PMF Finance PLC logo
1
applicant

Executive - IT Support & Data Protection

PMF Finance PLC    Colombo • Full-time

Job Description

The Executive - IT Support & Data Protection will support the IT Department in implementing, maintaining, and monitoring technical and operational controls related to data protection, privacy, endpoint security, and information security.
The role will support the IT Department in ensuring that customer, employee, vendor, and other personal information is handled in accordance with the Sri Lanka Personal Data Protection Act (PDPA), applicable regulatory requirements, internal policies, and established information security and data protection best practices.

The position will primarily focus on endpoint security, Data Loss Prevention (DLP), data classification, patch management, access controls, and other technical controls that support the protection of organizational and personal data.

Job Profile

  • Support the implementation, administration, and monitoring of Endpoint Security, EDR/Antivirus, and device security controls.
  • Support the implementation and ongoing management of Data Loss Prevention (DLP) controls across endpoints, email, cloud services, and other applicable platforms.
  • Assist in implementing and maintaining the organization's Data Classification framework, labels, policies, and user controls.
  • Support patch management and vulnerability remediation activities for endpoints and other assigned systems to maintain secure and compliant environments.
  • Monitor endpoint security alerts, DLP incidents, data classification violations, and related security events and escalate identified issues appropriately.
  • Assist in configuring and maintaining security policies for laptops, desktops, mobile devices, removable media, email, and cloud services.
  • Support user access management, access reviews, least-privilege controls, and other identity-related data protection controls.
  • Assist in maintaining Records of Processing Activities (ROPA), privacy registers, data inventories, and related data protection documentation.
  • Support DPIA, PIA, privacy risk assessments, personal data breach investigations, and data protection compliance reviews.
  • Assist in ensuring personal and confidential data is appropriately collected, stored, accessed, shared, retained, and securely disposed of.
  • Support the implementation of Privacy by Design and Privacy by Default requirements for new systems, applications, and technology projects.
  • Assist with IT, information security, data protection, internal audit, external audit, and regulatory review activities.
  • Maintain records relating to endpoint security, DLP, patching, incidents, access controls, and remediation activities.
  • Coordinate with Information Security, Compliance, Risk, Internal Audit, HR, Operations, and relevant business units on data protection and security matters.
  • Support staff awareness and user guidance relating to data classification, DLP, endpoint security, secure data handling, and privacy requirements.
  • Coordinate with technology vendors and service providers for implementation, maintenance, troubleshooting, and remediation of data protection-related technologies.
  • Perform other IT, information security, and data protection duties assigned by the AGM - IT / Head of IT.

Candidate Profile

  • Bachelor's Degree or Diploma in Information Technology, Information Security, Cybersecurity, Computer Science, Business Information Systems, or a related discipline.
  • Minimum 2-4 years of relevant experience in Information Technology, Endpoint Security, Information Security, Data Protection, IT Operations, or related areas.
  • Experience in a bank, finance company, insurance company, fintech, or other regulated financial institution will be an added advantage.
  • Practical knowledge of Endpoint Security, EDR/Antivirus, DLP, Data Classification, Patch Management, Access Management, and Microsoft 365.
  • Basic knowledge of the Sri Lanka Personal Data Protection Act (PDPA) and data privacy principles.
  • Exposure to ISO/IEC 27001, ISO/IEC 27701, vulnerability management, IT audit, risk management, or cybersecurity will be advantageous.
  • Strong analytical, troubleshooting, documentation, and communication skills.
  • High level of confidentiality, integrity, responsibility, and attention to detail.

Remuneration and rewards commensurate with qualifications, experience and competencies await those with ambition, motivation and the willingness to perform.

Forward your detailed CV with two non-related referees and a recent photograph within 7 days of this advertisement