Governance, Risk & Compliance Manager / Infosec
Governance, Risk & Compliance Manager / Infosec
Arab African International Bank- Posted a day ago
- Be among the first 10 applicants
Job Description
KEY ACCOUNTABILITIES
- Manage the information technology and cybersecurity risk management process and make sure there is ongoing risk reduction.
- Review security and compliance assessments on new and existing systems, processes, and technology.
- Oversee the communication with various business units to ensure controls are adequate, appropriate, and effective.
- Conduct Cyber Security and Information technology risk assessment.
- Review information technology and cybersecurity risks mitigation plans, and periodically update risk register.
- Manage periodic gap assessments against Cyber Security standards to validate compliance on an ongoing basis.
- Manage and review Information Security policies, procedures, and plans updates.
- Insure Engaging in new proposed projects to identify potential information technology and cybersecurity risks.
- Review (governance, risk, and compliance) activities to ensure the implementation of security controls, exceptions, and risk mitigation.
- Oversee the Development of Information Security policies to support AAIB s information Security governance and compliance objectives.
- Review and validate Compliance with CBE Conditional approvals related to information Security.
- Provide Consultation for design and implementation of the GRC platforms.
- Ensure Implementing the Cyber Security related Controls for local and international security regulations.
- Validate risks in RCSAs and their related security controls for new and existing AAIB Projects/Products.
- Participate and recommend improvements to policies, processes and procedures and manage their implementation to ensure all relevant legislative/procedural requirements are fulfilled
- Supervise the activities and work of subordinates to ensure that all work within a specific area is carried out in an efficient manner and in compliance with the set policies, processes and procedures.
- Supervise the day to day operations of the team providing some guidance in the related area, encouraging teamwork, innovation, recommending new approaches and facilitating related professional work processes in order to achieve high performance standards.
- Liaise with internal and external parties at the appropriate levels to ensure smooth flow of interactions.
QUALIFICATIONS, EXPERIENCE & SKILLS
- Experience with IT governance, risk, and compliance management in a large global environment
- Minimum of 7 - 10 years of experience
- Preferred certification: CRISC, CISM, CISA
- Excellent Knowledge of ISO 31000's risk management principles; ISO/IEC 38500 (corporate governance of information technology)
- Good knowledge of implementing and using GRC tools.
- Experience in implementing and operating an ISMS aligned to ISO/IEC 27001
- Experience in Cyber security and IT Risk standards ISO 27005.
- Knowledge of Information Security management frameworks ex: NIST 800-30 and compliance practices.
- Develop security policies and guidelines based on best practices and industry standards.
Skills:
- Excellent communication and leadership skills.
- Ability to handle high pressure situations with key stakeholders.
- Good Analytical skills, Problem solving and Interpersonal skills.
- Working knowledge and experience with MS office
More Info
Job Type:
Industry:
Employment Type:
Key Skills
Cyber security and IT Risk standards ISO 27005
ISMS aligned to ISO IEC 27001
ISO IEC 38500 corporate governance of information technology
GRC tools
IT governance risk and compliance management
