Enter a job title or keyword

Governance, Security & Compliance Specialist


Job Location:

Colombo - Sri Lanka

Monthly Salary: Not provided by the employer
Posted: 1 August 2026 (30+ days ago)
Application Deadline: 29 October 2026
Vacancies: 1 Vacancy

Job Summary

  • Review and enforce information security policies and cybersecurity standards across all engagement activities
  • Guide teams on AI governance and responsible AI practices (Knowledge AI) ensuring AI systems are used and deployed ethically
  • Ensureall data handling practices meet data protection and privacyrequirements (e.g. GDPR or applicable local data privacy laws)
  • Monitor and ensure engagement delivery meets regulatory requirements applicable to the financial services sector
  • Apply and oversee model risk management practices for AI/ML models including validation documentation and risk classification
  • Review development practices against secure software development standards (secure SDLC code review vulnerability management)
  • Assess and manage third-party risk management requirements for any vendors tools or sub-contractors involved in the engagement
  • Coordinate resource background verification for all personnel assigned to the engagement
  • Ensure confidentiality commitments (NDAs data handling agreements) are signed and enforced
  • Establish protocols for secure handling of sensitive information including storage access control and transmission

Requirements

  • 10 years of experience in informationsecurity IT compliance risk management or governance roles (financial services experience strongly preferred)
  • Working knowledge of cybersecurity frameworks and standards (e.g. ISO 27001 NIST)
  • Understanding of data privacy regulations such as GDPR and any relevant local data protection laws
  • Familiarity with financial sector regulatory requirements (e.g. relevant centralbank guidelines SOX PCI-DSS or similar depending on jurisdiction)
  • Experience with model risk management frameworks (e.g. SR 11-7 or equivalent) is a plus
  • Understanding of secure software development lifecycle (SDLC) practices
  • Experience conducting or coordinating third-party/vendor risk assessments
  • Ability to manage confidentiality processes including NDAs and background verification procedures
  • Strong attention to detail integrity and ability to work with sensitive/confidential information
  • Relevant certifications (e.g. CISSP CISA CRISC ISO 27001 Lead Auditor) are an advantage