TDI – Technology Information Security Officer (TISO) – VP

Singapore, One Raffles Quay

Deutsche Bank

Discover Deutsche Bank, one of the world’s leading financial services providers. News and Information about the bank and its products

View all jobs at Deutsche Bank

Apply now Apply later

Job Description:

Details of the Division and Team:

TISO is assigned a set of Application Software Assets and associated Databases, Infrastructure Software Assets, IT Services, Hardware Assets or IT Assets. TISO assumes ownership for these assets from an IT Security perspective.

It includes IT services outsourced to an external vendor and TISO is responsible to ensure compliance. TISO executes all tasks that are assigned to this role based on defined and approved internal policy, procedure, processes & controls.

What we will offer you:

A healthy, engaged and well-supported workforce are better equipped to do their best work and, more importantly, enjoy their lives inside and outside the workplace. That’s why we are committed to providing an environment with your development and wellbeing at its center.

You can expect:

  • Flexible benefits plan including virtual doctor consultation services

  • Comprehensive leave benefits

  • Gender Neutral Parental Leave

  • Flexible working arrangements

  • 25 days of annual paid leave, plus public holiday & Flexible Working Arrangement

Your key responsibilities:

TISO’s responsibilities within the assigned Division or Function comprise:

  • To accept the ownership and responsibility for the information security of the assigned IT Assets.

  • To carry out the Information Security Risk and Compliance Assessments for the assigned IT Assets and processes to help identified IT Assets related risk and determine appropriate controls to mitigate risks

  • To remain fully trained and skilled by completing the required Information Security training provided by CSO or as requested by the Principal TISO or the Divisional TISO.

  • To provide guidance to key role holders such as ITAOs (IT Asset Owner) and ISOs (Information Security Officer) to develop a secure environment by evaluating the IT Security requirements as early as possible in the system development life cycle to select the applicable information security controls for implementation.

  • To guide ITAOs on the implementation of compensating controls in case of deviations from the applicable information security controls.

  • To approve the access control and user authorization setup of the assigned IT Assets.

  • To execute and document periodical recertification of access rights in compliance with the DB Group Identity and Access Processes.

  • Monitor, track, and manage risk mitigations and exceptions and ensure that the necessary Information Security controls are implemented, influences IT risk & control-related policies/standards and provide feedback as subject matter expert. (Co-) Design implementation measures and oversee their implementation.

  • To cooperate with key role holders such as ITAOs and ISOs to put monitoring capabilities for IT Assets in place. To review the output of the monitoring jointly with the key role holders such as ITAOs and ISOs to avoid degradation of the required security level.

  • To analyze and review the configuration of IT Assets where required and to advise on the remediation of gaps according to the applicable Information Security policies.

  • To contribute to the Information Security Incident Management Process in the case of a security breach for their IT Assets, if requested.

  • To assess and document the IT Risk associated with outsourcing engagements with external vendors

  • To actively participate in the discussion with external vendors to ensure that proper due diligence is performed on IT Risk & Controls as per Bank’s and Regulatory framework

  • To maintain the Information Security related documentation of assigned IT Assets in the DB Group IT Asset inventory.

  • First point of escalation and conflict resolution internal as well as with central functions or parties outside DB (eg. Regulator).

  • Pre-empt changes in the legal/ regulatory environment and support and advise senior management of potential impacts.

  • Oversees the performance and quality assurance of assessment executions for upcoming audits and/or execution of legal/ regulatory.

  • Ensures appropriate senior management awareness/oversight to follow-up on action items to resolve identified issues.

Role is required to be performed on-site at One Raffles Quay office. Relevant vaccination requirements may apply.

Your skills and experience:

  • Min 7 years’ experience in Information Security risk and compliance management or similar experience. 

  • Working experience in Shell scripting, Windows, Unix, Linux platforms and Oracle & SQL database, Network protocols & security, multi-factor authentication

  • Proven understanding of MAS & HKMA TRM Outsourcing guidelines and Vendor Risk Management.

  • Working experience and knowledge : in either of Information Security, Data Protection, Software Development, Audit Management, DevOps Security, Broker solutions, Designing alert mechanisms & Monitoring, Recertification.

  • Proven experience in advising/implementing/assessing Information Security controls on Business applications

  • Proven working experience in Configuring TLS/SSL, PKI, ACLs, API Security.

  • Experience in Cloud Platform

  • Proven experience in advising/implementing/assessing Information Security controls on Business applications

  • Proven experience in performing analysis/review/monitoring from Risk management perspective

  • Working experience and knowledge : in either of Information Security, Data Protection, Software Development, Audit Management, DevOps Security, Broker solutions, Designing alert mechanisms & Monitoring, Recertification.

  • Proven understanding of MAS & HKMA TRM guidelines.

  • Minimum bachelor’s degree from an accredited college or university in either Computer Science/Engineering.

  • Certification in CISA, CISM, CRISC or CISSP.

  • Cloud Engineer Certification.

  • Analytical skills to evaluate problem, root cause and suggest a solution.

  • Experience in translating very complex topics in clear and crisp messages/ visions.

How we’ll support you:

  • Flexible working to assist you balance your personal priorities

  • Coaching and support from experts in your team

  • A culture of continuous learning to aid progression

  • A range of flexible benefits that you can tailor to suit your needs

  • Training and development to help you excel in your career

About us and our teams:

Deutsche Bank is the leading German bank with strong European roots and a global network. Click click here to see what we do.

Deutsche Bank & Diversity

We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.

Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.

We welcome applications from all people and promote a positive, fair and inclusive work environment.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: APIs Audits CISA CISM CISSP Cloud Compliance Computer Science CRISC DevOps Linux Monitoring Oracle PKI Risk management Scripting SQL TLS UNIX Windows

Perks/benefits: Career development Flex hours Parental leave

Region: Asia/Pacific
Country: Singapore

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.