Security Operation team supports security systems and processes in Avaloq to secure Avaloq's and our clients' IT application systems and infrastructure. The team is responsible for security system administrations, and security processes such as policies and standards development, security incident management, vulnerability assessment and security testing among others.
Support and maintain IT Security systems including network security and SIEM system (Splunk).
Conduct IT security incident investigation and threat hunting on the IT environment.
Develop and maintain a security control framework to ensure that security management systems and policies are effective, providing recommendation and remediation.
Develop and support emergency procedures and oversee incident responses as well as the investigation of security breaches and assist with disciplinary and legal matters associated with such breaches as required.
Develop and maintain a standard security contract framework for ITO outsourcing to ensure a harmonized and consistent security control framework.
Develop and maintain a security awareness program to assure a widespread culture of information security awareness.
Support the development and implementation of security policies, standards, guidelines and processes to ensure the ongoing maintenance of physical and logical security.
Participate in the security operational risk management activities as part of the Enterprise Risk Management to identify threats and institute appropriate security programs.
Conduct independent security audits and risk management assessments to verify and provide an opinion on the security posture.
Support and maintain the APAC's Information Security Management System (ISMS) to assure continuous compliance with regulations, laws and contractual obligations by adopting and deploying industry and market standards and accepted best practices.
What you need
Minimum of 5 to 10 years of experience in a similar role, i.e. in a combination role of security risk, information security and IT.
Degree in tertiary studies in relevant fields such as Computer Science, IT Security, Business IT, or IT engineering would be an advantage.
Proven experience in analysis, identifying, monitoring and controlling security risks
Experience in managing Identity / Access management, Intrusion Detection / Prevention, Data Protection and Data Leakage Prevention applications / devices including installation, configuration and its availability
Extended knowledge of relevant international security standards (ISO/IEC 27000-series), best practices (CobiT, ITIL), third party reporting (ISAE3402, SOC), trends and legal and regulatory requirements for data protection and outsourcing in the financial sector (e.g. MAS, HKMA).
Must have a minimum of one of the certifications from ISACA's CSX, CISA, CISM, CGEIT or CRISC or ISC2's SSCP, CCSP, or CISSP or GIAC's GISP or GSEC.