TDI – Technology Information Security Officer (TISO) – VP
Singapore, One Raffles Quay
Deutsche Bank
Discover Deutsche Bank, one of the world’s leading financial services providers. News and Information about the bank and its productsJob Description:
Details of the Division and Team:
TISO is assigned a set of Application Software Assets and associated Databases, Infrastructure Software Assets, IT Services, Hardware Assets or IT Assets. TISO assumes ownership for these assets from an IT Security perspective.
It includes IT services outsourced to an external vendor and TISO is responsible to ensure compliance. TISO executes all tasks that are assigned to this role based on defined and approved internal policy, procedure, processes & controls.
What we will offer you:
A healthy, engaged and well-supported workforce are better equipped to do their best work and, more importantly, enjoy their lives inside and outside the workplace. That’s why we are committed to providing an environment with your development and wellbeing at its center.
You can expect:
Flexible benefits plan including virtual doctor consultation services
Comprehensive leave benefits
Gender Neutral Parental Leave
Flexible working arrangements
25 days of annual paid leave, plus public holiday & Flexible Working Arrangement
Your key responsibilities:
TISO’s responsibilities within the assigned Division or Function comprise:
To accept the ownership and responsibility for the information security of the assigned IT Assets.
To carry out the Information Security Risk and Compliance Assessments for the assigned IT Assets and processes to help identified IT Assets related risk and determine appropriate controls to mitigate risks
To remain fully trained and skilled by completing the required Information Security training provided by CSO or as requested by the Principal TISO or the Divisional TISO.
To provide guidance to key role holders such as ITAOs (IT Asset Owner) and ISOs (Information Security Officer) to develop a secure environment by evaluating the IT Security requirements as early as possible in the system development life cycle to select the applicable information security controls for implementation.
To guide ITAOs on the implementation of compensating controls in case of deviations from the applicable information security controls.
To approve the access control and user authorization setup of the assigned IT Assets.
To execute and document periodical recertification of access rights in compliance with the DB Group Identity and Access Processes.
Monitor, track, and manage risk mitigations and exceptions and ensure that the necessary Information Security controls are implemented, influences IT risk & control-related policies/standards and provide feedback as subject matter expert. (Co-) Design implementation measures and oversee their implementation.
To cooperate with key role holders such as ITAOs and ISOs to put monitoring capabilities for IT Assets in place. To review the output of the monitoring jointly with the key role holders such as ITAOs and ISOs to avoid degradation of the required security level.
To analyze and review the configuration of IT Assets where required and to advise on the remediation of gaps according to the applicable Information Security policies.
To contribute to the Information Security Incident Management Process in the case of a security breach for their IT Assets, if requested.
To assess and document the IT Risk associated with outsourcing engagements with external vendors
To actively participate in the discussion with external vendors to ensure that proper due diligence is performed on IT Risk & Controls as per Bank’s and Regulatory framework
To maintain the Information Security related documentation of assigned IT Assets in the DB Group IT Asset inventory.
First point of escalation and conflict resolution internal as well as with central functions or parties outside DB (eg. Regulator).
Pre-empt changes in the legal/ regulatory environment and support and advise senior management of potential impacts.
Oversees the performance and quality assurance of assessment executions for upcoming audits and/or execution of legal/ regulatory.
Ensures appropriate senior management awareness/oversight to follow-up on action items to resolve identified issues.
Role is required to be performed on-site at One Raffles Quay office. Relevant vaccination requirements may apply.
Your skills and experience:
Min 7 years’ experience in Information Security risk and compliance management or similar experience.
Working experience in Shell scripting, Windows, Unix, Linux platforms and Oracle & SQL database, Network protocols & security, multi-factor authentication
Proven understanding of MAS & HKMA TRM Outsourcing guidelines and Vendor Risk Management.
Working experience and knowledge : in either of Information Security, Data Protection, Software Development, Audit Management, DevOps Security, Broker solutions, Designing alert mechanisms & Monitoring, Recertification.
Proven experience in advising/implementing/assessing Information Security controls on Business applications
Proven working experience in Configuring TLS/SSL, PKI, ACLs, API Security.
Experience in Cloud Platform
Proven experience in advising/implementing/assessing Information Security controls on Business applications
Proven experience in performing analysis/review/monitoring from Risk management perspective
Working experience and knowledge : in either of Information Security, Data Protection, Software Development, Audit Management, DevOps Security, Broker solutions, Designing alert mechanisms & Monitoring, Recertification.
Proven understanding of MAS & HKMA TRM guidelines.
Minimum bachelor’s degree from an accredited college or university in either Computer Science/Engineering.
Certification in CISA, CISM, CRISC or CISSP.
Cloud Engineer Certification.
Analytical skills to evaluate problem, root cause and suggest a solution.
Experience in translating very complex topics in clear and crisp messages/ visions.
How we’ll support you:
Flexible working to assist you balance your personal priorities
Coaching and support from experts in your team
A culture of continuous learning to aid progression
A range of flexible benefits that you can tailor to suit your needs
Training and development to help you excel in your career
About us and our teams:
Deutsche Bank is the leading German bank with strong European roots and a global network. Click click here to see what we do.
Deutsche Bank & Diversity
We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We welcome applications from all people and promote a positive, fair and inclusive work environment.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Audits CISA CISM CISSP Cloud Compliance Computer Science CRISC DevOps Linux Monitoring Oracle PKI Risk management Scripting SQL TLS UNIX Windows
Perks/benefits: Career development Flex hours Parental leave
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.