Sign up to save this job, get alerts, and apply with an optimized CV.
Information Security Manager
Lead
Job description
We are looking for an experienced Information Security Manager to join our Banking IT team. This role is responsible for strengthening the bank's information security framework, ensuring compliance with regulatory requirements, and driving security risk management initiatives across the organization. The successful candidate will combine security governance, risk management, and hands-on security expertise to oversee IT controls, coordinate security testing activities, lead awareness programs, and manage the Access Control function while working closely with IT, Risk, Compliance, and external security partners.
Key Responsibilities
- Lead and coordinate the organization's Information Security processes and controls framework.
- Manage the Access Control Team, ensuring effective user access management and compliance with security policies.
- Coordinate and oversee IT Controls Testing activities, ensuring deficiencies are identified, tracked, and remediated.
- Perform cybersecurity risk assessments and support the implementation of risk mitigation plans.
- Contribute to the development, maintenance, and continuous improvement of Information Security policies, standards, and procedures.
- Ensure compliance with applicable regulations and security frameworks, including ISO 27001, GDPR, SWIFT, and DORA.
- Coordinate and manage external penetration testing engagements, ensuring findings are addressed and reported appropriately.
- Plan and execute internal phishing simulation campaigns, analyse results, and drive security awareness initiatives across the organization.
- Support security incident management activities and collaborate with IT teams to investigate and resolve security-related events.
- Prepare and present regular reports on information security risks, testing results, incidents, and compliance status to management.
- Act as a trusted advisor for information security matters across business and technology teams.
Required Qualifications
- 6+ years of experience in Information Security, Cybersecurity, IT Risk Management, or a related field.
- Previous experience in the banking or financial services industry is highly preferred.
- Solid experience with IT Controls Testing, security governance, and regulatory compliance.
- Practical knowledge of Information Security processes, risk assessments, and security control frameworks.
- Experience coordinating penetration testing, vulnerability remediation, and security assurance activities.
- Hands-on experience in conducting or managing security awareness and phishing simulation programs.
- Strong understanding of regulatory and industry standards, including ISO 27001, GDPR, SWIFT, NIST, COBIT, and DORA.
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related discipline.
- Professional certifications such as CISSP, CISM, CRISC, or CISA are considered a strong advantage.
Technical Skills
- Good understanding of Data Loss Prevention (DLP) solutions and related security controls.
- Strong knowledge of Microsoft Active Directory and Microsoft Entra ID (Azure AD).
- Experience with Identity and Access Management (IAM) concepts and privileged access controls.
- Knowledge of vulnerability management, security monitoring, and incident response processes.
- Understanding of security architecture principles and security control implementation.
What We Are Looking For
- Strong ownership and accountability.
- Excellent communication (RO & EN) and stakeholder management skills.
- Ability to balance regulatory requirements with business needs.
- Analytical thinking and sound decision-making capabilities.
- A proactive mindset and passion for continuous improvement.
- High integrity and ability to build trust across the organization.
Required skills
incident response
risk management
gdpr
access control
swift
regulatory compliance
cybersecurity
penetration testing
cissp
information security
vulnerability management
iso 27001
financial services industry
cism
cisa
azure ad
security monitoring
nist
microsoft active directory
it controls
cobit
crisc
dora
microsoft entra id
risk mitigation
security testing
security architecture
vulnerability remediation
awareness programs
security governance
information security manager
identity and access management (iam)
security assurance
it risk management
information security policies
cybersecurity risk assessments
security incident management
phishing simulation
privileged access controls
data loss prevention (dlp)
banking it
information security processes
controls framework
access control team
it controls testing
Sign up to apply
Create a free account to apply for this job and get access to:
- AI-powered CV optimization for this specific job
- Save jobs and create custom alerts
- See your CV match score for each job
Company information
- Company
- Nexent Bank N.V Amsterdam Bucuresti
- Location
-
București; Hybrid
Romania - Posted
- 1 day ago
Interested in this position?
Create your free account and tailor your CV to match this job.