Job Details
About BNP Paribas Group: BNPParibas is a top-ranking bank in Europe with an international profile It operates in 71 countries and has almost 199000 employees The Group ranks highly in its three core areas of activity: Domestic Markets and International Financial Services (whose retail banking networks and financial services are grouped together under Retail Banking & Services) and Corporate & Institutional Banking, centered on corporate and institutional clients The Group helps all of its clients (retail, associations, businesses, SMEs, large corporate and institutional) to implement their projects by providing them with services in financing, investment, savings and protection In its Corporate & Institutional Banking and International Financial Services activities, BNPParibas enjoys leading positions in Europe, a strong presence in the Americas and has a solid and fast-growing network in the Asia/Pacific region.
About BNP Paribas India Solutions: Established in 2005, BNP Paribas India Solutions is a wholly owned subsidiary of BNP Paribas SA, a leading bank in Europe with an international reach With delivery centers located in Bengaluru, Chennai and Mumbai, we are a 24x7 global delivery center India Solutions services three business lines: Corporate and Institutional Banking, Investment Solutions and Retail Banking for BNP Paribas across the Group Driving innovation and growth, we are harnessing the potential of over 6000 employees, to provide support and develop best-in-class solutions About Business line/Function : Information Security and BCM Information security and BCM team are responsible to perform the security assessment of all new/existing infrastructure and application projects.
Also, responsible to assess business continuity requirement of each team and project based on the criticality and streamline the process to achieve the requirement Job Title: Shadow light IT reviewer Date: 8th April 2022 Department: Information Security Location: Mumbai Business Line / Function: APAC Security Risk Management Reports to NA Grade: (if applicable) Number of Direct Reports: 1 Directorship / Registration: NA Position PurposeShadow/Light IT Security Reviewer positions to help apply technical and procedural security controls on End User Developed software used in Singapore and Hong Kong Shadow IT refers to applications that are unknown/ uncontrolled end user applications Light IT refers to known/ controlled end user applicationsResponsibilities Direct ResponsibilitiesPrimary responsibility to inventory the Singapore and Hong Kong end user developed software that are critical for bank employees to perform their role, perform a security risk assessment on the applications, and develop and track plans to converge the applications into approved and Controlled enterprise applications Contributing ResponsibilitiesWork closely with asset owners or representatives and technical staff to communicate, drive and track the application security assessment and document resultant findings in a standardized format Technical & Behavioral Competencies.
Knowledgeable with common end user applications Office and associated macros, Javascript, CSharp, VB Scripts, Net, etc Extended knowledge of IT Security Risk Management concepts and with good understanding of industry APAC regulations ie.
MAS TRM, HKMA At least 2 years of direct IT Security Risk Assessment experience with a strong background in End User Application Risk Assessment, software development and SDLC, Must be able to handle stakeholders in a confident, positive and responsive manner Good communication, technical writing skills.
Must be motivated, and able to work independently as well as part of a team Must demonstrate ethical responsibility, maturity, and discretio Knowledgeable with IT infrastructure, network and/or application security.
Proficient in Fintech, Cloud, Mobile, Virtualization, and Sandbox technologies, agile development methodology, and Infrastructure & network (Internet, Intranet, Extranet, DMZ), and Application (Web, Client-Server, payment systems) security reviews Extended knowledge of IT Security Risk Management concepts and with good understanding of industry APAC regulations ie MAS TRM, HKMA, FSA, etc