Responsibilities :
- Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program
- Work directly with the business units to facilitate risk assessment and risk management processes Develop and enhance an information security management framework
- Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems and services
- Partner with business stakeholders across the company to raise awareness of risk management concerns
- Assist with the overall business technology planning, providing a current knowledge and future vision of technology and systems
Requirements :
Degree in business administration or a technology-related field requiredProfessional security management certificationMinimum of 7 years of experience in a combination of risk management, information security and IT jobsKnowledge of common information security management frameworks, such as ISO / IEC 27001, NIST, SOC 2 and GDPRExcellent written and verbal communication skills and high level of personal integrityInnovative thinking and leadership with an ability to lead and motivate cross functional, interdisciplinary teamsHands-on experience in managing information / cyber security systems and solutionsHaving exposure in formulation and implementation of information security policies and proceduresExperience with contract and vendor negotiations and management including managed services Specific experience in Agile (scaled) software development or other best in class development practicesExperience with Cloud computing / Elastic computing across virtualized environmentsA good understanding or working knowledge ofo Vulnerability assessments and penetration testing
o Application security source code reviews
o Incident management and investigations life cycle
o Security Architecture design principles and its applications in real world scenarios