

National Development Bank PLC
Senior Deputy Manager (Information Security)
Contact us to remove this listing
- Full Time
- Colombo, Sri Lanka
- Negotiable LKR / Month
National Development Bank PLC
Senior Deputy Manager (Information Security) – National Development Bank PLC
Job Overview
National Development Bank PLC (NDB) is seeking a Senior Deputy Manager – Information Security to join its Information Security team. The role focuses on safeguarding the Bank’s information assets, strengthening cyber resilience, ensuring regulatory compliance, and supporting strategic information security initiatives.
Job Title: Senior Deputy Manager – Information Security
Company: National Development Bank PLC (NDB)
Job Level: Senior Deputy Manager
Job Location: Colombo, Sri Lanka
Closing Date: 28 September 2026
Position Details
- Lead Information Security governance and second-line-of-defense activities.
- Review and challenge the effectiveness of cybersecurity controls and risk management practices.
- Support the Bank’s Information Security Committee and regulatory initiatives.
- Strengthen the Bank’s Information Security Management System (ISMS).
- Drive compliance with relevant information security standards and regulatory requirements.
Company Overview
National Development Bank PLC (NDB) is a Sri Lankan financial services institution providing commercial banking services through its island-wide operations. The Bank operates across areas including retail, business and corporate banking, treasury, trade finance and other financial services.
Qualifications & Experience
- Bachelor’s degree in Information Technology, Information Security, Computer Science or a related discipline.
- Professional certifications such as CISSP, CISM, ISO 27001 Lead Implementer/Auditor, ISO 27035 Practitioner or equivalent certifications are highly desirable.
- Minimum 3–5 years of solid experience in Information Security, with 5–7 years of working exposure particularly in regulated industries such as banking and finance.
- Deep understanding of regulatory frameworks including CBSL, SEC and CSE requirements.
- Knowledge of compliance standards such as PCI DSS and ISO standards.
- Proven experience in:
- ISMS implementation
- Security compliance audits
- Third-party risk management
- Incident management frameworks
Key Responsibilities
- Conduct second-line-of-defense activities by independently reviewing and challenging the effectiveness of cybersecurity controls, vulnerability management practices, incident management processes and remediation activities.
- Ensure identified risks are appropriately addressed and remediation actions are timely and effective.
- Participate actively in the Bank’s Information Security Committee (ISC) and drive initiatives in line with regulatory expectations.
- Drive implementation of ISO/IEC 27035 for Information Security Incident Management and other relevant ISO standards.
- Ensure alignment with the CBSL Technology Risk Management Framework.
- Expand and maintain the Bank’s Information Security Management System (ISMS) in line with evolving regulatory requirements and international standards.
- Support continuous improvement initiatives around ISO/IEC 27001 (ISMS).
- Develop, implement and periodically review Information Security policies and end-user guidelines.
- Lead and coordinate user access reviews and monitor organizational compliance.
- Enforce endpoint security controls, including email security and removable media controls.
- Maintain and improve data classification frameworks, including Data Classification Matrix and Data Loss Prevention (DLP) strategies.
- Develop and execute a comprehensive Information Security Awareness Programme covering employees, Board members and senior management.
- Support business units and IT teams in policy interpretation, standards alignment and secure-by-design principles.
Required Skills
- Strong Information Security governance and risk management skills.
- Knowledge of cybersecurity controls and vulnerability management.
- ISMS implementation and ISO 27001 knowledge.
- Information Security incident management.
- Data classification and DLP knowledge.
- Security compliance and regulatory knowledge.
- Strong leadership and stakeholder engagement skills.
- Excellent communication and influencing abilities.
- Analytical mindset with a proactive approach to identifying risks and recommending improvements.
- Ability to work effectively with senior leadership, business units and IT teams.
Salary & Benefits
- The advertisement does not specify a salary figure.
- The position offers an opportunity to work closely with senior leadership and contribute to strategic Information Security and cyber resilience initiatives.
How to Apply
Interested candidates should apply through the NDB Bank careers application process.
Application Deadline: 28 September 2026
Important Notes
- Job Level: Senior Deputy Manager.
- Job Location: Colombo, Sri Lanka.
- Strong experience in regulated industries, particularly banking and finance, is required.
- Professional Information Security certifications are highly desirable.
- NDB Bank will correspond only with shortlisted applicants.
- NDB Bank is an equal opportunity employer.
Job Category: IT & Software; Banking & Insurance; Security; Management; Private Jobs
Ready to apply?
Senior Deputy Manager (Information Security)
⏰ Deadline: October 5, 2026
More Opportunities
Related Job Vacancies


Credit Risk Specialist
Merchant Bank of Sri Lanka & Finance PLC

Executive | Junior Executive (SEO)
MedFuture Group


Recruitment Business Consultant
MedFuture Group

Senior | Executive (Procurement and Office Maintenance)
MedFuture Group

Assistant Manager (Compliance)
Alliance Finance Company PLC

Executive (Compliance)
Alliance Finance Company PLC