Lead Consultant in Information Security

hace 2 semanas


Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

Requisition ID:

At ScotiaTech, we are dedicated to nurturing our employees and supporting your professional growth.

Objective

What benefits await you?

This role offers a unique opportunity to demonstrate your leadership capabilities within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, referred to as GWE. An Information Security Consultant plays a pivotal role in providing expert advisory services to aid in the formulation and execution of robust security strategies and secure control mechanisms to safeguard the Bank's information and data assets.

The Team

You will contribute to the overall success of IT&S and ICRM within GWE, ensuring that specific individual objectives, plans, and initiatives are effectively executed in alignment with the team's business strategies and goals. It is essential that all activities adhere to governing regulations, internal policies, and procedures.

Key Responsibilities

Foster a customer-centric culture to enhance client relationships and leverage broader Bank connections, systems, and knowledge. Serve as a central reference point and core competency for Information Security, assisting in the classification and safeguarding of data resources by offering guidance on the secure and cost-effective implementation of the Bank's security policies and standards. Represent Information Security in various projects, initiatives, mergers, and acquisitions. Collaborate with business lines to develop effective security strategies and tactical plans aimed at the reliable execution of consistent and secure control processes to protect the Bank. Propel initiatives and support business functions in assessing security risks and making informed decisions to safeguard information assets. Provide guidance in designing, developing, and implementing effective risk management controls in accordance with the Bank's standards, ensuring compliance with industry regulations. Stay informed and knowledgeable about the regulatory demands within the financial industry across different regions based on practical experience. Pursue enhancements in security and control processes to advance compliance and improve internal operations. Engage in initiatives and projects led by various business lines. Advise project and delivery managers in designing and establishing sound information security practices, facilitating key documents such as security design documents, threat/risk assessments, and data classifications with the owner to ensure that risks are identified and effectively managed. When necessary, lead due diligence reviews over third-party outsourcing partners to ensure their security posture aligns with the Bank and industry best practices. Collaborate with the relationship owner and the third party to create and monitor an action plan for addressing identified issues. Act as a central reference point and core competency for Information Security, providing first-line subject matter expert advice on the classification and protection of data through the Bank's information security standards, policies, and processes, as well as industry best practices. Collaborate with internal and external security teams and business lines to develop effective security strategies and tactical plans aimed at the reliable execution of consistent and secure control processes to protect the Bank. Generate reports related to vulnerabilities identified by various security tools to monitor and manage the remediation of weaknesses and vulnerabilities within the technological platform. Monitor, follow up, and define specific actions to ensure the security compliance of the organization's assets. Execute tasks to maintain security controls and indicators within optimal thresholds to reduce the level of security risk within the organization. Collaborate with business line partners to assess and ensure compliance with Bank standards, escalating risks through appropriate channels. Understand how the Bank's risk appetite and risk culture should be integrated into daily activities and decision-making processes. Actively pursue effective and efficient operations within respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to, and effectiveness of daily business controls to meet obligations related to operational, compliance, AML/ATF/sanctions, and conduct risk. Promote a high-performance environment and contribute to an inclusive workplace.

Scope

Direct reporting line to the Director, ICRM GWE. Involvement in several projects related to a portfolio of approximately +150 banking applications. No budget, project, or financial oversight.

Education / Experience / Additional Information

A solid understanding and experience with security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application, and network environments is essential. Strong knowledge of cloud security controls, cloud computing concepts, and cloud architecture security is required. Familiarity with the financial services' Security Governance Framework (policies and standards) is a significant asset. Understanding of cryptographic concepts utilized in modern applications and systems is important. Knowledge of static and dynamic code analysis is necessary. Familiarity with Identity & Access Management, PKI, Intrusion Prevention, and vulnerability assessments is required. Understanding of network security components such as firewalls, routers, intrusion detection, and anti-virus software is crucial. Proficiency in Microsoft Office software, particularly Excel, Word, Visio, and PowerPoint, is necessary. Advanced verbal and written communication skills in English (B2) are required. Working knowledge of regulatory guidelines related to the financial industry, such as OSFI, is important. A university degree in computer science or a related field, or relevant work experience, is required. Certifications such as CISSP, CISM, CCSP, CRISC, or similar are advantageous. Other technical certifications are also beneficial.

Working Conditions

Work in a standard office-based environment; non-standard hours may occur.

#LI-Hybrid



  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled and experienced Information Security Consultant Lead to join our team at Scotiabank. As a key member of our Global Wealth Engineering team, you will play a critical role in supporting the development and implementation of sound security strategies and secure control processes to protect our information and data...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your career advancement. Objective What can you expect? This role offers a unique opportunity to demonstrate your leadership within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, also referred to as...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled Information Security Consultant Lead to join our team at Scotiabank. As a key member of our Global Wealth Engineering team, you will play a critical role in supporting the development and implementation of sound security strategies and secure control processes to protect our information and data resources.Key...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled and experienced Information Security Consultant Lead to join our team at Scotiabank. As a key member of our Global Wealth Engineering team, you will play a critical role in supporting the development and implementation of sound security strategies and secure control processes to protect our information and data...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we prioritize the growth and development of our employees, fostering a career path that aligns with your aspirations. Objective What benefits can you expect? This role offers a unique opportunity to demonstrate your leadership within the Technology Risk Management domain by supporting the Global Wealth Engineering...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your career journey. ObjectiveWhat you can expect:This role offers a unique opportunity to demonstrate your leadership capabilities within the Technology Risk Management sector by collaborating with the Global Wealth Engineering team, also referred to as...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled Information Security Consultant Lead to join our team at ScotiaTech. As a key member of our organization, you will play a critical role in supporting the Global Wealth Engineering team and contributing to the overall success of IT&S and ICRM in GWE.Key ResponsibilitiesChampion a Customer-Focused Culture: Deepen...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to nurturing our employees and facilitating their career progression. ObjectiveWhat can you expect?This role offers a chance to demonstrate your leadership capabilities within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, also referred to as GWE. An Information...


  • Bogotá, Bogotá D.E., Colombia Scotiabank - Global Banking and Markets A tiempo completo

    About the RoleWe are seeking a highly skilled Cybersecurity Expert to join our team at Scotiabank - Global Banking and Markets. As an Information Security Consultant Lead, you will play a critical role in supporting the Global Wealth Engineering team in developing and implementing sound security strategies and secure control processes to protect the Bank's...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we prioritize the growth and development of our employees, ensuring a rewarding career path. ObjectiveWhat we offer:This role provides an excellent opportunity to demonstrate your leadership capabilities within the Technology Risk Management sector by collaborating with the Global Wealth Engineering team, known as GWE. As a...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled Cybersecurity Expert to join our team at ScotiaTech. As a key member of our Global Wealth Engineering team, you will play a critical role in supporting the development and implementation of sound security strategies and secure control processes to protect our organization's information and data resources.Key...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your professional journey.ObjectiveThe TeamThe Threat Monitoring & Response (TMR) team at Scotiabank plays a crucial role in identifying, observing, and analyzing potential threats. Our team oversees essential programs that influence all sectors within the...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleThe Team Lead is responsible for leading a group of cybersecurity analysts, reviewing, assessing, and developing their analytical and technical skills. This role requires a strong desire to develop and train security analysts, investigators, and responders to fortify Scotiabank's controls.Key AccountabilitiesChampion a customer-focused culture...


  • Bogotá, Bogotá D.E., Colombia Convatec A tiempo completo

    About ConvatecConvatec is a leading global medical products and technologies company, dedicated to delivering innovative solutions for the management of chronic conditions. Our mission is to improve the lives we touch through pioneering trusted medical solutions.Key ResponsibilitiesInformation Security Management: Develop and implement a robust information...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Security Assurance Lead to join our team at Scotiabank. As a key member of our Security Risk Governance department, you will play a critical role in ensuring the security and integrity of our systems and data.Key ResponsibilitiesLead Security Reviews: Conduct thorough security reviews of our IT systems and...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    At Mitel, you will play a crucial role in enhancing the security posture of our organization, enabling businesses to connect and collaborate effectively while ensuring the protection of sensitive information. Your expertise will be instrumental in driving success within our global operations.Position Overview:Your responsibilities will include the...


  • Bogotá, Bogotá D.E., Colombia TTEC A tiempo completo

    Job Summary:The Security and Compliance Lead will oversee the implementation and maintenance of TTEC's Information Security Policy and contractual standards for specified clients. This role will ensure regular auditing of internal departments to drive calibration across the infrastructure.Key Responsibilities:Propose and evaluate solutions to mitigate risks...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    About Mitel:At Mitel, we empower organizations to enhance connectivity, collaboration, and customer experiences. Your expertise will play a crucial role in driving business success within our global framework, leveraging your distinctive skills and experiences.Position Overview:The role involves the fortification of solutions, meticulous documentation,...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    About Mitel:At Mitel, we empower organizations to connect and collaborate effectively, enhancing customer experiences. Your expertise will play a vital role in driving business success within our global framework, leveraging your distinct skills and experiences.Position Overview:The role involves ensuring the security of our solutions through rigorous...


  • Bogotá, Bogotá D.E., Colombia Somewhere A tiempo completo

    Are you an innovative leader in the IT sector with a strong commitment to strategic development and technology enhancement? Join our esteemed organization, Somewhere, as the Director of IT, where you will be instrumental in propelling our technological progress and ensuring comprehensive information security. Position: Director of ITCompensation: USDContract...