Project description
We are seeking a Cyber Security SME to lead the design, implementation, and governance of security controls across the bank's technology landscape. The role will ensure robust protection of platforms, networks, cloud environments, client data, and critical banking infrastructure while maintaining compliance with global regulatory requirements.
Responsibilities
- 1. Security Strategy & ArchitectureDefine and implement enterprise-wide cyber security strategy aligned to the bank's business and technology landscapeDesign and govern secure architectures across:Network infrastructure (on-prem and hybrid connectivity)Cloud platforms (Azure, AWS, GCP)Identity and access management ecosystemsCore banking, trading, and payment systemsEmbed security-by-design and zero trust principles across all layers2. Core Security Domains OwnershipLead and provide SME oversight across key cyber domains:Network Security (firewalls, IDS/IPS, segmentation, secure connectivity, DDoS protection)Cloud Security (secure configuration, CSPM, workload protection, cloud-native controls)Identity & Access Management (IAM/PAM) (RBAC, MFA, privileged access, identity governance)Endpoint & Infrastructure Security (EDR/XDR, device hardening, patching)Application Security (secure SDLC, DevSecOps, API security, code scanning)Data Security (encryption, tokenisation, DLP, data classification)3. Threat & Risk ManagementLead threat modelling and risk assessments across critical banking systems and infrastructureDefine mitigation strategies aligned to frameworks (NIST, ISO 27001, CIS)Oversee vulnerability management, penetration testing, and security assurance activities4. Security Operations & Incident ResponseProvide oversight on SOC, SIEM, SOAR, and threat detection capabilitiesEnhance monitoring through AI-driven anomaly detection and behavioural analyticsDefine and lead incident response strategies for cyber events (ransomware, breaches, insider threats, DDoS)5. Regulatory & ComplianceEnsure compliance with relevant regulations and standards:DORA (Digital Operational Resilience Act)PRA / FCA cyber resilience requirementsGDPR and data protection regulationsSWIFT Customer Security Programme (CSP)Support audits, regulatory reviews, and cyber resilience testing6. Third-Party & Supply Chain SecurityAssess and manage cyber risk across vendors, fintech partners, and infrastructure providersDefine third-party security standards, onboarding controls, and continuous monitoring7. Stakeholder Management & AdvisoryAct as trusted advisor to CIO, CISO, Risk, and business stakeholdersTranslate technical cyber risks into business and operational impactSupport RFPs, client engagements, and strategic cyber transformation initiatives
SKILLS
Must have
- Work Experience:Essential:
- At least 5 years of relevant experience in cyber security within banking / financial servicesProven expertise across network, cloud, IAM, application, and data security domainsHands-on knowledge of security frameworks (NIST, ISO 27001, CIS Controls)Technical CapabilitiesNetwork Security: Firewalls (e.g., Palo Alto, Fortinet), IDS/IPS, VPNs, segmentationCloud Security: Azure/AWS/GCP security services, CSPM, IAM integration, container securityIAM/PAM: Okta, Azure AD, CyberArk, SailPoint or similarSecurity Operations: SIEM (Splunk, Sentinel), SOAR, threat intelligence platformsEndpoint Security: EDR/XDR solutions (e.g., CrowdStrike, Defender)DevSecOps: CI/CD security integration, SAST/DAST toolsData Protection: Encryption standards, key management, DLPRegulatory KnowledgeStrong understanding of cyber resilience expectations within bankingExperience supporting audits, regulatory submissions, and control frameworksSoft SkillsStrong stakeholder engagement and executive communication skillsAbility to operate at both strategic (CISO-level) and hands-on technical levelsExperience working across global, distributed teams
Nice to have
Certifications: CISSP, CISM, CISA, CCSP, Azure/AWS Security certificationsExperience with Zero Trust Architecture and cloud transformation programmesExposure to AI-driven cyber security and automation