ensure they operate as intended.
· Establish AI security operations to monitor AI-enabled threats, misuse, data exposure, agent activity, and emerging attack techniques.
· Expand DLP governance and operations, including monitoring, tuning, investigation, exception management, and reporting.
· Manage critical security service providers, contract and control performance, service-level compliance, remediation, and escalation.
· Develop cyber-risk metrics, dashboards, threat briefings, and executive reports for the CSO Management, management committees, auditors, regulators, and the Board, as required.
· Coordinate with Security Architecture, IAM Governance, Access Management Operations, GRC, Technology, Legal, Privacy, ERM, and business leaders.
· Lead and develop Cyber Defense personnel, define accountabilities, establish coverage and on-call expectations, and maintain succession plans.
· Support new initiatives and technology implementations by identifying operational security requirements and validating readiness. Security Incident Management
· Responsible for the Information Security Incident Response Plan.
· Serve as a subject matter expert for Incident handling and response.
· Establishes and administers a process for investigating and acting on security incidents which may result in a informaiton breaches.
· Conduct Incident Management preparedness.
· Assist in forensic investigations regarding Information Security incident or events Information Security Project Management
· Assist the Project Management Office with the Project Delivery Lifecycle to ensure Information Security practices are maintained in each step: Requirement, Design, Testing, Implementation, etc.
· Ensure key security milestones are completed for each project (where applicable): Vulnerability scans, Code Review, Penetration Tests, Logging capabilities, Role-based Access, etc.
· Server as a Subject Matter Expert and provide recommendations for remediating vulnerabilities identified through Penetration tests and Vulnerability Scans.
· Ascertain hardening standards are contemplated as part of each project implementation. Management of Compliance scan to ensure new applications comply with Corporate Standards.
· Active participant of the Infrastructure Steering Committee. Threat Intelligence
· Ensure the Corporation receives adequate Threat Intel through different forums, such as working knowledge of FS-ISAC and similar open/commercial threat intelligence feeds.
· Process both internal and external Cyber Threat Intel for determination of potential threat and impact, and implementation of mitigating actions.
· Escalate with vendors any outstanding event that may hamper or negatively affect the Corporations IT Assets.
· Follow up with It / Information Security Vendors to ensure updates and upgrades have been implemented. Additional Responsibilities
· Performs other tasks as requested by the Corporate Security Officer.
· Performs/Supports highly technical tasks such as: o Systems and procedures review and implementation o Policies Awareness training o Special Investigations (Forensic) o Root Cause Analysis Process
· Performs special tasks in order to assist internal, external auditors and regulators in their procedures.
· Monitors compliance with continued education requirements.
· Safeguards information related to duties. What You’ll Need to Succeed
· A Bachelor’s Degree in Information Technology, Computer Science, Engineering, or Business is required.
· The incumbent must have at least six (6) years of Information Security experience or experience in a similar position within the banking industry.
· CISSP, CISM or any other similar certification is highly desired but not required.
· A Master's degree in Computer Science, Information Systems, Engineering is preferred.
· Strong understanding of Information Security Frameworks such as COBIT 5, ISO 27000, NIST, and others is required.
· 7 or more years of related work experience in IT, Information Security topics, or developing, implementing or architecting information security systems, in the banking industry highly preferred
· Minimum of 3 years of relevant experience at a financial services company or comparable experience working as an advisor to a financial services company. Competencies
· Strong understanding of Information Security Frameworks such as COBIT 5, ISO 27000, NIST, and others is required.
· Strong understanding of Information Security regulatory requirements and compliance issues, previous experience with applicable regulations from the FDIC, FFIEC, SOX, etc.
· Proficient in EXCEL, WORD, OUTLOOK, ACCESS, POWER POINT
· Knowledge of general security concepts and methods such as vulnerability assessments, privacy assessments, intrusion detection, incident response, security policy creation, enterprise security strategies, architectures and governance
· Experience in project management of information security projects including development of project charters and plans; management of project execution and successful implementation of the planned solution
· Supervisory, interpersonal communication, leadership and team skills
· Able to work in a team oriented, highly demanding and fast paced environment
· Exercise excellent written communication skills with direct experience drafting guidance documentations
· Understand complex business and Information Technology / Information Security processes
· Familiarity with vulnerability assessment and penetration testing best practices
· Organization and prioritization skills
· Strong analytical skills and problem-solving skills
· Strong analytical skills (analytical thinker) and self-starter
· Wide information technology knowledge within the Banking Industry
· Understand and be proficient in common cyber threat terminology, methodologies, possess basic understanding of cyber incident and response, and related current events
· Knowledge in databases, Web Applications, Network and communication Infrastructure, operating systems (ex. IBM, Unix, Linux and Windows), security technologies (firewalls, IDS/IPS, etc.)
· Hands-on skills in audit planning, development of audit programs, fieldwork and wrap-up
· Experience in process definition, workflow design and process mapping
· Committed to accuracy. Must be able to provide out of the box thinking solutions to highly complex issues Disclaimer: The above statements are intended to describe the general nature and level of work being performed by people assigned to this job. They are not intended to be an exhaustive list of all responsibilities, duties, skills required of personnel so classified. The reporting relationship may not reflect the most recent changes to the corporate reporting structure. EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER