Roles and Responsibilities
Strategy
- Develop and implement information-security strategies and operating models aligned with laws, regulations, and Authority needs.
- Define the risk framework: maintain registers, scenarios, and response plans with accountable owners and escalation paths.
- Set Authority-wide security programs and technical standards across sectors to embed best practices consistently.
- Evaluate emerging technologies and threat trends and issue strategic recommendations to improve security systems and infrastructure.
- Coordinate with departments to align cybersecurity strategies and work plans with organizational objectives.
Operations
- Lead in-depth analysis of security incidents, direct incident-response activities, and strengthen digital forensics and investigation quality.
- Plan and coordinate Security Operations Centre (SOC) operations and response workflows with internal and external stakeholders.
- Support and advise team leads in the development and management of the organization's Vulnerability Assessment and Penetration testing (VAPT) plan and building VAPT tools and frameworks
- Oversee the conduct of readiness evaluations and penetration tests; recommend preventive and corrective actions and track closure.
- Review architectures for new initiatives and system changes; prescribe security controls during design and implementation.
- Govern access and privileges: apply eligibility/approval procedures, review entitlements, monitor network/system activity, and report compliance.
- Execute risk-based audits of technical systems and projects; evaluate control effectiveness and drive corrective plans.
- Assess new technology projects for alignment with cybersecurity strategy and risk profile; provide improvement recommendations.
- Manage security assessments of external suppliers and partners and ensure compliance with required security standards.
- Execute additional Information Security duties assigned by leadership beyond the defined Section scope.
Product/Process Improvement
- Maintain risk registers and mitigation plans; analyse performance metrics and report system effectiveness and residual risks.
- Manage and update cybersecurity documentation, including policies, procedures, contingency plans, and ensure legal and regulatory compliance.
- Prepare and refine emergency/incident response and recovery plans via exercises and lessons learned.
Job Qualifications & Requirements
Education
- Bachelor's degree/ master's degree in computer science/ information technology
Experience
- 9+ Years in case of Master's degree (11+ years in case of Bachelor's degree)
Qualification
- Certifications such as Certified Information Systems Security Professional (CISSP) or, Certified Information Security Manager (CISM), ISO/IEC 27001 Lead Implementer/ Lead Auditor