Jobiglo

No results.

Senior IT Security GRC Engineer

Commercial Bank of Ceylon PLC · Colombo

Senior 🇬🇧 English
COBIT ITIL ISO/IEC 27001 PCI DSS CBSL Guidelines SWIFT security framework Technology risk assessment

Job description

About the role

We are seeking a Senior IT Security GRC Engineer to lead the design, deployment, and continuous improvement of our enterprise IT Governance framework across overseas operations and subsidiaries. The role ensures compliance with regulatory requirements and global standards while supporting risk‑aware decision making.

Key responsibilities

  • Deploy and continuously improve the enterprise IT Governance Framework aligned with COBIT, ITIL, ISO/IEC 27001, PCI DSS and other global standards.
  • Conduct annual gap assessments, map controls to regulatory requirements, and maintain a control‑to‑regulation traceability matrix.
  • Develop, review and maintain IT policies, SOPs and guidelines.
  • Execute end‑to‑end technology risk assessments for critical information systems, cloud environments and third‑party integrations.
  • Ensure compliance with CBSL Regulatory Framework, PDPA and other local regulations.
  • Maintain the IT Asset and IT Risk Register and facilitate regular risk control assessments.
  • Support information security controls such as user access management, data encryption and privilege reviews.
  • Track audit findings, vulnerabilities and regulatory gaps, driving remediation within agreed SLAs.
  • Maintain an accurate software license inventory and address compliance deviations.
  • Respond to information security due‑diligence inquiries from clients and third parties.

Required profile

  • Bachelor’s degree in Information Security, Computer Science or a related field.
  • Minimum 5 years of experience in technology risk management, preferably within licensed banks, finance companies or a global audit firm serving the financial sector.
  • Direct experience with CBSL regulatory frameworks is preferred.
  • Professional certifications such as CISA, CompTIA Security+, ISO27001 Lead Auditor/Implementor or ITIL Foundation are a plus.

Required skills

  • COBIT
  • ITIL
  • ISO/IEC 27001
  • PCI DSS
  • NIST Cybersecurity Framework
  • CBSL Guidelines and regulatory framework
  • SWIFT security framework
  • Technology risk assessment
  • Governance, Risk & Compliance (GRC) processes

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Commercial Bank of Ceylon PLC.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 3 weeks from now

25 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Commercial Bank of Ceylon PLC

Colombo