Title: Senior Manager, Information & Communication Technology Audit, ICC
Company Name: BRAC Bank PLC
Vacancy: --
Age: At least 30 years
Job Location: Dhaka
Salary: --
Experience:
A master’s or bachelor’s degree in computer science, electronics, IT or a related field from a reputed university.
At least eight to ten years of relevant experience.
Relevant professional certifications from organisations such as ISACA, ISO, ISC2, Microsoft, RHCE, VMware and CKS, or equivalent certifications.
Experience in technology audits, preferably within banks.
Knowledge of risk management and business continuity.
Sound knowledge of Agile and DevSecOps processes.
Experience working with audit systems, such as SAP, Diligent and Archer.
Ability to adapt quickly to a dynamic and challenging environment.
Customer-centric, a team player and committed to developing others.
BRAC Bank PLC is building the future of banking in Bangladesh through trust, innovation, and inclusion. As a values-based financial institution, the bank empowers customers and businesses with responsible financial solutions while upholding the highest standards of compliance, governance and transparency. For professionals, BRAC Bank offers a platform where performance, integrity, and innovation thrive together.
The bank is seeking a qualified and purpose-driven professional for the following position within its Internal Control and Compliance Division:
Job Grade: AVP
Key Responsibilities:
Perform end-to-end audits in IT, Information Security, and Cloud Security .
Identify potential risks in AD, DC, DNS, hypervisors, virtualisation platforms, container-based technologies and databases.
Design and run data analytics scripts and queries for full-population testing.
Write and execute SQL queries independently against production databases, including Oracle, SQL Server, MySQL and PostgreSQL.
Review and perform manual and automated testing to identify functional and operational issues, inconsistencies and security vulnerabilities.
Identify potential risks related to data security, IT processes, and compliance with regulatory requirements and industry standards.
Plan and design audit procedures and strategies based on the organization`s specific needs and objectives.
Conduct audits of IT systems, applications, and processes to assess their effectiveness, security, and compliance.
Maintain detailed records of audit findings, including vulnerabilities, weaknesses, and recommendations.
Ensure that the organization`s Technology practices adhere to relevant laws, regulations, and industry standards (e.g., Bangladesh Bank Guidelines, ISO, PCI DSS, SWIFT, NIST).
Provide recommendations to address identified vulnerabilities and improve IT security and efficiency.
Stay updated on emerging threats, technologies, and industry best practices to enhance the organization`s cybersecurity posture continually.
Adequately analyse, assess and evaluate risks associated with IT and information security systems and applications.
Conduct data analysis using appropriate Computer-Assisted Audit Techniques (CAATs).