The successful candidate will be expected to perform the following duties and responsibilities:
Cybersecurity Operations
- Develop, implement and continuously improve the BMA’s cybersecurity operations capability to protect information assets, systems, networks, cloud platforms and digital services against cyber threats.
- Administer, monitor and optimise operational cybersecurity technologies, including endpoint security, email security, network security, cloud security and related technical symbols.
- Implement and maintain security configuration baselines, technical hardening standards and secure configuration requirements across ICT infrastructure, operating systems, cloud platforms and business applications.
- Review cybersecurity configurations for new systems, infrastructure changes and technology implementations to ensure alignment with approved security standards and organisational requirements.
- Develop and maintain cybersecurity operational procedures, technical standards, implementation guides and supporting documentation.
- Provide specialist cybersecurity guidance to ICT teams, business units and project teams on operational security risks, controls and mitigation measures.
- Coordinate vulnerability remediation with ICT infrastructure, application and service owners to ensure identified weaknesses are addressed within agreed risk-based timeframes.
- Review security logs, alerts and configuration reports from operational cybersecurity tools to identify control failures, misconfigurations and areas requiring corrective action.
- Support patch management and secure maintenance activities by validating that critical systems, endpoints and security technologies are updated in line with approved security requirements.
Identity and Access Security
- Develop, implement and continuously improve the organisation’s Identity and Access Management capability to ensure secure, appropriate and auditable access to systems, applications and ICT resources.
- Design, implement and maintain identity and access security controls, including authentication, authorisation, multi-factor authentication, role-based access control, privileged access management and adaptive access controls.
- Implement and maintain Identity Governance and Administration processes for the provisioning, modification, recertification and de-provisioning of user, privileged, service and third-party accounts.
- Administer enterprise identity services, directory services, authentication mechanisms and access control technologies in line with approved security standards.
- Monitor identity-related security events, authentication risks and anomalous access activities, and initiate appropriate technical responses where required.
- Provide specialist advice on identity architecture, authentication mechanisms and access control requirements for new ICT solutions, projects and technology implementations.
- Maintain technical documentation, operational procedures and standards relating to identity and access security technologies.
Threat Detection, Incident Response and Cyber Resilience
- Develop, implement and continuously improve the organisation’s cybersecurity monitoring and incident response capability to enable timely detection, analysis, containment, eradication and recovery from cybersecurity threats and incidents.
- Monitor the organisation’s ICT environment for cybersecurity threats, malicious activity and indicators of compromise using approved security monitoring technologies and threat intelligence sources.
- Coordinate and manage cybersecurity incidents throughout the incident lifecycle, ensuring incidents are classified, prioritised, investigated, contained, resolved, documented and formally closed.
- Conduct technical investigations into cybersecurity incidents, analyse root causes and recommend corrective and preventive actions to minimise recurrence.
- Coordinate or support digital forensic investigations and ensure digital evidence is preserved, collected and handled in accordance with approved procedures and legal requirements.
- Develop, maintain and periodically review the Cybersecurity Incident Response Plan, incident response playbooks, escalation procedures and communication protocols.
- Coordinate and participate in cybersecurity incident simulations, tabletop exercises and cyber resilience testing to validate organisational preparedness.
- Support cyber recovery and ICT disaster recovery planning, testing and improvement in collaboration with ICT infrastructure, business continuity and disaster recovery stakeholders.
- Develop operational dashboards and management reports on cybersecurity incidents, threat trends, response performance and organisational cyber resilience.
Cybersecurity Programme Delivery
- Develop, implement, coordinate and monitor cybersecurity projects and initiatives that support the organisation’s cybersecurity strategy, ICT strategic objectives and digital transformation programme.
- Provide specialist cybersecurity input into ICT projects, solution designs, technology acquisitions and procurement activities to ensure security requirements are embedded throughout the project lifecycle.
- Develop cybersecurity technical specifications, standards and security requirements for ICT infrastructure, cloud services, applications, software, hardware and managed security services.
- Evaluate cybersecurity technologies and solutions and provide recommendations on suitability, technical capability, security effectiveness, integration requirements and alignment with organisational needs.
- Support cybersecurity procurement processes by reviewing technical proposals, validating compliance with security requirements and contributing to bid evaluation activities where required.
- Manage cybersecurity vendors, managed security service providers and technology partners to ensure contracted services are delivered in accordance with agreed service levels, contractual obligations and organisational expectations.
- Track cybersecurity programme risks, issues, dependencies, milestones and deliverables, and escalate matters requiring management intervention.
- Develop, monitor and report cybersecurity Key Risk Indicators, Key Performance Indicators and operational metrics to provide management with insight into cybersecurity posture, service performance and emerging risks.
Stakeholder Management
- Build and maintain effective working relationships with internal business units, ICT teams, governance structures, service providers and relevant external stakeholders to support the delivery of cybersecurity services and initiatives.
- Provide specialist cybersecurity advice, technical guidance and recommendations to management, ICT teams, project teams and business stakeholders on cybersecurity risks, controls and mitigation measures.
- Coordinate cybersecurity-related inputs, updates and follow-ups with stakeholders to support incident response, access security, operational control improvements and cybersecurity programme delivery.
- Promote cybersecurity awareness, responsible technology use and a strong security culture through collaboration, communication and engagement with relevant stakeholders.