Head of Cyber Security

بنك مسقط ش م ع ع
MUSCAT GOVERNORATE, Oman Full Time قبل ١٧ يوم
تقنية المعلومات الأمن والسلامة الأمن السيبراني الأمن السيبراني
Job Title: Head of Cyber Security
Department: IT Department

Main Role (Overall accountability):
The Head of Cyber Security leads the cyber defence operation covering Cyber Strategy & Resilience, Security Design & Engineering, Cyber Defense & Operations and Security Services & Remediation operations

Principal Accountabilities:
• Overall accountable leader for cyber security within the First Line of Defence (1LOD), reporting to GM-Technology (CIO).
• Designated as the "Accountable Lead" for Cyber Security, responsible for the end-to-end delivery of the Bank's cyber security strategy, operations, and resilience capabilities .
• Accountable for the effective design, implementation, and operation of all 1LOD cyber security controls across the enterprise, ensuring controls meet the objectives set by the Second Line of Defence (2LOD).
• Provides strategic direction and leadership across all cyber security functions: Strategy & Resilience, Security Design & Engineering, Cyber Defense & Operations, Security Services & Remediation, and 1.5LOD Governance, Risk & Compliance.
• Accountable for ensuring the Bank's cyber security posture meets regulatory requirements (CBO), international standards, and operates within the Board-approved cyber risk appetite.
• Represents the 1LOD cyber security function at executive management and Board forums, meetings as required, providing assurance on the effectiveness of the 1LOD control environment.
• Partners with the 2LOD Head of Technology and Cyber Risk (CISD) to ensure constructive alignment between independent risk oversight and operational delivery, maintaining the integrity of the Three Lines of Defence model.
• Accountable for the allocation of cyber security resources, budget, and investment priorities to maximise risk reduction and strategic value.
• Champions a culture of security awareness across the enterprise and ensures cyber security is embedded in business and technology decision-making.
• Accountable for the Bank's cyber incident response at the executive level, acting as the senior decision-maker during major cyber incidents and crisis events.
• Drives the maturation of the Bank's overall cyber security capability, establishing measurable objectives and ensuring continuous improvement across all functions.

Personnel Specifications:
 15+ years in cyber security, information security, or technology risk management, with a significant portion within banking or financial services
 Minimum 10 years in senior leadership roles with executive committee and board-level reporting and engagement experience
 Proven track record of building, leading, and maturing large, multi-disciplinary cyber security functions (50+ FTEs) in a regulated environment
 Experience developing and executing enterprise cyber security strategies aligned to business objectives and regulatory requirements
 Competent in leading teams operating across the full spectrum of cyber security domains: security architecture, engineering, defense operations (SOC/IR), GRC, and resilience
 Experience managing regulatory relationships and ensuring compliance with financial sector cyber regulations (e.g., CBO requirements)
 Track record of managing significant security investment portfolios (OpEx/CapEx) and demonstrating measurable risk reduction
 Executive-level crisis management and incident command experience
 Experience operating within a formal Three Lines of Defence model and partnering effectively with 2LOD and 3LOD (Internal Audit) functions

Qualifications (Guide):
 Bachelor's degree in Computer Science, Information Systems, Cyber Security, or related field (Master's degree or MBA preferred)
 CISSP certification required
 CISM certification highly advantageous
 CISA or CRISC advantageous
 Strategic leadership or executive management qualification beneficial (e.g., Cranfield, INSEAD, or equivalent)
 Professional membership of relevant bodies (e.g., (ISC)², ISACA)
 Knowledge of CBO regulations, Basel standards, and international cyber security frameworks (NIST CSF, ISO 27001)
رقم الوظيفة: 6697

احصل على وظائف مخصصة لك على واتساب

اشترك مجاناً واختر تخصصاتك، وسنرسل لك الوظائف المناسبة مباشرة على واتساب

اشترك عبر واتساب مجاناً
قدّم الآن