Job Description
IT RISK SPECIALIST
Deputy Manager/ Assistant Manager Grade
Merchant Bank of Sri Lanka & Finance PLC (MBSL), a subsidiary of the Bank of Ceylon, is a leading financial institution committed to delivering innovative financial solutions while upholding the highest standards of corporate governance and regulatory compliance. We are seeking a highly motivated and experienced Information Security Risk Specialist to strengthen our Information Security and Risk Management function. The successful candidate will play a key role in safeguarding organisational information assets, managing security risks, ensuring regulatory compliance, and supporting business continuity initiatives.
Qualifications & Experience:
- Bachelor's Degree in Information Technology, Computer Science, Information Security, Cyber Security, or a related discipline from a recognized university.
- Minimum 3–5 years' experience in Information Security, IT Risk Management, Cyber Security, IT Governance, IT Audit, or a related field.
- Experience in the relevant professional standards will be an added advantage.
- Hands-on experience in ISMS implementation, IT risk assessments, security monitoring, compliance reviews, and Business Continuity Management (BCM).
- Strong analytical, problem-solving, report-writing, and presentation skills, with the ability to recommend practical risk mitigation measures.
- Advanced proficiency in MS Excel, including data analysis and reporting.
Key Responsibilities:
- Manage and monitor Information Security risks across the organization.
- Oversee Privileged Access Management (PAM) and Risk Assessment & Risk Treatment (RART) processes.
- Conduct security risk assessments and recommend mitigation strategies to address identified vulnerabilities.
- Support the implementation, maintenance, and continuous improvement of the Information Security Management System (ISMS).
- Review the confidentiality, integrity, and availability of information assets and IT infrastructure.
- Support Business Continuity Planning (BCP) initiatives and monitor key security controls, including Active Directory, encryption, and information classification.
- Monitor security incidents, logs, and events, and recommend corrective actions and control improvements.
- Review IT and Information Security policies, procedures, and standards to ensure compliance and effectiveness.
Apply Now
[email protected]
Apply online: Scan the QR code or visit the link below. Click Here to Apply
Deadline: 23rd September 2026