IT Application and Security Manager
Canadia Bank · Phnom-Penh
Job description
About the role
The IT Application and Security Manager will lead the bank’s application security program, ensuring that all software assets are protected against threats and comply with regulatory standards. Reporting to the Head of IT Security, the role combines strategic planning, hands‑on penetration testing, and team leadership to safeguard the organization’s information systems.
Key responsibilities
- Develop and implement the bank’s application security strategy, framework and roadmap aligned with business and regulatory requirements.
- Lead the Application Security team in delivering security assessments, penetration testing, and vulnerability management for web, mobile, API and cloud applications.
- Establish and maintain security standards, policies, procedures and secure development practices, and provide guidance throughout the SDLC.
- Review and approve security assessment reports, risk ratings and remediation plans before management reporting.
- Collaborate with business and IT stakeholders to embed security requirements into projects and system implementations.
- Monitor compliance with regulations such as NBC TCRMG, PCI DSS, OWASP, ISO 27001 and NIST.
- Manage security vendors and oversee external security assessments and penetration testing engagements.
- Prepare security metrics, management reports and executive presentations, and support audits and regulatory examinations.
- Mentor and develop team members while promoting continuous improvement and security awareness.
Required profile
- Bachelor’s degree in Information Security, Computer Science, IT or a related field.
- Minimum 5 years of information security experience, including at least 2 years in a leadership role.
- Strong knowledge of application security, secure SDLC, DevSecOps, penetration testing and vulnerability management.
- Familiarity with regulatory frameworks such as OWASP, PCI DSS, ISO 27001, NIST and NBC TCRMG.
- Relevant certifications (e.g., CISSP, OSCP, GWAPT, GPEN, CEH) are preferred.
Required skills
- Burp Suite
- OWASP ZAP
- Nmap
- Application security testing
- Penetration testing
- Vulnerability management
- DevSecOps
- Secure SDLC
- OWASP standards
- PCI DSS
- ISO 27001
- NIST
- NBC TCRMG
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Cambodia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 2 weeks from now
26 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Canadia Bank
Phnom-Penh
Related job offers
-
IT Audit Intern
KPMG Cambodia Phnom-Penh -
Customer Support Specialist
Jobify (Cambodia) Co., Ltd Phnom-Penh -
IT Business Partner – Cambodia & Laos, Supply Chain
Unilever Phnom-Penh -
Open Source GitHub Maintainer – Remote Contractor
RemoteWFAJobs | Emplois en télétravail et carrières à distance Preaek Hour -
Scientific Coding (Chemistry & Python) – $100/hr Remote Project
Expert Remote Jobs Preaek Hour