Job Description:
Be #InGoodHands with Metrobank!
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development.
With Metrobank, a meaningful life is within your reach!
The Head of Security Architecture and Innovation Department (SAID) is responsible for defining, developing, and maintaining the Bank’s overall security architecture to protect its information systems, technology infrastructure, and digital assets from evolving security threats and risks. This role aligns security strategies, architectures, policies, and standards with the Bank’s business objectives, regulatory requirements, and risk management framework.
The position leads the development of secure and resilient technology solutions, establishes enterprise security standards and infrastructure strategies, evaluates and implements security technologies, and drives innovation in cybersecurity capabilities. Working closely with ITG and other stakeholders, the role ensures that security is integrated into the design, implementation, and operation of the Bank’s technology environment while supporting business growth, operational efficiency, and regulatory compliance. The role also serves as the Bank’s subject matter expert on security architecture and infrastructure, providing leadership in security risk management, governance, and continuous improvement initiatives.
Key Responsibilities
Security Architecture & Strategy
- Develop a comprehensive understanding of the Bank's technology landscape, information systems, business objectives, and security risks.
- Lead the design and implementation of the Bank's security architecture and infrastructure in alignment with business strategies, technology roadmaps, risk assessments, and industry best practices.
- Define and maintain security architecture frameworks, standards, processes, and procedures that ensure secure and resilient technology environments.
- Drive the development of innovative cybersecurity strategies and solutions to address emerging threats and evolving business needs.
Security Governance & Standards
- Establish and maintain IT security policies, technical standards, procedures, and guidelines governing the protection of information assets, technology infrastructure, facilities, and third-party services.
- Ensure security architecture and infrastructure initiatives align with regulatory requirements, risk management objectives, and the Bank's overall security strategy.
- Identify security gaps and vulnerabilities in existing and proposed technology environments and recommend appropriate remediation or enhancement measures.
Security Infrastructure & Technology Management
- Evaluate, recommend, and oversee the implementation of security technologies and infrastructure solutions.
- Ensure security tools, platforms, and infrastructure components are securely configured, effectively managed, and regularly reviewed for continued effectiveness and optimization.
- Oversee testing and validation of security controls and infrastructure, including disaster recovery and business continuity capabilities.
- Review and approve the implementation and modification of security technologies, including network devices, VPNs, servers, intrusion detection systems, and related infrastructure.
Risk Management & Security Advisory
- Serve as the Bank's subject matter expert on security architecture, infrastructure security, and cybersecurity best practices.
- Provide guidance to technology and business teams on secure solution design and implementation.
- Conduct research on emerging cybersecurity trends, technologies, and threats to strengthen the Bank's security posture.
- Ensure security requirements are appropriately integrated into IT initiatives while balancing business objectives and risk considerations.
- Develop business cases and recommendations for information security projects and strategic investments.
Stakeholder Collaboration & Vendor Management
- Collaborate closely with ITG and other stakeholders to ensure security architecture and infrastructure initiatives are aligned with technology plans and operational priorities.
- Work with other Information Security Division units to deliver integrated and effective security services across the organization.
- Review and approve vendor performance assessments and security-related evaluations as part of the vendor governance process.
Leadership & People Management
- Support the Information Security Division Head in implementing and continuously enhancing the Bank's information security strategy, programs, and initiatives.
- Lead, coach, and develop department personnel, ensuring effective execution of responsibilities and achievement of departmental objectives.
- Manage departmental resources, priorities, and performance to ensure efficient delivery of services.
- Foster collaboration, accountability, and continuous improvement within the team.
Reporting & Administrative Responsibilities
- Prepare management reports, performance updates, and other required departmental reports.
- Perform additional information security governance, risk management, compliance, and related responsibilities as assigned by the Head of the Information Security Division.
Qualifications
- Bachelor's degree in computer science, Information Technology, Cybersecurity, Computer Engineering, or a related field.
- At least 5 years of experience in information security, security architecture, infrastructure security, or IT security risk assessment.
- Strong knowledge and hands-on experience in security architecture, network security, server security, database security, application security, cloud security, data protection, authentication technologies, and infrastructure security.
- Solid understanding of security protocols, cryptography, authentication, authorization, vulnerability management, penetration testing, and cybersecurity risk assessment.
- Experience designing and implementing secure enterprise infrastructure and technology solutions.
- Familiarity with business continuity, disaster recovery, operational security, and security governance frameworks.
- Experience with identity and access management solutions, including multi-factor authentication (MFA), single sign-on (SSO), and identity management technologies.
- Strong analytical, problem-solving, and risk assessment capabilities.
- Professional cybersecurity certifications such as CISSP, CEH, GIAC, GSEC, or equivalent.
- Experience in banking, financial services, or other highly regulated industries.
- Knowledge of cloud security frameworks and controls, including risks associated with cloud computing environments.
- Experience leading security infrastructure projects and evaluating security technologies.
- Familiarity with vendor risk management and third-party security assessments.
Leadership & Core Competencies
- Strong leadership and people management skills with experience coaching, developing, and managing teams.
- Excellent stakeholder management and collaboration skills across business and technology groups.
- Strong project management and organizational capabilities with the ability to manage multiple initiatives simultaneously.
- Ability to identify emerging threats, security gaps, and opportunities for security enhancement.
- Excellent verbal and written communication skills, with the ability to translate complex technical concepts into clear business language.
- Strong decision-making, conflict resolution, and problem-management skills.
- Proficiency in Microsoft Office applications, including PowerPoint, Word, Excel, and Project.
Requirements: