Jobiglo

No results.

IT Application and Security Manager

Canadia Bank · Phnom-Penh

Senior 🇬🇧 English
Burp Suite OWASP ZAP Nmap Application security testing Penetration testing Vulnerability management DevSecOps Secure SDLC PCI DSS ISO 27001 NIST NBC TCRMG

Job description

About the role

The IT Application and Security Manager will lead the bank’s application security program, ensuring that all software assets are protected against threats and comply with regulatory standards. Reporting to the Head of IT Security, the role combines strategic planning, hands‑on penetration testing, and team leadership to safeguard the organization’s information systems.

Key responsibilities

  • Develop and implement the bank’s application security strategy, framework and roadmap aligned with business and regulatory requirements.
  • Lead the Application Security team in delivering security assessments, penetration testing, and vulnerability management for web, mobile, API and cloud applications.
  • Establish and maintain security standards, policies, procedures and secure development practices, and provide guidance throughout the SDLC.
  • Review and approve security assessment reports, risk ratings and remediation plans before management reporting.
  • Collaborate with business and IT stakeholders to embed security requirements into projects and system implementations.
  • Monitor compliance with regulations such as NBC TCRMG, PCI DSS, OWASP, ISO 27001 and NIST.
  • Manage security vendors and oversee external security assessments and penetration testing engagements.
  • Prepare security metrics, management reports and executive presentations, and support audits and regulatory examinations.
  • Mentor and develop team members while promoting continuous improvement and security awareness.

Required profile

  • Bachelor’s degree in Information Security, Computer Science, IT or a related field.
  • Minimum 5 years of information security experience, including at least 2 years in a leadership role.
  • Strong knowledge of application security, secure SDLC, DevSecOps, penetration testing and vulnerability management.
  • Familiarity with regulatory frameworks such as OWASP, PCI DSS, ISO 27001, NIST and NBC TCRMG.
  • Relevant certifications (e.g., CISSP, OSCP, GWAPT, GPEN, CEH) are preferred.

Required skills

  • Burp Suite
  • OWASP ZAP
  • Nmap
  • Application security testing
  • Penetration testing
  • Vulnerability management
  • DevSecOps
  • Secure SDLC
  • OWASP standards
  • PCI DSS
  • ISO 27001
  • NIST
  • NBC TCRMG

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec Canadia Bank.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 1 month ago

Expires 2 weeks from now

26 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

Canadia Bank

Phnom-Penh