Title: Associate Manager, Information & Communication Technology Audit, ICC
Company Name: BRAC Bank PLC
Vacancy: --
Age: At least 20 years
Job Location: Dhaka
Salary: Negotiable
Experience:
• Master’s or bachelor’s degree in computer science, IT or a related field from a reputed university.
• At least four to five years of relevant experience.
• Relevant professional certifications from ISACA, ISC2, IIA or EC-Council, or certifications such as RHCE, CEH and ITIL.
• Experience in IT and banking IT systems.
• Knowledge of risk management and business continuity.
• Up-to-date knowledge of IT security and vulnerability-management practices.
• Sound knowledge of Agile and DevSecOps processes.
• Customer-centric, a team player and keen to develop others.
BRAC Bank PLC is building the future of banking in Bangladesh through trust, innovation, and inclusion. As a values-based financial institution, the bank empowers customers and businesses with responsible financial solutions while upholding the highest standards of compliance, governance and transparency. For professionals, BRAC Bank offers a platform where performance, integrity, and innovation thrive together.
The bank is seeking a qualified and purpose-driven professional for the following position within its Internal Control and Compliance Division:
Associate Manager, Information & Communication Technology Audit, ICC
Job Grade: SO/PO
KEY RESPONSIBILITIES:
Perform end-to-end audits in Information Technology, Information Security and Cloud Security, covering initiation and risk assessment, planning, work programme development, execution and reporting.
Identify potential risks in AD, DC, DNS, hypervisors, virtualisation platforms, container-based technologies and databases.
Write and execute SQL queries independently against production databases, including Oracle, SQL Server, MySQL and PostgreSQL.
Identify potential risks related to data security, IT processes, and compliance with regulatory requirements and industry standards.
Plan and design audit procedures and strategies based on the organisation's specific needs and objectives.
Conduct audits of IT systems, applications, and processes to assess their effectiveness, security, and compliance.
Maintain detailed records of audit findings, including vulnerabilities, weaknesses, and recommendations.
Ensure that the organisation’s IT practices adhere to relevant laws, regulations and industry standards, including Bangladesh Bank’s ICT and Cloud Security Guidelines, ISO 27001 and PCI DSS.
Provide recommendations and action plans to address identified vulnerabilities and improve IT security and efficiency.
Communicate audit findings and recommendations to relevant stakeholders, including management and IT teams.
Stay updated on emerging threats, technologies and industry best practices to continually enhance the organisation’s cybersecurity posture.
Stay updated on banking practices, Bangladesh Bank guidelines and circulars, auditing standards, and changes and amendments to applicable laws and regulations.
Adequately analyse, assess and evaluate risks associated with IT and information security systems and applications.
Conduct data analysis using appropriate Computer-Assisted Audit Techniques (CAATs).