Empowering Africa’s tomorrow, together…one story at a time.
With over 100 years of rich history and strongly positioned as a local bank with regional and international expertise, a career with our family offers the opportunity to be part of this exciting growth journey, to reset our future and shape our destiny as a proudly African group.
My Career Development Portal: Wherever you are in your career, we are here for you. Design your future. Discover leading-edge guidance, tools and support to unlock your potential. You are Absa. You are possibility.
Job Summary
The job holder will be a member of the Converged Security Office (CSO), responsible to assist and support the Chief Security Officer in driving the operations across the CSO departments namely Fraud and Forensics, Physical Security, Information Security, Cyber Security, Resilience and Records Management for Mauritius.The primary function of the role is to derive trends and business intelligence based on data analytics obtained across the different departments of the Converged Security Office. Additionally, the job holder will also be involved in the delivery of services provided by the CSO departments and will be closely working with the departmental heads of the Converged Security Office.
The job holder will be involved to deliver on the following areas:
- Ensuring controls as per Group policies and standards are enforced within the Business to ensure information is protected effectively and consistently as per its classification.
- To assist the CSO team in performing security risk assessments for new projects and initiatives.
- To assist the Forensic team to plan and execute professional investigations into suspicions of fraudulent and criminal activities, and any activities as reported by stakeholders.
• To assist the Fraud Operations Team for the monitoring of the fraud risk systems, performing fraud samplings as per relevant policies, processes, and standards, perform data analytics and building Management Information.
Job Description
Cyber Security & Information Risk
- Work closely with the CSO Team to implement best practices for Cyber Security, Information Risk, Resilience and Data Privacy.
- Be a custodian of Cyber Security, Information Risk, Resilience and Records Management in Absa Mauritius and across the group.
Third Party Management
- Assist to carry out Cyber Security and Information Risk due diligence on new 3rd Parties and suppliers.
- Ensure risk is managed and mitigated in accordance with policy and governance, and that regular reviews of risk are provided.
Logical Access Management (LAM)
- Assist the CSO Team to identify appropriate mandates / role profiles for employees, contractors and vendors.
- Assist the CSO Team to establish a process that maintains roles through movements of individuals (joiners/movers/leavers) and assist the business to adhere to the processes in place.
- Ensure that identified in-scope applications meet all requirements of the LAM standards.
Records Management
- Implement and embed the controls on Records Management as mandated by the Group policy and standards.
- Implement paperless initiatives across the organisation.
- Engagement with business functions to promote the use of digital technologies and be less paper based.
Education and Awareness
- Support the CSO Team in delivering education and awareness training programme for Cyber Security, Information Risk, Records Management and Data Privacy within the business.
Data Privacy and Data Leakage Prevention
- Assist the Data Privacy Officer to devise and implement plans and system to manage confidentiality and privacy of information held within the Bank.Assist the Data Privacy Officer to raise awareness on Data Privacy, Data Protection and Cyber Security across the Bank.
Risk and Control Governance
- Assist the Information Security Manager to perform risk assessment on Cyber Security, Information Risk, Resilience and Records Management on a regular basis.
Mandatory Risk and Control Objective
- Ensure all activities and duties are carried out in full compliance with regulatory requirements, Enterprise-Wide Risk Management Framework and Internal ABSA Policies and Policy Standards.
- Understand and manage risks and risk events (incidents) relevant to the role.
Resilience
- Assist the Information Security Manager and the BCM Specialist to carry out Business Continuity simulation testing across the bank.
Reporting
- Assist the CSO Team to prepare the monthly, quarterly, and annual reports which are submitted to internal committees, Boards and Regulators.
- Timely completion of required reporting ensuring all deliverables for Mauritius is effectively closed.
- Build reports on trends analysis for CSO departments to provide business intelligence.Perform market research on new trends and innovations within CSO departments.
Forensic Investigation
- To assist the Fraud and Forensic Manager to investigate cases of criminal, fraudulent and security related incidents, examining appropriate records and documentation, interviewing all relevant parties internally and externally and reporting findings to management.
Fraud Operations
- Assist the Fraud Team to perform fraud sampling of products in line with latest Fraud Sampling Procedures Manual.
- Assist the Fraud Team to conduct analysis on fraudulent cases (including card transactions).
Physical Security
- To support the Physical Security Manager on deliverables within the Physical Security department in terms on managing the security risk profile of the bank, managing security incidents and aligning to the governance as per Absa’s policies and standards.
Other relevant information
- Provide advice and guidance on Cyber Security, Information Risk, Resilience and Records Management to both business and Technology.
- Must be able to implement, drive and monitor initiatives and small projects within the CSO Team.
- Must be able to work without supervision and be able to implement initiatives and changes.
- Perform on tasks assigned by the Chief Security Officer.Participate and support the implementation of strategic initiatives.
Role/Person Specification
Preferred Education:
- Diploma or Degree in Information Technology field or equivalent / Professional Certification in Information Technology or Cyber Security field
- Candidate must hold an Advanced Diploma or Degree (minimum BSc) in Information Technology or equivalent
Preferred Experience:
- Experience in a financial institution dealing with Fraud Operations, Cyber Security, Information Risk or Business Continuity Management would be an advantage.
- 2 years’ experience in IT related field and exposure to Cyber Security and Information Risk related fields.
Professional certification
- Candidate must hold professional certifications related to Cyber Security or Information Security or Information system audits
Knowledge & Skills:
- Good understanding of the Cyber Security/Information Risk best practices and Frameworks.
- Good understanding of new Fraud trends and Fraud prevention
- Good understanding of Cyber Security Frameworks (Identify, Protect, Detect, Respond and Recover)
- Good understanding of IT Security requirements for applications used by Financial Institutions.
- Must be up to date with market techniques and tools for the safeguard of information within organisations.
Technical Competencies.
- Must have exposure to Vulnerability Management and Penetration testing.
- Must have good knowledge of IT Infrastructure, Applications and Database Security requirements.
- A good understanding of data encryption and data pseudonymization.
- A good understanding of the issues faced with outsourcing to external vendors and experience of conducting vendor assessments.
- Must be conversant with controls on Cloud infrastructures.
- Must be conversant with IT Change Management Process best practices.
- Knowledge on business products to enable an effective review of various areas in Operations and Technology and effectively identify risks and controls.
- In depth knowledge of information classification and handling requirements.
- Exposure to Cybersecurity and information security projects.
Behavioral Competencies:
- Team Player and solution driven.
- Must be able to engage and manage stakeholders of the organization.
Education
Further Education and Training Certificate (FETC): Business, Commerce and Management Studies (Required)
