ThePlatformSecurityfunctionoverseestechnicalsecurityforcloudandon-premsystems,ensuringsecure-by- designimplementationacrossapplicationsandinfrastructure.Itmanagesaccesscontrols,enforcessecuritystandards,reviewstools,conductstesting,andvalidatescontrolstomaintaincomplianceandreducerisk.
Duties and Responsibilities:
Security Architecture & Engineering
- Define secure reference architectures for cloud (AWS/GCP), APIs, core banking integrations, and third-party fintech services.
- Ensure security-by-design for applications and infrastructure using Zero Trust principles.
- Lead threat modeling and secure architecture reviews of payment systems, onboarding workflows, and core financial services.
DevSecOps & Automation
- Embed secure SDLC practices by integrating SAST, DAST, and secrets management tools into CI/CD pipelines.
- Enforce security-as-code and policy-as-code (e.g., using Terraform, OPA).
- Automate platform compliance checks via Cloud Custodian, Prisma Cloud, or CSPM tools.
Monitoring, Detection & Incident Response
- Oversee implementation and tuning of SIEM, SOAR, and threat detection systems for real-time monitoring (e.g., GuardDuty, CrowdStrike).
- Direct incident triage, forensics, and investigation efforts during platform-level security events.
- Supervise threat intelligence, detection engineering, and forensic evidence collection.
Governance, Risk & Compliance (GRC)
- Ensure full adherence to BSP Circulars 982/808, PCI-DSS, and ISO 27001.
- Oversee and update security policies, standards, SOPs, and incident response playbooks.
- Lead annual risk assessments and third-party security certifications.
Vendor & API Security Oversight
- Review API authentication, rate limiting, encryption, and Open Finance controls.
- Evaluate vendors and contracts for outsourcing, privacy, and data security requirements.
- Approve third-party integrations and ensure onboarding follows BSP outsourcing guidelines.
Cloud Security & Network Hardening
- Establish cloud security guardrails, multi-cloud governance, and container protection (e.g., CWPP, KMS).
- Approve and monitor firewall configurations, network segmentation, and remote access controls.
Collaboration & Leadership
- Lead organization-wide security awareness programs for internal teams, partners, and customers.
- Serve as lead liaison during BSP inspections, regulatory walkthroughs, and third-party audits.
- Other tasks as assigned by his/her immediate supervisor
Qualifications:
- Bachelor's degree in Information Technology or Security, Cybersecurity, Computer Science, or Engineering
- At least 7 years of experience, with at least 3 in platform or cloud security within fintech or regulated industries.
- Deep technical understanding of AWS/GCP, Kubernetes, IAM, Terraform, WAFs, encryption, scripting, security architecture, security engineering, security operations, risk management.
- Strong familiarity with BSP, DPA,PCI-DSS, ISO 27001, OWASP, MITRE ATT&CK.