- The selected candidate will be reporting to the AGMCISO and responsible for the following.
- Developing and implementing secure processes and systems used to prevent detect mitigate and recover from cyberattacks
- Meeting regulatory legal and other compliances
- Educating staff and managing technology risk in collaboration with business leaders
- Building and driving a cybersecurity strategy and framework with initiatives to secure the organizations cyber and technology assets
- Continuously evaluating and managing the cyber and technology risk posture of the organization
- Implementing and managing the Cyber Governance Risk and Compliance (GRC) process
- Developing justifying and evaluating cybersecurity investments
- Developing and implementing ongoing security awareness training and education for users up to Board of Directors
- Work together with BCP team in leading cybersecurity operations and implementing disaster recovery protocols and business continuity plans with business resilience in mind
- Review all Information Security Policies and Procedures annually introduce new Policies and Procedure as and when required
- Monitor and follow up Cyber Security related activities reported to Incident Response Team (IRT)
Requirements
- The right candidate should possess a Bachelor of Science Degree in one of the following (Computer Engineering / Electronics Engineering
- Computer Science / Information Technology / Information Security)
- Professional Diploma from British Computer Society and at least one of the following Certifications / Qualifications
- Master s degree in information security or master s degree in computer science / information technology specialising in Information Security
- (ISC)2 Certified Information Systems Security Professional (CISSP)
- GIAC Strategic Planning Policy and Leadership (GSTRT)
- GIAC Information Security Professional (GISP)
- ISACA Certified Information Systems Auditor (CISA)
- ISACA Certified Information Security Manager (CISM)
- ISACA Certified in Risk and Information Systems Control (CRISC) And
- At least 5 years of experience as a Information Security professional with 3 years in managerial level
Other Competencies Required:
- Familiar with leading security standards such as NIST and ISO 27001:2022
- Must have strong management communication leadership and negotiation abilities
- Need to understand cloud and application security aware of the potential security risks associated with emerging technologies such as machine learning.
- Sound technical knowledge in Information Security Network Technologies Databases and Operating Systems
- A thorough understanding of latest security principles techniques and protocols
- Familiarity with Web related techniques and development environments
- Should be a strong Team Player who can work under pressure autonomously
The right candidate should possess a Bachelor of Science Degree in one of the following (Computer Engineering / Electronics Engineering Computer Science / Information Technology / Information Security) Professional Diploma from British Computer Society and at least one of the following Certifications / Qualifications Master s degree in information security or master s degree in computer science / information technology specialising in Information Security (ISC)2 Certified Information Systems Security Professional (CISSP) GIAC Strategic Planning, Policy, and Leadership (GSTRT) GIAC Information Security Professional (GISP) ISACA Certified Information Systems Auditor (CISA) ISACA Certified Information Security Manager (CISM) ISACA Certified in Risk and Information Systems Control (CRISC) And At least 5 years of experience as a Information Security professional with 3 years in managerial level Other Competencies Required: Familiar with leading security standards such as NIST and ISO 27001:2022 Must have strong management, communication, leadership, and negotiation abilities Need to understand cloud and application security, aware of the potential security risks associated with emerging technologies such as machine learning. Sound technical knowledge in Information Security, Network Technologies, Databases and Operating Systems A thorough understanding of latest security principles, techniques and protocols Familiarity with Web related techniques and development environments Should be a strong Team Player who can work under pressure autonomously