Information Security Advisory Manager

hace 2 meses


Bogotá, Colombia Scotiabank A tiempo completo

 

 

 

 Requisition ID: 203445  

We are committed to investing in our employees and helping you continue your career at ScotiaTech.


 

Purpose

What’s in it for you?

Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor provides advisory services to assist in the development and support of sound security strategies and secure control processes to protect the Bank's information and data resources.

The Team

Contributes to the overall success of IT&S and ICRM in GWE, ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team’s business strategies and objectives. Ensures all activities conducted follow governing regulations, internal policies and procedures..

 

Accountabilities

  • Champions a customer focused culture to deepen client relationships and leverage broader Bank relationships, systems and knowledge.
  • Acting as a central point of reference and core competency for Information Security. Assisting in the classification and protection of data resources by providing guidance on secure and cost effective implementation of Bank's security policies and standards.
  • Representing Information Security in projects, initiatives, mergers and acquisitions. Working with business lines to develop sound security strategic and tactical plans towards the reliable implementation of consistent and secure control processes to protect the Bank.  Drive initiatives and support business functions to assess security risks and to make informed decisions to protect information assets.
  • Providing guidance to design, develop and implement sound risk management controls in accordance with Bank's standards that assure the Bank's compliance with industry regulations.  Keeping informed and well versed on financial industry regulations demands in different regions based on practical experience.
  • Pursuing security and control process improvements to advance security compliance and improve internal processes
  • Participate in initiatives and projects driven by various business lines. Guide project and delivery managers to design and establish sound information security practices, facilitating key artifacts such as security desgin documents, threat/risk assessments and data classifications with the owner to ensure that risks are identified and effectively managed. Where required by risk, lead due diligence reviews over third party outsourcing partners to ensure that their security posture aligns with the Bank and industry best practice. Work with the relationship owner and the third party to create and track an action plan for remediation of issues.
  • Acting as a central point of reference and core competency for Information Security, providing first line subject matter expert advise on classification and protection of data through Bank's information security standards, policies and processes, and industry best practices.
  • Liaise with internal and external security teams and business lines to develop sound security strategic and tactical plans towards the reliable implementation of consistent and secure control processes to protect the Bank.
  • Generate reports associated with the vulnerabilities reported by the different security tools to follow up and manage the remediation of vulnerabilities and weaknesses identified in the technological platform.
  • Monitor, follow up, and define specific actions to guarantee the security compliance of the organization's assets.
  • Execute tasks to keep the security controls and indicators within the optimal thresholds for decreasing the level of security risk in the Organization.
  • Work with our business line partners to assess and ensure compliance to the Bank standards. Escalating risk through appropriate channels.
  • Understand how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.
  • Actively pursues effective and efficient operations of his/her respective areas in accordance with Scotiabank’s Values, its Code of Conduct and the Global Sales Principles, while ensuring the adequacy, adherence to and effectiveness of day-to-day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions and conduct risk.
  • Champions a high-performance environment and contributes to an inclusive work environment.

 

Dimensions

  • Direct reporting line to Director, ICRM GWE. Several projects related to a portfolio of approx. +150 banking applications. No budget, project or financial oversight

 

Education / Experience / Other Information

  • Must have a solid understanding and experience with security controls/mechanisms and threat/risk assessment techniques pertaining to complex data, application and network environments.
  • Strong knowledge of cloud security controls, cloud computing concepts, and cloud architecture security.
  • Knowledge of financial services' Security Governance Framework (policies and standards) is a strong asset.
  • Sound knowledge of cryptographic concepts leveraged in modern applications and systems.
  • Sound knowledge of static and dynamic code analysis.
  • Sound knowledge of Identity & Access Management, PKI, Intrusion Prevention, and vulnerability assessments.
  • Sound knowledge of network security components such as firewalls, routers, intrusion detection, anti-virus software.
  • Strong Microsoft Office software skills particularly Excel, Word, Visio, and PowerPoint.
  • Must have advanced verbal and written communication skills in English.
  • Working knowledge of regulatory guidelines related to the financial industry like OSFI.
  • University degree in computer science/related field or relevant work experience
  • Certifications CISSP, CISM, CCSP, CRISC or alike are nice to have.
  • Other technical certifications are nice to have

 

Working Conditions

  • Work in a standard office-based environment; non-standard hours are a common occurrence.

 

Location(s): Bogotá or Home-Office

ScotiaTech is a business unit within ScotiaGBS, a Scotiabank Group company located in Bogota, Colombia. The ScotiaTech hub was created to support different technology systems and processes of the Bank. We offer an inclusive, positive work environment, and competitive benefits.

At ScotiaTech, we value the unique skills and experiences each individual brings and are committed to creating and maintaining an inclusive and accessible environment for everyone. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at ScotiaTech; however, only those candidates who are selected for an interview will be contacted.

 

Note: All postings in me@Scotiabank will remain live for a minimum of 5 days.



  • Bogotá, Colombia Scotiabank A tiempo completo

    Requisition ID: 203445 We are committed to investing in our employees and helping you continue your career at ScotiaTech. Purpose What’s in it for you? Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor...


  • Bogotá, Cundinamarca, Colombia Scotiabank A tiempo completo

    **Requisition ID**: 205097 We are committed to investing in our employees and helping you continue your career at ScotiaTech. **Purpose** - What’s in it for you?_ Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor...


