10 Sep
|
China Merchants Bank Co.
|
Sydney
10 Sep
China Merchants Bank Co.
Sydney
Established in 1987 in Shenzhen, China Merchants Bank (CMB) is at the forefront of China's reform and opening-up drive, CMB is China's first joint-stock commercial bank and also the first bank to attend the national experiment for the promotion of China's banking industry reform driven by endeavors from outside the government.
We are the one of the largest banks in the world. We bank our value/strategic customers with a wide range of lending and financial products and services to meet their financial needs. You will have the opportunity to work on all aspects of the deal process, from analyzing new investment opportunities, to negotiating deal terms, to presenting these to the firm's credit committee and rating agencies.
More importantly, you will gain invaluable hands-on experience through exposure to many renowned deal opportunities and interaction with many outstanding clients.
Currently we are looking for a friendly and hardworking Information & Data Security with a minimum 3 years of experience to join us.
About the role The Information & Data Security reports to the Head of Information Technology. The role involves driving digitalization and data security initiatives branch-wide, collaborating with cross-functional teams to understand data, system and security requirements, and supporting the secure management and use of data across the Branch.
Key responsibilities
- Drive digitalisation and data security initiatives branch-wide, collaborating closely with cross-functional teams to understand data, system and security requirements and support the secure management and use of data across the Branch.
- Support the implementation, testing,
monitoring and improvement of data systems, workflows and security controls, including the integration and protection of data across various systems and platforms.
- Perform data classification and sensitive data protection activities, and support the implementation and ongoing monitoring of Data Loss Prevention (DLP) controls.
- Manage and review user access across Active Directory, databases and business applications, including periodic access reviews and security log analysis.
- Conduct data security reviews and risk assessments, identify security weaknesses and control gaps, and work with relevant stakeholders to implement appropriate remediation actions.
- Develop and refine information and data security procedures and policies to ensure data protection and compliance with industry best practices and regulatory requirements.
- Monitor and analyse data security events and incidents, including potential data breaches, and support investigation, response, remediation and reporting activities.
- Support the operation and continuous improvement of relevant security platforms and controls, including DLP, SIEM and EDR.
- Prepare and maintain technical and security documentation, including procedures, risk assessments, access review records, incident records and audit evidence.
- Stay updated on the latest information security and data security technologies, threats, regulatory requirements and industry trends.
Skills and Attributes:
Essential Requirements
- 3–4 years of relevant experience in Information Security or Data Security
- Strong foundational knowledge and practical experience in data security, including data classification, user access management, and sensitive data protection
- Hands-on experience in at least one of the following areas: DLP monitoring and analysis, data security reviews, data breach investigations, or data security risk assessments
- Practical experience in user access management, access reviews, and security log analysis across Active Directory, databases, and business applications
- Strong English and Chinese communication, documentation, analytical, and cross-functional collaboration skills
Preferred Qualifications:
- Information Security or Data Security experience within banking, financial services, or other regulated industries (preferred)
- Project or operational experience in DLP, data classification, data breach response, personal information protection, or privacy (preferred)
- Hands-on experience with security platforms such as SIEM, EDR, and DLP, including security monitoring and incident analysis (preferred)
- Experience supporting regulatory compliance, risk assessments, or audits relating to the Australian Privacy Act, APRA CPS 230, and CPS 234 (preferred)
- CISSP or other relevant professional certifications in information security, data security, or privacy (preferred)
📌 Information & Data Security (Sydney)
🏢 China Merchants Bank Co.
📍 Sydney