KEY ACCOUNTABILITIES
- Assist in conducting the information technology and cybersecurity risk management processes and make sure there is ongoing risk reduction.
- Prepare the required Information Security policies to support AAIB s information Security governance and compliance objectives.
- Perform Cyber Security assessments on new and existing systems, processes, technology and ensure compliance with CBE and Security Standard
- Work with various AAIB business units to ensure Information Security controls are effectively implemented.
- Prepare information technology and cybersecurity risks mitigation plans, and periodically update risk register.
- Engage in new proposed projects to identify potential information technology and cybersecurity risks.
- Perform (governance, risk, and compliance) activities to ensure the implementation of security controls, exceptions, and risk mitigation.
- Ensure Compliance with CBE Conditional approvals related to information Security.
- Communicate with AAIB different teams for Proactive Compliance Risk Management - identification, assessment, risk action planning, and closures.
- Assist and share best practices for design and implementation of the GRC platforms.
- Support in preparing information security reports to track remediation activities and action plans.
- Identify Cyber Security and Information Technology risks in RCSAs and their related security controls for new and existing AAIB Projects/Products.
Prepare and update Information Security Key Risk indicators
QUALIFICATIONS, EXPERIENCE & SKILLS
- Strong knowledge in information Security policies and procedures development
- Minimum of 3 – 7 years of experience
- Good knowledge with IT governance, risk, and compliance management in a large global environment
- Preferred certification: CGRC, GRCP, CRISC, ISO 27K
- Good Knowledge of ISO 31000's risk management principles; ISO/IEC 38500 (corporate governance of information technology)
- Familiarity with implementing and using GRC tools.
- Familiarity with Cyber security and IT Risk standards ISO 27005.
- Knowledge of Information Security management frameworks ex: NIST 800-30 and compliance practices.
- Strong knowledge in security assessment background
- Good knowledge of compliance and regulatory standards
- CBE standards
- NIST standards
- PCI-DSS
Skills
- Excellent communication and leadership skills.
- Ability to handle high pressure situations with key stakeholders.
- Good Analytical skills, Problem solving and Interpersonal skills.
- Working knowledge and experience with MS office.