Senior Officer — Cyber / Technical Security
National Payment and Innovation Company of Trinidad and Tobago
Job description
Job Purpose The Senior Officer — Cyber / Technical Security is responsible for the design, implementation, operation and continuous assurance of the technical security controls that protect NPICTT’s national payments infrastructure and corporate estate. The Company operates systems of national significance: the Centralized Management Payment Platform and Gov.
PayTT, through which citizens transact with the State; the national real-time payment scheme and its switch; and the cryptographic infrastructure on which those transactions depend. A material security failure would carry consequences for citizens, for the Government’s revenue, and for the public confidence in the national payments system.
The position exists to ensure that does not happen, and to be able to demonstrate to regulators, assessors and auditors that it will not. The incumbent is expected to combine hands-on technical capability with the discipline of a control environment: controls that are designed, operated, evidenced and tested, rather than assumed.
Key Responsibilities
Security architecture and engineering
- Conduct security design review of all new and materially changed services, platforms and integrations before they are approved for build, and record the outcome.
- Define and maintain network segmentation, including the separation of cardholder data environment, switch environment, corporate and development networks.
- Own the technical configuration and rule-base governance of the perimeter and internal security estate, including the high-availability firewall pair, intrusion prevention, web application fire-walling and secure remote access.
- Harden identity: conditional access, multi-factor authentication, privileged access management, service account governance and joiner-mover-leaver enforcement across the Microsoft Entra ID estate.
- Define encryption standards for data in transit and at rest, and manage the certificate estate and its lifecycle. Cryptographic and key management
- Operate and assure key management for the payments estate, including hardware security modules supporting the national switch.
- Plan and execute key ceremonies under dual control and split knowledge, maintain custodian registers and ceremony records, and administer key rotation and compromise procedures.
- Maintain the cryptographic inventory and ensure algorithms and key strengths remain compliant with scheme, PCI and Central Bank expectations. Compliance and assurance
- Own the Company’s technical compliance posture against the PCI Data Security Standard, including scope definition and minimization, evidence collection, self-assessment questionnaires and, where applicable, Report on Compliance support.
- Coordinate approved scanning vendor scans, annual penetration testing and segmentation testing; triage findings; track remediation to closure; maintain a risk-accepted exception register with expiry dates.
- Maintain an information security control set aligned to ISO/IEC 27001 and support the Company’s obligations under the Financial Institutions Act and the requirements of the Central Bank of Trinidad and Tobago in respect of payment system operation.
- Prepare security assurance evidence for partners, participant banks and scheme partners, and respond to their security questionnaires and audits. Vulnerability and configuration management
- Operate a scheduled vulnerability scanning and configuration assessment regime across servers, endpoints, network devices, cloud workloads and applications.
- Risk-rate findings, set and enforce remediation service levels with Infrastructure Support and Product Development, and report on the vulnerability position.
- Maintain secure baseline configurations and monitor for drift. Monitoring, detection and incident response
- Design and operate the security logging and monitoring capability, ensuring that security-relevant events across the estate are collected, retained and correlated.
- Triage alerts, investigate suspected incidents, and lead technical containment, eradication and recovery.
- Maintain and periodically exercise the security incident response plan and playbooks, including scenarios for compromise of the payment channel, ransomware, credential compromise and insider misuse.
- Preserve evidence to a forensically sound standard and support any subsequent investigation.
- Advise on notification obligations, including to the Central Bank, scheme partners, affected individuals and the relevant national authorities, in accordance with the general privacy principles of the Data Protection Act.
- Participate in an on-call rota for security incidents. Third-party and supply chain security
- Conduct security due diligence on vendors, integration partners, acquirers and service providers prior to engagement, and periodically thereafter.
- Specify security schedules, control requirements and audit rights for inclusion in contracts, in conjunction with Procurement and Legal.
- Collect and review third-party attestations and remediate identified gaps. Policy, awareness and culture
- Maintain the Company’s information security policy, standards and technical procedures, and keep them current.
- Deliver security awareness training and phishing simulation, and report on outcomes.
- Provide security input to the Company’s risk register and prepare security risk reporting for management and the Board in language a non-technical reader can act on. Key Relationships Internal
- Technology Operations; Product Development; Payments Operations; Legal and Corporate Secretarial; Procurement; Risk and Compliance.
- The Chief Executive Officer and the Board, through the reporting line, on material security risk and incidents. External
- Central Bank of Trinidad and Tobago; qualified security assessors and approved scanning vendors; penetration testing providers.
- NPCI International Payments Limited and participant banks on scheme and interface security.
- National cyber security authorities and computer incident response bodies; technology vendors and managed service providers.
Requirements
Minimum Qualifications and Experience
- A Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering or a related discipline from a recognized institution.
- A minimum of five (5) years’ experience in information technology, of which at least three (3) years in a dedicated information or cyber security role.
- Experience in financial services, payments, banking or another regulated environment is strongly preferred.
- Demonstrable hands-on experience of security operations: firewall and network security administration, vulnerability management, endpoint protection, and incident investigation.
- One or more professional certifications, or a commitment to attain one within an agreed period: CISSP, CISM, CompTIA Security+ or CySA+, GIAC certifications, OSCP, CEH, CCSP, or PCI Professional / Internal Security Assessor credentials.
- Exposure to PCI DSS compliance and to cryptographic key management is a significant advantage.