
Information Security Specialist
- Hybrid
- Birkirkara, Birkirkara, Malta
- Moneybase
Job description
Calamatta Cuschieri Moneybase is a unified established brand, expanding across payments, global investing, wealth management, and business banking, and changing how people invests and manages money. Social and digital are where much of that story gets told.
This role has been created as part of the continued evolution of the organisation's Information Security capability and reflects its ongoing investment in strengthening and maturing its security function.
The Information Security Specialist is responsible for supporting the organisation's Information Security Programme through the implementation, operation, and continuous improvement of technical and administrative security controls. The role is responsible for monitoring the organisation's security posture, managing vulnerabilities, supporting security operations, implementing security controls, coordinating compliance activities, and providing technical security guidance across the organisation.
The role works closely with IT, project teams, business stakeholders, and third party suppliers to ensure that information assets are protected, cyber risks are effectively managed, and regulatory and industry security requirements are met.
Security Operations
Monitor, analyse, and investigate security events and alerts to identify, triage, and respond to potential security incidents.
Support incident response activities, including investigation, containment, recovery, and post incident reviews.
Identify emerging threats and recommend improvements to security monitoring and detection capabilities.
Information Security Improvement
Support the continuous improvement of the organisation's information security framework, policies, standards, procedures, and technical controls.
Assist in implementing security initiatives that strengthen the organisation's overall security posture.
Security Architecture and Technical Advisory
Provide security guidance for infrastructure, cloud, application, and technology projects.
Review technical solutions to ensure compliance with security standards, regulatory requirements, and security by design principles.
Vulnerability and Patch Management
Coordinate vulnerability assessments, penetration testing, remediation activities, and validation of identified security weaknesses.
Coordinate the deployment of security patches with Infrastructure and Application teams and, where appropriate, deploy security updates for security platforms and appliances.
Monitor vulnerability and patch compliance, reporting on remediation progress and escalating overdue actions.
Identity and Access Governance
Maintain the organisation's Access Control Matrix and coordinate periodic user and privileged access reviews.
Support segregation of duties assessments and promote least privilege across business applications and technology platforms.
Compliance and Risk Management
Support compliance with regulatory, contractual, and organisational security requirements.
Perform technical security assessments, identify control gaps, recommend remediation actions, and assist with internal and external audits.
Business Continuity and Incident Preparedness
Support Business Continuity, Disaster Recovery, and cyber incident response activities, including participation in recovery exercises and tabletop simulations.
Reporting and Stakeholder Engagement
Produce security reports, dashboards, and metrics covering incidents, vulnerabilities, patch compliance, penetration testing, audit findings, and remediation activities.
Communicate security risks and recommendations to stakeholders, maintain security documentation, and collaborate with internal teams and third party suppliers to improve the organisation's security posture.
Job requirements
Degree in Information Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience.
Experience in an Information Security, Cyber Security, Infrastructure, or Systems Administration role.
Experience with enterprise security technologies, including SIEM, EDR, vulnerability management, identity and access management, cloud security, and patch management.
Experience coordinating vulnerability assessments, penetration testing, remediation activities, and security improvement initiatives.
Experience managing user access governance, including Access Control Matrices and periodic access reviews.
Good understanding of security monitoring, incident response, technical risk management, networking, operating systems, cloud technologies, authentication, encryption, and secure system design principles.
Experience supporting internal and external security audits.
Strong analytical, problem solving, communication, and documentation skills.
Relevant professional security certification or equivalent industry experience.
Highly Desirable
Microsoft Azure and Microsoft 365 security experience.
Microsoft cloud security certifications (for example Azure Security, Security Operations, Identity and Access, or Cybersecurity certifications).
Experience working within financial services or other regulated environments.
Experience supporting compliance with PCI DSS, SWIFT Customer Security Programme (CSP), and the Digital Operational Resilience Act (DORA).
Experience implementing Zero Trust, Conditional Access, Privileged Identity Management, and cloud security controls.
Knowledge of recognised security frameworks and industry best practices.
Our Values:
🚀Innovation – Stay Curious, Move Fast
🔒Integrity – Do What’s Right, Always
🎯Accountability – Own It, Fix It, Learn
🤝Collaboration – Win Together
🌍Respect – Value Every Voice
Remuneration
We are committed to attracting and selecting top people to join our team. We are also committed to creating a workplace that encourages individual growth; we value our people and their well-being.
What we offer:
Ongoing internal training
Study Leave
Sponsorship schemes for further studies
Opportunities for career growth
Variable bonus linked to KPI
Visit our home page to see more about our company CC Moneybase Careers
All applications will be acknowledged and treated with maximum confidentiality
Reference: CCMT02627
or
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.
