Kanthoruwa

Senior Deputy Manager, Information Security

National Development Bank PLC

Salary
Not disclosed
Job type
Full-time
Work type
On-site
Experience
Senior

Posted Sep 21, 2026

Senior Deputy Manager – Information Security

Company: National Development Bank PLC

Join our dynamic Information Security team and play a pivotal role in safeguarding the Bank's information assets and ensuring regulatory compliance. This position offers a unique opportunity to work closely with senior leadership; influence strategic decisions, and strengthens the Bank's cyber resilience.

The Job

  • Conduct 2nd Line of Defense activities by independently reviewing and challenging the effectiveness of cyber security controls, vulnerability management practices, incident management processes, and remediation activities, ensuring that identified risks are appropriately addressed, remediation actions are timely and effective, and the overall control environment remains effective
  • Actively participate in the Bank's Information Security Committee (ISC) and drive initiatives in line with regulatory expectations
  • Drive the implementation of ISO/IEC 27035 (Information Security Incident Management) and other relevant ISO standards, ensuring full alignment with CBSL Technology Risk Management Framework
  • Expand and maintain the Bank's Information Security Management System (ISMS) to meet evolving regulatory requirements and international standards. Support continuous improvement initiatives around ISO/IEC 27001 (ISMS), and ensure full integration into the Bank's operations meeting alignment with CBSL Technology Risk Management Framework
  • Develop, implement, and periodically review information Security policies and end-user guidelines (such as Acceptable Use Policies), ensuring alignment with regulatory, industry, and internal standards
  • Lead and coordinate user access reviews, enforce end point security controls such as email security and removable media controls, and monitor compliance across the organization
  • Maintain & improve data classification frameworks including Data classification Matrix and Data Loss Prevention (DLP) strategies
  • Develop and execute a comprehensive Information Security Awareness Program covering all employees, including Board members and senior management
  • Support business units and IT teams in policy interpretation, standards alignment, and ensure secure-by-design principles

The Person

  • A Bachelor's degree in Information Technology, Information Security, Computer Science, or a related discipline
  • Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, ISO 27035 Practitioner, or equivalent certifications are highly desirable
  • A minimum of 3 - 5 years of solid experience in Information Security with 5 - 7 years working exposure particularly in regulated industries such as banking and finance
  • Deep understanding of regulatory frameworks (CBSL, SEC, CSE) and compliance standards (e.g., PCI DSS, ISO standards)
  • Proven experience in ISMS implementation, security compliance audits, third-party risk management, and incident management frameworks
  • Strong leadership, communication, and stakeholder engagement skills with the ability to influence at all levels of the organization
  • Analytical mindset, with a proactive approach to identifying risks and recommending improvements

The position is at Senior Deputy Manager level.

Please login to https://www.ndbbank.com/careers to apply on or before 28th September 2026.