  • Bogotá, Colombia Scotiabank A tiempo completo

    Requisition ID: 205097 We are committed to investing in our employees and helping you continue your career at ScotiaTech. Purpose What’s in it for you? Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor...


  • Bogotá, Colombia Scotiabank A tiempo completo

        Requisition ID: 205097   We are committed to investing in our employees and helping you continue your career at ScotiaTech. PurposeWhat’s in it for you?Opportunity to showcase your leadership in the Technology Risk Management space by supporting the Global Wealth Engineering team, otherwise known as GWE. An Information Security Advisor provides...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your professional journey.ObjectiveThe TeamThe Threat Monitoring & Response (TMR) team at Scotiabank plays a crucial role in identifying, observing, and analyzing potential threats. Our team oversees essential programs that influence all sectors within the...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we prioritize the growth and development of our employees, fostering a career path that aligns with your aspirations. Objective What benefits can you expect? This role offers a unique opportunity to demonstrate your leadership within the Technology Risk Management domain by supporting the Global Wealth Engineering...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we prioritize the growth and development of our employees, ensuring a rewarding career path. ObjectiveWhat we offer:This role provides an excellent opportunity to demonstrate your leadership capabilities within the Technology Risk Management sector by collaborating with the Global Wealth Engineering team, known as GWE. As a...


  • Bogotá, Colombia Amadeus A tiempo completo

    Job TitleInformation Security AnalystAbout the Area/Department: Our mission is to Provide cross-organizational security operations to predict, detect and react to actual security incidents​.Summary of the role: Information Security Analyst is an active member of the SOC (Security Operations Center) who will support the Computer Security Incident Response...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to nurturing our employees and supporting your professional growth. Objective What benefits await you? This role offers a unique opportunity to demonstrate your leadership capabilities within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, referred to as...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your career advancement. Objective What can you expect? This role offers a unique opportunity to demonstrate your leadership within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, also referred to as...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    At Mitel, you will play a crucial role in enhancing the security posture of our organization, enabling businesses to connect and collaborate effectively while ensuring the protection of sensitive information. Your expertise will be instrumental in driving success within our global operations.Position Overview:Your responsibilities will include the...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to fostering the growth of our employees and supporting your career journey. ObjectiveWhat you can expect:This role offers a unique opportunity to demonstrate your leadership capabilities within the Technology Risk Management sector by collaborating with the Global Wealth Engineering team, also referred to as...


  • Bogotá, Bogotá D.E., Colombia Scotiabank A tiempo completo

    Requisition ID: At ScotiaTech, we are dedicated to nurturing our employees and facilitating their career progression. ObjectiveWhat can you expect?This role offers a chance to demonstrate your leadership capabilities within the Technology Risk Management domain by collaborating with the Global Wealth Engineering team, also referred to as GWE. An Information...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    About Mitel:At Mitel, we empower organizations to enhance connectivity, collaboration, and customer experiences. Your expertise will play a crucial role in driving business success within our global framework, leveraging your distinctive skills and experiences.Position Overview:The role involves the fortification of solutions, meticulous documentation,...


  • Bogotá, Bogotá D.E., Colombia Mitel A tiempo completo

    About Mitel:At Mitel, we empower organizations to connect and collaborate effectively, enhancing customer experiences. Your expertise will play a vital role in driving business success within our global framework, leveraging your distinct skills and experiences.Position Overview:The role involves ensuring the security of our solutions through rigorous...


  • Bogotá, Colombia bbva A tiempo completo

    ¿Qué estamos buscando Talento STEM en el grupo BBVA ¿Que te ofrecemos? Formarás parte de un equipo de más de expertos en Tecnología, en 25 países, cuyo propósito es llevar al banco más allá gracias a la tecnología. Participarás en alguno de los proyectos punteros de tecnología que realizamos anualmente y que tienen un impacto positivo...


  • Bogotá, Colombia bbva A tiempo completo

    ¿Qué estamos buscando Talento STEM en el grupo BBVA ¿Que te ofrecemos? Formarás parte de un equipo de más de expertos en Tecnología, en 25 países, cuyo propósito es llevar al banco más allá gracias a la tecnología. Participarás en alguno de los proyectos punteros de tecnología que realizamos anualmente y que tienen un impacto positivo...


  • Bogotá, Bogotá D.E., Colombia Somewhere A tiempo completo

    Are you an innovative leader in the IT sector with a strong commitment to strategic development and technology enhancement? Join our esteemed organization, Somewhere, as the Director of IT, where you will be instrumental in propelling our technological progress and ensuring comprehensive information security. Position: Director of ITCompensation: USDContract...


  • Bogotá, Colombia ConvaTec A tiempo completo

    Pioneering trusted medical solutions to improve the lives we touch: Convatec is a global medical products and technologies company, focused on solutions for the management of chronic conditions, with leading positions in advanced wound care, ostomy care, continence care, and infusion care. With around 10,000 colleagues, we provide our products and services...


  • Bogotá, Bogotá D.E., Colombia SOS Trabajo A tiempo completo

    General Overview The Cloud Security Specialist plays a crucial role in the development and implementation of secure cloud solutions, ensuring that all necessary security measures and requirements are integrated into the cloud architecture. Key Responsibilities Safeguard the organization's cloud assets in accordance with applicable governance laws,...