Manager, IT Security Testing Unit

Foreign Trade Bank of Cambodia

Southern Downs Regional

On-site

AUD 180,000 - 230,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Foreign Trade Bank of Cambodia is seeking a Manager, IT Security Testing Unit to lead the security testing program across banking systems, infrastructure, digital channels, applications, APIs and third‑party services. You will oversee vulnerability assessments, penetration testing, and testing strategy to identify and prioritize risks.

The role requires 5+ years in cybersecurity with at least 3 years in leadership, strong reporting skills, and experience in banking or payments.

Qualifications

  • Bachelorss degree or equivalent in CS/IT/Cybersecurity or related field.
  • OSCP, eCPPT, CEH/CPENT, or eJPT type certification preferred.
  • 5+ years cybersecurity experience, including at least 3 years in testing.
  • 3+ years in team leadership, project coordination, vendor management, or reporting.
  • Banking or payments domain experience preferred.

Responsibilities

  • Develop, maintain, and execute the Banks annual IT security testing plan across environments.
  • Lead internal security testing activities within scope, test window, rules of engagement, and data protection requirements.
  • Conduct and/or supervise vulnerability assessments and penetration testing to identify weaknesses.
  • Define security testing methodology, scope, risk rating criteria, acceptance criteria, and evidence requirements.
  • Coordinate and lead external penetration testing, red team/adversarial simulations, PCI DSS, SWIFT related testing.
  • Validate and retest identified vulnerabilities after remediation.
  • Track, report, and escalate remediation progress for vulnerabilities.
  • Prepare and present technical and executive reports to management and stakeholders.
  • Support compliance with NBC TCRMG, PCI DSS, SWIFT CSP, ISO 27001, OWASP.
  • Review testing results from internal/ external sources.
  • Work with system owners and vendors to ensure timely remediation.
  • Provide testing advice for new systems before production deployment.
  • Monitor emerging threats and testing tools relevant to the Banknvironment.
  • Develop and improve testing procedures, templates, KPIs.

Skills

Vulnerability assessment
Penetration testing
Application security testing
Security reporting
Team leadership

Education

Bachelorsss degree in Computer Science, Information Technology, Cybersecurity, or related field

Job description

The Manager, IT Security Testing Unit leads FTB’s security testing program to identify, validate, prioritize, and report technology and cyber risks across banking systems, infrastructure, digital channels, applications, APIs, payment/card environments, and third‑party technology services. The role manages vulnerability assessment, penetration testing, application security testing, mobile/API testing, segmentation testing, adversarial attack simulation coordination, retesting, remediation tracking, and management reporting. The role must ensure testing is performed safely, ethically, and within approved scope, rules of engagement, test windows, data protection requirements, and regulatory expectations.

Responsibilities
  • Develop, maintain, and execute the Bank’s annual IT security testing plan covering applications, infrastructure, network, mobile, API, digital banking, payment systems, and critical technology environments.
  • Lead internal security testing activities within approved scope, test window, rules of engagement, change coordination, data protection requirements, rollback plans, and escalation procedures.
  • Conduct and/or supervise vulnerability assessments and penetration testing to identify security weaknesses in systems, applications, networks, and banking technology platforms.
  • Define security testing methodology, test scope, risk rating criteria, acceptance criteria, evidence requirements, and reporting format for each engagement.
  • Coordinate and lead external penetration testing, red team/adversarial simulation, PCI DSS testing, SWIFT‑related testing, and other independent security assessment projects.
  • Validate and retest identified vulnerabilities after remediation to confirm effective closure and reduce repeat findings.
  • Track, report, and elevate remediation progress for vulnerabilities, including overdue, repeated, high‑risk, and critical findings.
  • Maintain proper security testing records, including test scope, evidence, findings, risk rating, remediation action, retest result, closure status, and management approval where required.
  • Prepare and present technical and executive‑level reports to management, IT Risk Committee, system owners, application owners, and relevant stakeholders.
  • Support compliance with NBC TCRMG, PCI DSS, SWIFT CSP, ISO 27001, OWASP, and internal IT security policies and procedures.
  • Review security testing results from internal teams, external vendors, auditors, regulators, and third‑party service providers.
  • Work with system owners, application owners, infrastructure teams, digital banking teams, and vendors to ensure timely remediation of security weaknesses.
  • Provide security testing advice for new systems, applications, digital banking services, infrastructure changes, and technology projects before production deployment.
  • Monitor emerging threats, attack techniques, exploit trends, vulnerabilities, and security testing tools relevant to the Bank’s environment.
  • Develop and improve security testing procedures, checklists, templates, testing standards, reporting formats, and key performance indicators for the unit.
Qualifications
  • Bachelor’s degree or equivalent in Computer Science, Information Technology, Cybersecurity, Software Engineering, or related field.
  • Professional certification is strongly preferred: OSCP, eCPPT, CEH/CPENT, eJPT, or equivalent penetration testing/application security certification.
  • Minimum 5 years of cybersecurity experience, including at least 3 years in vulnerability assessment, penetration testing, application security testing, or security control assessment.
  • At least 3 years of team leadership, project coordination, vendor management, or management reporting experience is preferred.
  • Banking, financial services, payment/card, SWIFT, or digital banking experience is strongly preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Testing Manager
IT Security Testing Manager

Foreign Trade Bank of Cambodia • Southern Downs Regional

On-site
AUD 180,000 - 230,000
Security Testing - Lead Specialist
Security Testing - Lead Specialist

XPT Software • City of Melbourne

On-site
AUD 160,000 - 230,000
Security Testing Lead
Security Testing Lead

Zone IT Solutions • Council of the City of Sydney

On-site
AUD 110,000 - 170,000
Penetration Tester
Penetration Tester

Xpt Software Australia Pty Ltd • City of Melbourne

On-site
AUD 180,000 - 260,000
Assistant Vice President / Vice President, Information Security Threat Management Specialist (A[...]
Assistant Vice President / Vice President, Information Security Threat Management Specialist (A[...]

Bank of America • Council of the City of Sydney

On-site
AUD 140,000 - 180,000
Penetration Tester
Penetration Tester

Synechron • Sydney

On-site
AUD 120,000 - 180,000
Security Testing Lead Specialist
Security Testing Lead Specialist

XPT Software Australia Pty Ltd • Australia

On-site
AUD 120,000 - 190,000
Vice President, Cyber Threat Intelligence Analyst, Global Information Security, Sydney, Australia
Vice President, Cyber Threat Intelligence Analyst, Global Information Security, Sydney, Australia

Bank of America • Sydney

On-site
AUD 140,000 - 180,000
Penetration Tester
Penetration Tester

W Solutions Co • City of Brisbane

Hybrid
AUD 90,000 - 120,000
Penetration Tester
Penetration Tester

Jobtailor • City of Brisbane

Hybrid
AUD 90,000 - 130,000