Sobre este puesto de Cybersecurity Manager en Manulife
Manulife is a leading international financial services provider, helping people make decisions easier and lives better. Help shape the future you want to see — and discover that better can take you anywhere you want to go.
The Opportunity
We are looking for Information Technology (IT) Security Manager who will be directly reporting to Asia Regional Office Security Officer under the Regional Business Unit Security Office of Asia Cybersecurity & Information Security Office (CISO) function at Manulife Financial Corporation (MFC). The IT Security Manager will serve as Information Security Officer of BUSO Center of Excellence (BUSO CoE) team.
The BUSO CoE sits within the Asia Cybersecurity & Information Security Office function. Its main mission is to support the market Business Unit Security Officer (BUSO) on specialized tasks. The BUSO CoE team works hand in hand with the regional team and the BUSOs in supporting the execution of the technology controls program. Including BAU, process improvement and project related work. In particular, this includes analyzing high risk service request tickets, reviewing alerts, supporting and conducting information security risk assessments and executing, automating and operationalizing core security processes.
The function sits within Manulife’s line 1b of defense – where we align with leadership to set the risk culture, support IT in identifying and mitigating risks at scale, and provide a common view and narrative of key risks to enable business discussions.
The BUSO CoE helps line 1b business units to ensure uninterrupted BAU on a day-to-day basis by effectively managing their information and operational risks. To achieve this, we need to ensure success in maintaining internal controls and liaison with Manulife’s line 2b of defense that owns Manulife control policies and standards.
What motivates you?
You obsess about customers, listen, engage, and act for their benefit
You think big, with curiosity to discover ways to use your agile mindset and enable business outcomes
You thrive in teams, and enjoy getting things done together
You take ownership and build solutions, focusing on what matters
You do what is right, work with integrity and speak up
You share your humanity, helping us build a diverse and inclusive work environment for everyone
We are looking for someone with:
University/College graduate with 3 – 5 years of progressive experience related to Information Security Management and 3+ years as an Information Security Officer.
Solid background in Information Security Management, Information Security Risk Assessment (both in project and BAU), Security Incident Handling, Access Review, Data Loss Prevention Management and other security processes like incident/crisis management, access management, vulnerability and patch management, as well as operational processes for business continuity and disaster recovery.
Profound knowledge and understanding of Manulife’s Information Risk Management Framework (Risk Identification and Assessment, Risk Treatment, Risk Monitoring, Sustain and Independent Review), CIA Triad (Confidentiality, Integrity and Availability), Zero-Trust Tolerance.
Expert in the following technologies: BlueCat Address Manager, JIRA, ServiceNow, Devo, PowerBI, Process Unity, Confluence, Archer.
Knowledge of latest technology development and financial services / insurance business.
Self-driven, able to meet objectives with a minimal amount of managerial oversight/supervision.
Can distill complex issues into simple reports, solutions, and designs.
A team player who can interact with other control functions on project delivery
Advocate constant learning from both success and failure, and encourages openness to change and continuous improvement
Excellent organizational and problem-solving abilities that enable you to manage through creative abrasion
Proficient in verbal and written communication with the ability to effectively articulate and communicate technical vision, possibilities, and outcomes
On the job you will:
Conduct operational tasks that could be centralized (or outsourced) from market BUSOs;
Work with relevant stakeholders and market BUSO to develop standardized approach on processing tasks which aims to operationalize and streamline processes such that CoE team could handle those effectively and consistently;
Set up general governance for each task (e.g., reporting structure, onboarding/ offboarding toolkit) and engage market BUSO for follow-up / escalation when required
Perform knowledge transfer /sharing to new members of the team and/or other IT control and governance team members;
Coordinate with market BUSOs for regular status update;
Support operational information risk activities and other operational processes.
Support security program activities in segment level like performing/facilitating application security assessments and providing application security consulting services to IT and other relevant partners and clients.
Support security program activities in segment level like performing/facilitating application security assessments and providing application security consulting services to IT and other relevant partners and clients
Promote the information risk assessment program across Asia Markets.
- Assist the set-up of the framework for the execution of project risk assessment from a technical security and information risk management perspective (includes risk identification based on information criticality through to control implementation and management of risk acceptance by business areas). This involves establishing playbooks, training programs, quality assurance plans, standardized reporting, and mechanisms to share best practices
- Perform and review Project Information Risk Assessments, provide guidance on risks mitigation strategies and ensure prompt execution of remediation actions; Assist with preparing and maintaining the schedule of risk mitigation action plans and commitments.
- Perform review of project risk assessments completed by assessors from Asian countries to promote consistent risk assessment methodologies
Support in the end-to-end management and timely resolution of security incidents, particularly on Data Loss Prevention (DLP) related incidents.
**People Leader Role: No
Our commitment to you:
Our mission: to be a part of making Decisions Easier and Lives Better
A leadership team dedicated to your growth and success
A bold ambition and set of goals to be a leader in driving transformation in our industry
Our best. Every day.
Learn more about opportunities with us at jobs.manulife.com
** This job description does not represent a comprehensive listing of job duties that are required of the employee performing this role. We reserve the right to change duties or assign additional duties at any time with or without notice.
About Manulife and John Hancock
Manulife Financial Corporation is a leading international financial services provider, helping people make their decisions easier and lives better. To learn more about us, visit https://www.manulife.com/en/about/our-story.html.
Manulife is an Equal Opportunity Employer
At Manulife/John Hancock, we embrace our diversity. We strive to attract, develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related conditions), sexual orientation, genetic characteristics, veteran status, gender identity, gender expression, age, marital status, family status, disability, or any other ground protected by applicable law.
It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process, contact [email protected].
Working Arrangement