Skip to content

Information Security Specialist

  • Hybrid
    • Birkirkara, Birkirkara, Malta
  • Moneybase

Job description

Calamatta Cuschieri Moneybase is a unified established brand, expanding across payments, global investing, wealth management, and business banking, and changing how people invests and manages money. Social and digital are where much of that story gets told.

This role has been created as part of the continued evolution of the organisation's Information Security capability and reflects its ongoing investment in strengthening and maturing its security function.

The Information Security Specialist is responsible for supporting the organisation's Information Security Programme through the implementation, operation, and continuous improvement of technical and administrative security controls. The role is responsible for monitoring the organisation's security posture, managing vulnerabilities, supporting security operations, implementing security controls, coordinating compliance activities, and providing technical security guidance across the organisation.

The role works closely with IT, project teams, business stakeholders, and third party suppliers to ensure that information assets are protected, cyber risks are effectively managed, and regulatory and industry security requirements are met.

Security Operations 

  • Monitor, analyse, and investigate security events and alerts to identify, triage, and respond to potential security incidents.

  • Support incident response activities, including investigation, containment, recovery, and post incident reviews.

  • Identify emerging threats and recommend improvements to security monitoring and detection capabilities.

Information Security Improvement 

  • Support the continuous improvement of the organisation's information security framework, policies, standards, procedures, and technical controls.

  • Assist in implementing security initiatives that strengthen the organisation's overall security posture.

Security Architecture and Technical Advisory 

  • Provide security guidance for infrastructure, cloud, application, and technology projects.

  • Review technical solutions to ensure compliance with security standards, regulatory requirements, and security by design principles.

Vulnerability and Patch Management 

  • Coordinate vulnerability assessments, penetration testing, remediation activities, and validation of identified security weaknesses.

  • Coordinate the deployment of security patches with Infrastructure and Application teams and, where appropriate, deploy security updates for security platforms and appliances.

  • Monitor vulnerability and patch compliance, reporting on remediation progress and escalating overdue actions.

Identity and Access Governance 

  • Maintain the organisation's Access Control Matrix and coordinate periodic user and privileged access reviews.

  • Support segregation of duties assessments and promote least privilege across business applications and technology platforms.

Compliance and Risk Management 

  • Support compliance with regulatory, contractual, and organisational security requirements.

  • Perform technical security assessments, identify control gaps, recommend remediation actions, and assist with internal and external audits.

Business Continuity and Incident Preparedness 

  • Support Business Continuity, Disaster Recovery, and cyber incident response activities, including participation in recovery exercises and tabletop simulations.

Reporting and Stakeholder Engagement 

  • Produce security reports, dashboards, and metrics covering incidents, vulnerabilities, patch compliance, penetration testing, audit findings, and remediation activities.

  • Communicate security risks and recommendations to stakeholders, maintain security documentation, and collaborate with internal teams and third party suppliers to improve the organisation's security posture.

Job requirements

  • Degree in Information Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience.

  • Experience in an Information Security, Cyber Security, Infrastructure, or Systems Administration role.

  • Experience with enterprise security technologies, including SIEM, EDR, vulnerability management, identity and access management, cloud security, and patch management.

  • Experience coordinating vulnerability assessments, penetration testing, remediation activities, and security improvement initiatives.

  • Experience managing user access governance, including Access Control Matrices and periodic access reviews.

  • Good understanding of security monitoring, incident response, technical risk management, networking, operating systems, cloud technologies, authentication, encryption, and secure system design principles.

  • Experience supporting internal and external security audits.

  • Strong analytical, problem solving, communication, and documentation skills.

  • Relevant professional security certification or equivalent industry experience.

Highly Desirable 

  • Microsoft Azure and Microsoft 365 security experience.

  • Microsoft cloud security certifications (for example Azure Security, Security Operations, Identity and Access, or Cybersecurity certifications).

  • Experience working within financial services or other regulated environments.

  • Experience supporting compliance with PCI DSS, SWIFT Customer Security Programme (CSP), and the Digital Operational Resilience Act (DORA).

  • Experience implementing Zero Trust, Conditional Access, Privileged Identity Management, and cloud security controls.

  • Knowledge of recognised security frameworks and industry best practices.

Our Values:

🚀Innovation – Stay Curious, Move Fast 

🔒Integrity – Do What’s Right, Always 

🎯Accountability – Own It, Fix It, Learn 

🤝Collaboration – Win Together 

🌍Respect – Value Every Voice

Remuneration

We are committed to attracting and selecting top people to join our team. We are also committed to creating a workplace that encourages individual growth; we value our people and their well-being.

What we offer:

  • Ongoing internal training

  • Study Leave

  • Sponsorship schemes for further studies

  • Opportunities for career growth

  • Variable bonus linked to KPI

Visit our home page to see more about our company CC Moneybase Careers

All applications will be acknowledged and treated with maximum confidentiality

Reference: CCMT02627

or