ICBC Turkey is the Turkish subsidiary of ICBC Group, which ranks as the world's largest bank in The Banker's “Top 1000 World Banks” list. Operating in 49 countries today through its global network, ICBC Group is among the most powerful institutions in the international financial sector.
ICBC Turkey Bank is searching for a teammate to be recruited in the Internal Control and Compliance Department under the Head Office.
You will have below responsibilities for this position:
- Employees to be hired will be in charge of the following fields;
- Controlling of the activities and processes of the information systems of the Bank and its subsidiaries subject to consolidation, conducting general controls, preparing IS internal control reports and tracking the actions of the internal control findings
- Assessing the effectiveness of IS general controls, including data security, access management, authorization, change management, log management, segregation of duties, backup, and business continuity etc. controls
- Monitoring and evaluating processes for identifying information systems security risks, control deficiencies, and non-compliance issues, and tracking the resulting action plans
- Monitoring compliance with regulations issued by authorities such as the CBRT, CMB, and the Turkish Data Protection Authority
- Contributing to the enhancement of the information systems control framework in line with regulatory changes and technological developments
- Monitoring third-party software development life cycle (SDLC) controls, code quality and security scan results, and following up on related actions
- Assessing the design and effectiveness of cybersecurity controls and developing recommendations to mitigate risks
- Giving consultancy for new projects and applications
To fit this position, you need to have the below qualifications:
- Bachelor’s or master’s degree in Computer Engineering, Electrical and Electronics Engineering, Software Engineering, Industrial Engineering, Mathematical Engineering, Mathematics, Computer Technology and Information Systems, or a related field from a university recognized by the relevant authorities
- At least 5 years of experience in Information Systems Internal Control, Information Systems Audit, Information Systems Governance or related fields
- Knowledge of the BRSA’s regulations on information systems, as well as governance and information security standards such as COBIT, ITIL, ISO 27001, and ISO 22301
- Preferably holding national or international certifications such as CISA, CISM, CISSP, ISO 27001 Lead Auditor, ISO 22301, or equivalent
- Preferably knowledgeable in data analytics, reporting, and query languages such as SQL
- Advanced proficiency in English, including reading, writing, and speaking
- Strong analytical thinking skills and an inquisitive mindset
This position do not offer a remote work.