← Job search

HFC Bank

IT Assurance Officer

HFC BankSuva

IT & DigitalJob type not stated

Salary not disclosedPosted 1 day ago

Closes in 13 days

About the company

HFC Bank is a financial institution operating in Fiji's banking sector. It describes itself as a fast-paced, Equal Opportunity Employer that invests in its people and offers attractive benefits. The organisation positions itself as a challenging, creative environment with dedicated and energetic colleagues.

About the role

This IT Assurance Officer role sits within HFC Bank's Information Technology team at the head office in Suva, reporting to the Manager IT Assurance. The position is responsible for testing and evaluating IT controls against the Bank's IT and Information Security policies, and against standards such as PCI DSS, SWIFT, and ISO 27001. It involves conducting Key Control Effectiveness testing, supporting internal and external audits, and tracking audit findings to closure. The role also covers IT asset management, including inventory, stocktakes, and End-of-Life/End-of-Support tracking, as well as maintaining IT contracts, SLAs, licenses, and subscriptions. It carries responsibility for IT Risk, Incident Management, and Change Management registers, governance administration, and support for cybersecurity initiatives and technical audits of systems and infrastructure.

Key responsibilities

  • Testing, reviewing, and evaluating IT controls against the Bank's Information Technology and Information Security policies and procedures.
  • Assessing IT controls against applicable technology standards and regulatory requirements, including PCI DSS, SWIFT, and ISO 27001.
  • Conducting periodic Key Control Effectiveness (KCE) testing and preparing assurance and control testing reports.
  • Supporting the annual review and enhancement of IT policies, procedures, and governance frameworks.
  • Assisting with internal and external audits, regulatory reviews, and compliance attestations through collation, validation, and submission of audit evidence, and monitoring findings through to closure.
  • Ensuring IT assets are inventoried, tagged, and subjected to quarterly stocktakes, with timely reporting to Finance, and monitoring End-of-Life and End-of-Support lifecycle tracking.
  • Maintaining IT contracts, agreements, SLAs, licenses, and subscriptions, and supporting timely renewals.
  • Maintaining and reporting on IT Risk, Incident Management, and Change Management registers, and conducting technical audits of systems, databases, servers, network devices, and infrastructure against hardening standards.

About the successful candidate

  • A Degree in Computing Science, Information Systems, Information Technology, or Cybersecurity with a minimum of two years' experience in IT, Information Security, IT Audit, IT Risk, Compliance, or a related assurance function.
  • Alternatively, a Diploma in a related field with at least 3 years' experience in similar roles.
  • Experience in control testing, verification and validation, reporting, data quality management, risk assessment, incident management, and compliance monitoring.
  • Knowledge of cybersecurity principles, standards, and best practices is an added advantage.
  • Sound understanding of IT governance, risk management, information security controls, and regulatory compliance requirements.
  • Strong analytical, problem-solving, investigative, and report-writing skills.
  • Excellent attention to detail and the ability to work independently while managing multiple priorities.
  • Strong interpersonal and stakeholder engagement skills, with the ability to communicate with both technical and non-technical audiences.