The IT Control Officer is responsible for monitoring, reviewing, and testing the Bank's information technology controls to ensure that IT systems, applications, infrastructure, and processes operate securely, effectively, and in accordance with approved policies, regulatory requirements, and industry best practices.
Job Description
Review and monitor user access to critical banking applications, systems, databases, servers, and administrative portals to ensure access is appropriately authorized, role-based, and aligned with the principle of least privilege.
Conduct periodic user access reviews and certification, including reviews of privileged/admin accounts, terminated or transferred staff access, maker-checker controls, and segregation-of-duties conflicts.
Review IT change management controls to ensure system, application, network, and infrastructure changes are properly initiated, authorized, tested, approved, implemented, and documented, including subsequent review of emergency changes.
Monitor IT operational controls and procedures, including EOD/EOM processing, batch jobs, scheduled activities, system interfaces, system downtime, incidents, and other critical operational activities to ensure appropriate approvals and evidence are maintained.
Assess and monitor cybersecurity controls covering endpoint security, firewalls, SIEM, encryption, vulnerability management, security monitoring, and other critical security tools, ensuring identified weaknesses are appropriately addressed.
Develop and execute IT control assessments and testing programs covering IT General Controls (ITGCs), applications, operating systems, databases, networks, data centers, access management, change management, backup and recovery, incident management, and system operations.
Review and test application controls across critical banking systems, including T24, NIP, Mobile Banking, and other integrated applications, to ensure the completeness, accuracy, validity, security, and integrity of data and transactions.
Identify, document, and report IT control deficiencies, risks, and compliance gaps, providing practical recommendations for improvement and monitoring agreed corrective actions through to closure.
Participate in IT-related fraud and incident investigations by reviewing system access, transaction trails, logs, user activities, system changes, and control weaknesses to support effective root-cause analysis and resolution.
Support the development and execution of the Annual IT Control/Audit Plan, ensuring key technology risks and emerging threats are appropriately assessed and covered, while contributing to the continuous improvement of the Bank's IT control framework and methodologies.