Job description
Responsible for developing and maintaining information security policies and processes, managing IT governance and risk, developing, and maintaining an effective disaster recovery and business continuity plan to ensure systems recovery and service availability in case of disasters.
- B.Sc. in a technology discipline (Computer Science, Information Management, Computer Engineering, Cybersecurity
- Security certifications such as CompTIA Security +, CISSP, CISA, CCNA or equivalent or working certification are highly preferable
- Minimum 7 years’ experience working directly in an Information Security or Information Technology department with experience in developing or managing Risk Management Programs.
- IT internal audit experience a plus.
Fluent in English.
DESIRABLE:
- Security certifications such as CompTIA Security +, CISSP, CISA, CCNA or equivalent or working certification.
- Oversee the assessment, development, and implementation of an organization-wide information security program and for maintaining ongoing activities to preserve the availability, integrity and confidentiality of information resources in compliance with applicable security policies and standards.
- Design, implement and monitor security systems in IT Infrastructure to ensure information confidentiality, integrity and availability at all times and proactively identify and resolve potential security breaches.
- Develop IT security policies and procedures, including those for end users, in an efficient and effective way, and oversee the enforcement of those policies in order to ensure compliance with industry-standard best practices.
- Stay abreast of new threats, vulnerabilities and security-focused technologies and incorporate such into Information Security Program and systems; ensuring the overall security, integrity and availability of systems and data.
- Provide third level support and investigate any security incidents in an effective way to ensure secure operation of the organization’s computer systems, servers, and network connections.
- Coordinate and manage the entire IT project lifecycle of IT Security systems – including management of scope, business requirements, functional and technical specifications, testing, implementation, deployment and phase management; identifying and managing project related issues, risks and mitigating scope creep; ensuring that all project goals are accomplished according to specifications and business objectives.
- Create and develop disaster recovery plan and define an IS risk register to ensure systems recovery and service availability in case of disasters and to remediate or mitigate risks.
- Prepare audit plans and conduct regular security audits in order to enforce security policies, determine any future needs and improvements and develop innovative solutions for information security.
- Directly responsible for IS assessments to ensure systems and applications are complying with policies, applicable regulatory and legal requirements, and leading industry practices.
- Provide ongoing career development, support and coaching for direct reports. Provide feedback to team and identify need-based training requirements for direct reports.
- Research, evaluate and recommend new security systems in order to improve information systems security.
- Monitor trends, develop, and provide monthly metrics and performance/status reports to ensure visibility of status to wider organization. Analyse performance of current IT Security systems and documented resolutions to enhance quality of service and to prevent future problems.