Deputy Manager IT Risk Specialist
Merchant Bank of Sri Lanka & Finance PLC (MBSL)
- Salary
- Not disclosed
- Job type
- Full-time
- Work type
- On-site
- Experience
- Executive
Colombo 3·Posted Sep 9, 2026
Job title: IT Risk Specialist - (Deputy Manager | Assistant Manager Grade)
Company: Merchant Bank of Sri Lanka & Finance PLC (MBSL)
Merchant Bank of Sri Lanka & Finance PLC (MBSL), a subsidiary of the Bank of Ceylon, is a leading financial institution committed to delivering innovative financial solutions while upholding the highest standards of corporate governance and regulatory compliance. We are seeking a highly motivated and experienced Information Security Risk Specialist to strengthen our Information Security and Risk Management function. The successful candidate will play a key role in safeguarding organisational information assets, managing security risks, ensuring regulatory compliance, and supporting business continuity initiatives.
Qualifications & Experience:
- Bachelor's Degree in Information Technology, Computer Science, Information Security, Cyber Security, or a related discipline from a recognized university.
- Minimum 3-5 years' experience in Information Security, IT Risk Management, Cyber Security, IT Governance, IT Audit, or a related field.
- Experience in the relevant professional standards will be an added advantage.
- Hands-on experience in ISMS implementation, IT risk assessments, security monitoring, compliance reviews, and Business Continuity Management (BCM).
- Strong analytical, problem-solving, report-writing, and presentation skills, with the ability to recommend practical risk mitigation measures.
- Advanced proficiency in MS Excel, including data analysis and reporting.
Key Responsibilities:
- Manage and monitor Information Security risks across the organization.
- Oversee Privileged Access Management (PAM) and Risk Assessment & Risk Treatment (RART) processes.
- Conduct security risk assessments and recommend mitigation strategies to address identified vulnerabilities.
- Support the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS).
- Review the confidentiality, integrity, and availability of information assets and IT infrastructure.
- Support Business Continuity Planning (BCP) initiatives and monitor key security controls, including Active Directory, encryption, and information classification.
- Monitor physical access controls, biometric authentication systems, and environmental security measures.
- Review security incidents, logs, and events, and recommend corrective actions and control improvements.
- Review IT and Information Security policies, procedures, and standards to ensure compliance and effectiveness.
Deadline: 23rd September 2026