Job Description:
Be #InGoodHands with Metrobank!
Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development.
With Metrobank, a meaningful life is within your reach!
Network Security Engineer Design, implement, and maintain network security solutions to protect the Bank’s systems, infrastructure, and data. Support the execution of security strategies and enterprise security projects by enforcing security standards, managing security tools, assessing security risks, and ensuring the effective implementation of security controls. Serve as a subject matter expert for assigned security domains, providing technical guidance, risk assessment support, and continuous improvements to strengthen the Bank’s overall security posture.
Specific Duties & Responsibilities:
- Develops detailed designs for implementation base on the approved IT security systems and infrastructure architecture.
- Formulate, review and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank.
- Provide support to CPSD and SQRD, serve as the security subject matter expert related to IT security and network infrastructure architecture. Identify security design gaps in existing and proposed architectures and recommend changes or enhancements.
- Evaluate cost-effective solutions and prepare the business case for IT security projects.
- Manage the testing of technical controls related to network security and monitors its implementation.
- Define and document network security tool/device standard configuration parameters. Ensures that network security controls are securely configured and functions effectively and efficiently.
- Perform regular security configuration reviews, ensure efficacy of controls and use is optimized.
- Monitor and if necessary, assist ITG administrators in ensuring problems of security devices/systems are timely resolved.
- Review installation and changes to security infrastructure, i.e., firewall, VPN, routers, IDS scanning technologies, servers and network devices and assess impact to security posture and operations.
- Manages the implementation of baseline system security standards various legacy systems.
- Collaborates and coordinates with other ISD Departments to ensure that holistic ISD service is provided to internal customers.
- Establish disaster recovery strategy of network security tools implemented and ensures it is regularly tested for effectiveness.
- Stay up to date with latest security technology and trends, vulnerabilities and threats.
- Proactively works with the SAID Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.
- Perform other information security governance, risk and compliance related duties and responsibilities as directed by the SAID Head.
Qualification
- Bachelor’s degree in computer science, Information Security, Cybersecurity, or a related technical field.
- Strong understanding of security vulnerabilities, common attack techniques, and an attacker mindset to identify and assess potential threats.
- Knowledge of OWASP Top 10 Application Security risks and best practices.
- Relevant certifications such as OSCP, GPEN, GWAP, CEH, or equivalent are preferred.
- Hands-on experience in ethical hacking and penetration testing.
- Strong technical knowledge of networking, digital forensics, reverse engineering, web applications, databases, and wireless technologies.
- Proficiency in scripting and programming to support security testing and assessments.Understanding of the business and financial impact of cybersecurity incidents and breaches.
- Strong analytical and problem-solving skills.
- Results-driven with a focus on risk reduction and remediation.
- Excellent collaboration skills with the ability to work effectively in teams and lead security initiatives.
- Strong written and verbal communication skills, with the ability to explain complex security concepts to both technical and non-technical audiences.
- Excellent time management skills and ability to perform in a fast-paced environment.
- Self-motivated, organized, and capable of working independently.
Requirements: