Information Security Consultant Lead

hace 3 días


Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo
Title: Information Security Consultant Lead

Requisition ID: 205097

We are committed to investing in our employees and helping you continue your career at ScotiaTech.

Purpose

Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor provides advisory services to assist in the development and support of sound security strategies and secure control processes to protect the Bank's information and data resources.

The Team

Contributes to the overall success of IT&S and ICRM in GWE, ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team's business strategies and objectives. Ensures all activities conducted follow governing regulations, internal policies and procedures.

Accountabilities

  1. Champions a customer focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  2. Acting as a central point of reference and core competency for Information Security. Assisting in the classification and protection of data resources by providing guidance on secure and cost effective implementation of Bank's security policies and standards.
  3. Representing Information Security in projects, initiatives, mergers and acquisitions. Working with business lines to develop sound security strategic and tactical plans towards the reliable implementation of consistent and secure control processes to protect the Bank.
  4. Providing guidance to design, develop and implement sound risk management controls in accordance with Bank's standards that assure the Bank's compliance with industry regulations.
  5. Pursuing security and control process improvements to advance security compliance and improve internal processes.
  6. Participate in initiatives and projects driven by various business lines. Guide project and delivery managers to design and establish sound information security practices, facilitating key artifacts such as security design documents, threat/risk assessments and data classifications.
  7. Liaise with internal and external security teams and business lines to develop sound security strategic and tactical plans towards the reliable implementation of consistent and secure control processes to protect the Bank.
  8. Generate reports associated with the vulnerabilities reported by the different security tools to follow up and manage the remediation of vulnerabilities and weaknesses identified in the technological platform.
  9. Monitor, follow up, and define specific actions to guarantee the security compliance of the organization's assets.
  10. Execute tasks to keep the security controls and indicators within the optimal thresholds for decreasing the level of security risk in the Organization.
  11. Work with our business line partners to assess and ensure compliance to the Bank standards. Escalating risk through appropriate channels.
  12. Understand how the Bank's risk appetite and risk culture should be considered in day-to-day activities and decisions.
  13. Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank's Values, its Code of Conduct and the Global Sales Principles.
  14. Champions a high-performance environment and contributes to an inclusive work environment.

Dimensions

  • Direct reporting line to Director, ICRM GWE. Several projects related to a portfolio of approx. +150 banking applications. No budget, project or financial oversight.

Education / Experience / Other Information

  • Must have a solid understanding and experience with security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application and network environments.
  • Strong knowledge of cloud security controls, cloud computing concepts, and cloud architecture security.
  • Knowledge of financial services' Security Governance Framework (policies and standards) is a strong asset.
  • Knowledge of cryptographic concepts leveraged in modern applications and systems.
  • Knowledge of static and dynamic code analysis.
  • Knowledge of Identity & Access Management, PKI, Intrusion Prevention, and vulnerability assessments.
  • Knowledge of network security components such as firewalls, routers, intrusion detection, anti-virus software.
  • Strong Microsoft Office software skills particularly Excel, Word, Visio, and PowerPoint.
  • Must have advanced verbal and written communication skills in English (B2).
  • Working knowledge of regulatory guidelines related to the financial industry like OSFI.
  • University degree in computer science/related field or relevant work experience.
  • Certifications CISSP, CISM, CCSP, CRISC or alike are nice to have.
  • Other technical certifications are nice to have.

Working Conditions

  • Work in a standard office-based environment; non-standard hours are a common occurrence.

Location(s): Bogotá or Home-Office

ScotiaTech is a business unit within ScotiaGBS, a Scotiabank Group company located in Bogota, Colombia. The ScotiaTech hub was created to support different technology systems and processes of the Bank. We offer an inclusive, positive work environment, and competitive benefits. At ScotiaTech, we value the unique skills and experiences each individual brings and are committed to creating and maintaining an inclusive and accessible environment for everyone. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at ScotiaTech; however, only those candidates who are selected for an interview will be contacted. #J-18808-Ljbffr

  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Job DescriptionThis role is designed for a seasoned Information Security professional who can lead our team in the development and implementation of sound security strategies.Key ResponsibilitiesAdvise on security controls, threat/risk assessment techniques, and cloud security best practices to ensure the protection of our complex data, application, and...


  • Bogotá, Bogotá D.E., Colombia Emmes A tiempo completo

    Overview Information Security Analyst LATAM Remote Emmes Group: Building a better future for us all. Emmes Group is transforming the future of clinical research, bringing the promise of new medical discovery closer within reach for patients. Emmes Group was founded as Emmes more than 47 years ago, becoming one of the primary clinical research providers to...


  • Bogotá, Bogotá D.E., Colombia Emmes A tiempo completo

    Overview Information Security Analyst LATAM Remote Emmes Group: Building a better future for us all. Emmes Group is transforming the future of clinical research, bringing the promise of new medical discovery closer within reach for patients. Emmes Group was founded as Emmes more than 47 years ago, becoming one of the primary clinical research providers to...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    **Job Overview**The ScotiaTech hub was created to support different technology systems and processes of the Bank. We offer an inclusive, positive work environment, and competitive benefits.As a Security Assurance Lead, you will be responsible for leading a team of analysts and conducting reviews of IT application and supporting IT pervasive controls.Key...


  • Bogotá, Bogotá D.E., Colombia Hire Horatio CX A tiempo completo

    Position Summary: The Information Security and Compliance Lead is responsible for ensuring that Hire Horatio's information technology (IT) systems and processes comply with relevant laws, regulations, and standards. Responsibilities: Monitor and interpret regulatory requirements, industry standards, and best practices related to information...


  • Bogotá, Bogotá D.E., Colombia Control Risks A tiempo completo

    Please submit your CV in English.We are growing our cyber security team.The team provides strategic and technical cyber security consulting to help clients reduce their risk, secure their information, and respond to incidents.We are looking for information security and consulting professionals with a passion for helping clients around the world secure their...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: 212142 Thanks for your interest in ScotiaTech, Scotiabank's new and innovative Technology hub in Bogota. Join a purpose driven winning team that promotes creativity and innovation in a fast-paced environment, where we're always committed to results, in an inclusive, diverse, and high-performing culture. Purpose Security Assurance within...


  • Bogotá, Bogotá D.E., Colombia Control Risks A tiempo completo

    We are growing our cyber security team. The team provides strategic and technical cyber security consulting to help clients reduce their risk, secure their information, and respond to incidents. We are looking for information security and consulting professionals with a passion for helping clients around the world secure their business and manage their cyber...


  • Bogotá, Bogotá D.E., Colombia PayU Payments Private Limited A tiempo completo

    A Career in Information Security with PayUPursuing a career in information security requires dedication, expertise, and passion for protecting sensitive data and maintaining operational continuity. At PayU, we believe that this role plays a vital part in ensuring our organization remains secure and compliant with industry regulations.The successful candidate...


  • Bogotá, Bogotá D.E., Colombia Control Risks A tiempo completo

    Please submit your CV in English. We are growing our cyber security team. The team provides strategic and technical cyber security consulting to help clients reduce their risk, secure their information, and respond to incidents. We are looking for information security and consulting professionals with a passion for helping clients around the world secure...


  • Bogotá, Bogotá D.E., Colombia Control Risks A tiempo completo

    Please submit your CV in English. We are growing our cyber security team. The team provides strategic and technical cyber security consulting to help clients reduce their risk, secure their information, and respond to incidents. We are looking for information security and consulting professionals with a passion for helping clients around the world secure...


  • Bogotá, Bogotá D.E., Colombia Amadeus IT Group, S.A. A tiempo completo

    As an Information Security Professional at Amadeus IT Group, S.A., you will play a critical role in protecting the company's IT infrastructure and data from cyber threats.About the TeamJoin a dynamic team of cybersecurity professionals who are passionate about innovation and excellence.Collaborate with cross-functional teams to identify and address security...


  • Bogotá, Bogotá D.E., Colombia Teletech Holdings, Inc. A tiempo completo

    WelcomePlease sign in or register with us.| My Account OptionsJob Description - Information Security Advisor (03ZVZ) Information Security Advisor Be the spark that brightens days and ignite your career with TTEC's award-winning employment experience.As an Information Security Advisor working remotely in Colombia, you'll be a part of bringing humanity to...


  • Bogotá, Bogotá D.E., Colombia Positivo S+ Latam A tiempo completo

    Job DescriptionWe are seeking a highly skilled IT Security Expert to join our team at Positivo S+ Latam. As a key member of our Information Technology department, you will be responsible for designing and implementing robust security protocols to protect against cyber threats.About the RoleThis is an exciting opportunity to work with a leading organization...


  • Bogotá, Bogotá D.E., Colombia Horatio A tiempo completo

    Information Security and Compliance Lead (BOG)Horatio Bogota, D.C., Capital District, ColombiaPosition Summary:The Information Security and Compliance Lead is responsible for ensuring that Hire Horatio's information technology (IT) systems and processes comply with relevant laws, regulations, and standards.Responsibilities:- Monitor and interpret regulatory...


  • Bogotá, Bogotá D.E., Colombia TeleTech Holdings, Inc. A tiempo completo

    Welcome Please sign in or register with us. | My Account OptionsJob Description - Information Security Advisor (03ZVZ)Information Security AdvisorBe the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Information Security Advisor working remotely in Colombia, you'll be a part of bringing humanity to...


  • Bogotá, Bogotá D.E., Colombia TeleTech Holdings, Inc. A tiempo completo

    Welcome Please sign in or register with us. | My Account Options Job Description - Information Security Advisor (03ZVZ) Information Security Advisor Be the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Information Security Advisor working remotely in Colombia, you'll be a part of bringing humanity...


  • Bogotá, Bogotá D.E., Colombia TeleTech Holdings, Inc. A tiempo completo

    Job Description - Information Security Advisor (03ZVZ)Information Security AdvisorBe the spark that brightens days and ignite your career with TTEC's award-winning employment experience. As an Information Security Advisor working remotely in Colombia, you'll be a part of bringing humanity to business. #experienceTTECWhat You'll Do1. Establish positive...


  • Bogotá, Bogotá D.E., Colombia Amadeus IT Group, S.A. A tiempo completo

    Information Security Analyst page is loaded Information Security Analyst Apply locations Bogota time type Full time posted on Posted 5 Days Ago time left to apply End Date: March 17, 2025 (14 days left to apply) job requisition id R25565 About the Business Area/Department: Our mission is to provide cross-organizational security operations to...

  • IT Security Lead

    hace 2 días


    Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    About this IT Security Lead Position:We are looking for an experienced IT Security Lead to lead a team of analysts and/or conduct reviews of IT application and supporting IT pervasive controls.Main Responsibilities:Maintain documentation supporting business requirements.Day-to-day decisions regarding approaches to security and control reviews are handled...