Manager, Secure Configuration Management Specialist, Cyber Security Department
Join to apply for the Manager, Secure Configuration Management Specialist, Cyber Security Department role at Bank Negara Malaysia
Lead Secure Configuration management to develop strategy, plan and operationalisation of secure configuration baseline development, enforcement, deployment, validation, and reporting, and administer and support relevant secure configuration management tool and capability. Ensuring the processes and tools (covering on-premise and cloud environments) are effective and relevant to safeguard the Bank’s critical information assets against emerging cybersecurity threats.
PRINCIPAL ACCOUNTABILITIES
- Lead, plan, oversee and operationalize secure configuration management processes in terms of development, enhancement, enforcement, and validation of secure configuration baselines and reporting its compliance to the management through collaboration with various teams from security architecture, administration, and operation, technical infrastructure, application management, cloud management, and technology governance teams.
- Lead, plan, assess, manage, and support secure configuration management tools (or its equivalences) that enable secure configuration management processes in terms of its system / tools lifecycle to ensure adherence to the technology architecture design, standards and principles, and deliver the intended security objectives without major impact to IT operational performance.
- Lead research and development and / or enhancement on new secure configuration management process, tools, and its baselines, risks and threats and assess whether it is relevant and continuously effective to meet the Bank's security objectives and assessment, and work with relevant security and technical team to develop remediation and / or mitigation plan to address any non-compliance or deviation from secure baselines.
- Build and maintain strategic and technical relationship / networking and collaborations with external IT security experts, IT security technology principal and providers and other IT organisations in order to benchmark and improve the Bank’s IT security service delivery to the stakeholders.
QUALIFICATIONS
Academic Qualifications : Degree in Computer Science / Information Technology or its equivalent.IT technical certifications in operating system systems, networking, databases, and any certification in cyber security such as CISSP, CISA is an added advantage.Technical knowledge and working experience with operating system, network device, databases, middleware administration, cloud, configuration deployment, enforcement and validation tools such as Ansible, Puppet, Tripwire, Change Tracker, Qualys, Tenable, AWS Security Hub, Azure Defender, Google SCC Cloud Security Posture Management, TerraForm, CNAP, CSPM or IaaC scripting.Experience : At least 7 years working experience with strong knowledge in technical infrastructure and cloud technologies and cybersecurity technology, implementation and maintenance.ONLY SHORTLISTED CANDIDATES WILL BE NOTIFIED
Mid-Senior levelFull-timeInformation TechnologyFinancial Services and Information Services#J-18808-Ljbffr