If you are looking to excel and make a difference, take a closer look at us…
Overview
We are seeking a Technical Governance Manager specializing in Network Security Controls to oversee the policy, compliance, and risk management frameworks governing our bank's perimeter defenses.
In this role, you will act as the ultimate authority on the security rules should be, ensuring our Firewalls, WAFs, Proxies, VPN infrastructure, and Wireless Access Networks strictly adhere to banking regulations and internal security standards. You will ensure that every rule, policy, network access pathway, and application defense mechanism is justified, documented, regularly reviewed, and fully compliant with financial sector mandates.
Responsibilities
- Security Framework Alignment: Define and maintain the Bank's technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
- Policy & Standard Engineering: Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
- Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
- Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
- WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
- WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
- Firewall Rule Lifecycle Governance: Define the mandatory review intervals and lifecycle processes for firewall rules. Oversee the automated or manual recertification of rule base to eliminate legacy, overly permissive, or unused rules.
- Proxy & Content Filtering Governance: Establish governance frameworks for URL categorization, SSL decryption policies, data loss prevention (DLP) integration at the proxy level, and the formal approval process for proxy bypasses.
- VPN & Remote Access Compliance: Ensure VPN configurations, multi-factor authentication (MFA) mandates, and conditional access policies align with Zero Trust principles and banking regulatory standards.
- Assurance & Continuous Auditing: Utilize network assurance and compliance tools to continuously audit configurations against established golden images and security compliance baselines.
- Exception Management & Risk Acceptance: Formally evaluate, risk-score, and manage the lifecycle of technical exception requests (e.g., emergency port openings, WAF rule bypasses for specific legacy applications, or non-compliant wireless device onboarding), ensuring temporary risks are tracked and mitigated.
- Regulatory & Audit Liaison: Serve as the primary subject matter expert during internal, external, and central bank/regulatory audits concerning network perimeter security, application protection, and network access controls.
Skills & Experience We Are Looking For:
- Experience: 5+ years in cybersecurity, technical risk, or IT audit
- Perimeter & Application Security Expertise: Deep conceptual and technical understanding of firewall architectures Web Application Firewall, secure web gateways/proxies and enterprise VPN platforms.
- Identity & NAC Expertise: Proven experience auditing or defining policies within Cisco ISE (Identity Services Engine) for enterprise WiFi management, including certificate-based authentication and guest network segmentation.
- Network Auditing Tools: Strong familiarity with Network Security Policy Management (NSPM) tools used for rule optimization and compliance mapping.
- Regulatory Knowledge: Clear understanding of banking-specific compliance requirements related to network segmentation, application layer security, wireless security, and data protection (e.g., PCI-DSS compliance for public-facing web applications).
- Certifications: CISA /CRISC/ CISSP, or technical networking/security certifications (
- Mindset: A highly analytical, detail-oriented professional who values strict documentation and process-repeatable outcomes over quick operational fixes.
For more job opportunities, please go to HLB Careers: