About this role
<p> </p> <p><span style=""><strong>Be #InGoodHands with Metrobank!</strong></span></p> <p> </p> <p><span style="">Here at Metrobank, we don't simply hire employees—we hone future leaders. We provide opportunities that enhance your skills and unlock your talents, helping you evolve into a well-rounded individual. We supply you with all the pieces you need to do your best work, unleashing your full potential to help you secure your future and lead a fulfilling career. And with Metrobank's strong heart for the community, you have the chance to give back and make worthwhile contributions to our nation's economic and social development. With Metrobank, a meaningful life is within your reach!</span></p> <p> </p> <p><span style=""><strong>Position Title: </strong>Platform Engineer</span></p> <table class="MsoNormalTable" style="width:1475.0px;border-collapse:collapse;border:none;height:140.531px" border="1" cellspacing="0" cellpadding="0"> <tbody> <tr style="height:105.4pt"> <td style="width:1460.62px;border:none;padding:0.0in 5.4pt" valign="top"> <p style="margin:0.0in -22.5pt 1.0E-4pt 0.0in;Times New Roman', serif"> </p> <p style="margin:0.0in -22.5pt 1.0E-4pt 0.0in;Times New Roman', serif"><span style=""><strong>Job Summary: </strong></span></p> <p style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"> </p> <p style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"><span style="">Understand the organization, overall business goals and security risks in order to define the overall security required to protect the Bank’s IT system and infrastructure. Develop the security architecture of the Bank that addresses threats. Develop and establish the security policies and standards that support and guide the implementation of the security architecture. Develop the security infrastructure strategy, evaluate security solutions and manage its implementation. Establish strategies to innovate security in the Bank’s IT infrastructure and collaborate with ITG Teams in developing and implementing secure solutions and infrastructure.</span></p> <p style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"> </p> </td> </tr> </tbody> </table> <p style="margin:0.0in -22.5pt 1.0E-4pt 0.0in;Times New Roman', serif"><span style=""><strong>Specific Duties & Responsibilities:</strong></span></p> <p style="margin:0.0in -22.5pt 1.0E-4pt 0.0in;Times New Roman', serif"><span style=""><strong> </strong></span></p> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Develop a complete understanding of the Bank’s technology and information systems.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Architect and implement security systems based on the <a href="https://security.uci.edu/security-plan/index.html"><span style="">Information Security roadmap and plan</span></a>, results of security risk assessments, IT security best practices, IT and business strategy.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Leads the development of a secure information system infrastructure design and architecture. </span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Develop the specifications, processes and procedures for the implementation of capabilities that meets security requirements and resilient security infrastructure.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Collaborates and coordinates with ITG the security architecture and infrastructure design to ensure alignment with IT plans and activities.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Formulates and maintain IT security policies, technical standards, internal ISD procedures and guidelines related to securing the information processing environment, IT facilities and connected third party services/providers of the Bank. </span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Researches on new IT security architectures and solutions to keep abreast of new techniques to support the changing business environment and mitigate emerging threats.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Serves as the information security subject matter expert on matters related to IT security architecture and infrastructure. Identify security design gaps in existing and proposed architectures and recommend changes or enhancements.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Manages the testing of security tools and infrastructure controls and monitors its implementation. Ensures disaster recovery procedures of security infrastructure are established and tested.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Ensures that IT security infrastructure projects make business sense without sacrificing the need for security controls and control objectives are met. Prepares the business case for IT security projects.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Ensures that IT security infrastructure is securely configured and functions effectively and efficiently, configuration of security tools are regularly reviewed to ensure efficacy and its use is optimized.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Approve vendor performance review as part of VPRC process.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Review and approve installation of and changes in security tools/infrastructure, VPN, routers, IDS scanning technologies, servers and network devices.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Collaborates and coordinates with other ISD Departments to ensure that holistic ISD service is provided to internal customers.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Proactively works with the Information Security Division Head in implementing programs for the continuous improvement of the bank’s information security plans and strategies.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Manages utilization of resources within his/her department and performance of department officers and staff. Provide supervision and guidance to the team to ensure assigned function and tasks are completed.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Prepare department management and performance reports and other reports as required.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Performs other information security governance, risk and compliance related duties and responsibilities as directed by the Head of the Information Security Division</span></li> </ul> <p style="margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"><span style=""><strong> </strong></span></p> <table class="MsoNormalTable" style="border-collapse:collapse" border="0" cellspacing="0" cellpadding="0"> <tbody> <tr> <td style="width:5.2in;padding:0.0in 5.4pt 0.0in 5.4pt" valign="top"> <p style="margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"><span style=""><strong>Job Specifications:</strong></span></p> <p style="margin:0.0in 0.0in 1.0E-4pt;Times New Roman', serif"><span style=""><strong> </strong></span></p> </td> <td style="width:68.8pt;padding:0.0in 5.4pt 0.0in 5.4pt" valign="top"> <p style="margin:0.0in 0.0in 1.0E-4pt;text-align:justify;Book Antiqua', serif"> </p> <p style="margin:0.0in 0.0in 1.0E-4pt;text-align:justify;Book Antiqua', serif"> </p> </td> </tr> </tbody> </table> <ul style="margin-bottom:0.0in;margin-top:0.0px"> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Has deep understanding, strong working knowledge and experience in building/implementing IT Systems Architecture/Infrastructure Security, authentication technologies, Server Security, Network Security, Database Security, Application Security, Communications Security, Data Security, High Level Code Review, Static and Dynamic Code Analysis, IT Security Risk Assessment, Vulnerability Assessment, Penetration Testing, Business Continuity, Physical Security, Operations Security and Cloud Secure architecture.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Has at least 5 year experience in IT security and IT security risk assessment</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Solid understanding of security protocols, cryptography, authentication, authorization and security</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Security considerations of cloud computing, including data breaches, hacking, account hijacking, malicious insiders, third parties, authentication, APTs, data loss and DoS attacks</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Preferably with IT security related certification such as CISSP, CEH (or equivalent) GIAC, GSEC, etc.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Extensive experience on IT security risk assessment</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Ability to think like a malicious hacker to anticipate and defend one’s organization against cyber security risks.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Experience implementing multi-factor authentication, single sign-on, identity management or related technologies</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">People Management Skills: Ability to lead and work well with the team, internal, and external clients. Have good teamwork and collaboration skills: good team player with the ability to lead security initiatives, explain and enforce security measures.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Good Project management skills: to lead and manage accomplishments of assigned tasks/risk assessment activities.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Possess excellent time management skills, thrive in a fast paced demanding environment</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Be a self-managed, self-starter with good organizational skills </span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Be able to work under pressure on multiple assessments/projects simultaneously</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Good written and verbal communication skills: to effectively articulate and explain complex security topics in simple language, concise and easy to understand concepts.</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Conflict and Problem management Skills</span></li> <li style="text-align:justify;margin:0.0in 0.0in 1.0E-4pt 0.0px"><span style="">Knowledge in using MS office tools such as PowerPoint, word, excel and project </span></li> </ul> <p style="margin:0.0in -22.5pt 1.0E-4pt 0.0in;text-align:justify;Times New Roman', serif"> </p>