Responsibilities
: Oversee daily Information Security Risk processes, focusing on risk identification and reduction activities. Supportpliance efforts, including ISO22301 and ISO27001 re-certification. Review and develop security policies and standards in line with industry standards, regulatory requirements, and the current threat environment. Implement security processes for assurance activities, including risk issue management, third-party risk assurance, and security criteria for projects. Produce regular security reporting dashboards and packs forernance groups. Develop, monitor, and report key indicators (KPIs/KRIs/KCIs). Assist withpliance and legal initiatives related to information security and operational risk processes such as RCSA, Threat Modelling, and Incident Management. Evaluate and procure new security services, technologies, and systems.
Skills and Experience:
In-depth knowledge of information security, data privacy, and risk management principles. Familiarity with regulations, audit, and certification processes. Understanding of modern Internet technologies and ability to assess technical findings in a broader organizational context. Capability to develop security standards and guidelines based on best practices, regulatory requirements, and industry standards. Insight into threat vectors and security risks across different IT environments. Strong understanding of effective cyber risk management. Proficient project management skills. Knowledge of industry standards/frameworks (, ISO, NIST, COBIT, ITIL).
Qualifications:
Experience with security frameworks and standards. Certifications such as CISA, CRISC, CISSP are desirable but not required. Degree, diploma, or equivalent experience in a technology-related field is advantageous but not mandatory.