Job DescriptionRoles & Responsibilities Reporting to: Digitalization and IT Security Manager Role Objective: Lead the design, development and implementation of an effective Information Security Management framework that supports business activities and maintain the delivery of a secure environment. This role will also be responsible for developing, enhancing and ensuring adherence to IT security policies and procedures. The role will also hold approval responsibility for Change Management for IT technology related solutions (firewalls, IDS/IPS, Anti-Virus, etc.) throughout the enterprise. Duties and Responsibilities: 1. Design, implement and document appropriate security procedures with respect to the IT infrastructure and technology systems against accidental or unauthorized modification, destruction or disclosure in line with external best practice and organizational requirements. 2. Identify and manage key information security risks, audit findings and other incidents pertaining to IT related business risk. 3. Establish and implement an Information Security Management System (ISMS). 4. Plan, develop, and implement Internal & External Assurance Programs. 5. Develop, review, and publish the Information Security Strategy, Governance Policies, Codes of Practice, Specifications, and Procedures. 6. Integrate information security into Business Continuity, Emergency, and Disaster Recovery Programs. 7. Perform compliance and assurance activities. 8. Manage information security incidents. 9. Enable digital forensics capabilities. 10. .Stay abreast of the latest information security controls, technologies, practices, techniques and capabilities in the marketplace. Recommend and acquire new security technologies to ensure MDO is well positioned against the threat landscape 11. Ensure business continuity and disaster recovery plans are implemented and adhered to across all organizational levels and divisions 12. Works across the organization with system owners to remediate vulnerabilities and improve internal processes 13. Ensure risk assessments and tests are conducted to monitor the effectiveness of security measures 14. Monitor and conduct audits to understand compliance to IT security policies and procedures and regulate access to safeguard information. 15. Manage security violation and recommend disciplinary action in line with policy 16. Ensure IT governance is effective, efficient and transparent 17. Promote Information Security risk management as an embedded discipline in MDO 18. Collaborate with IT teams to ensure security integration across all systems and applications. 19. Design and implement security architectures, including network security, endpoint protection, and cloud security solutions. 20. Conduct security awareness and training programs. 21. Establish security metrics and Key Performance Indicators (KPIs). 22. Develop and execute an annual business plan 23. Perform additional information security tasks assigned by regulatory bodies. 24. Work closely with compliance teams to align security practices with regulatory requirements and certifications. Education: Bachelor's degree in IT Master s degree in IT is desired Experience: Minimum 7 years of experience in IT Security. Demonstrated ability to bring the benefits of IT to solve business issues while also managing costs and risks Competencies: Technical Expertise Strong knowledge of IT security principles, threat landscapes, and cybersecurity best practices. Problem-Solving Skills Ability to analyze security risks and quickly develop effective solutions. Attention to Detail A keen eye for identifying vulnerabilities and ensuring compliance with security policies. Communication Skills Ability to clearly convey security concepts to both technical and non-technical stakeholders. Incident Management Expertise in handling security incidents, forensic investigations, and mitigation strategies. Collaboration & Teamwork Ability to work effectively with IT, compliance, and business teams to implement security measures. Adaptability & Continuous Learning Staying updated on emerging security threats, technologies, and industry trends. Leadership & Mentorship Guiding junior team members and driving security awareness within the organization. Compliance & Regulatory Knowledge Understanding of frameworks like ISO 27001, NIST, GDPR, SOC 2, etc. Project Management Ability to manage security initiatives, meet deadlines, and align with business objectives
Subscribe for free, choose your specializations, and we'll send matching jobs directly to your WhatsApp
Subscribe via WhatsApp, free