POSITION DESCRIPTION
Reporting to Head, IT Security, Manager, Application Security, this role is responsible for safeguarding the organization's information systems by identifying and mitigating security vulnerabilities. This role involves planning, executing, and managing advanced penetration tests and security assessments to uncover potential security weaknesses and another task assigned.
DUTY & RESPONSIBILITY
- Develop and implement the Bank's Application Security strategy, framework, and roadmap in alignment with business and regulatory requirements.
- Lead and manage the Application Security team, ensuring the effective delivery of security assessments, penetration testing, and vulnerability management activities.
- Oversee application security assessments, including web, mobile, API, and cloud security reviews, and ensure timely remediation of identified vulnerabilities.
- Establish and maintain application security standards, policies, procedures, and secure development practices.
- Provide security consultation throughout the Software Development Life Cycle (SDLC) and support the implementation of DevSecOps practices.
- Review and approve security assessment reports, risk ratings, and remediation plans prior to management reporting.
- Collaborate with business and IT stakeholders to ensure security requirements are incorporated into projects and system implementations.
- Monitor compliance with applicable regulatory requirements and industry standards, including NBC TCRMG, PCI DSS, OWASP, and ISO 27001.
- Manage security vendors and oversee external security assessments and penetration testing engagements.
- Prepare security metrics, management reports, and executive presentations.
- Support internal and external audits, regulatory examinations, and compliance assessments.
- Mentor and develop team members while promoting continuous improvement and security awareness.
- Perform other duties as assigned by the Head of IT Security Department.
QUALIFICATION
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field.
- Minimum 5 years of experience in Information Security, with at least 2 years in a leadership role.
- Strong knowledge of Application Security, Secure SDLC, DevSecOps, penetration testing, and vulnerability management.
- Familiarity with OWASP, PCI DSS, ISO 27001, NIST, and NBC TCRMG.
- Experience with application security testing tools such as Burp Suite, OWASP ZAP, Nmap, and related technologies.
- Strong leadership, communication, stakeholder management, and problem-solving skills.
- Relevant certifications such as CISSP, OSCP, GWAPT, GPEN, or CEH(P) are preferred.
How to apply
Interested and qualified applicants should submit your updated Cover Letter and CV stating the position applied for with your current photo (4x6) through hr@canadiabank.com.kh

