Responsibilities and Qualifications:
- Developing security policies and procedures based on industry standards, ISO requirements, COBIT 19, government regulations, and best practices.
- Overseeing and reporting security measures implementation such as firewalls, encryption technology, and data backups to protect against unauthorized access to data.
- Develop access management for core and other applications and overseeing and reporting implementation.
- Monitoring security systems to ensure that they are functioning properly.
- Develop annual information security plan and budget and overseeing and reporting implementation of the plan.
- Managing risk by assessing vulnerability of systems to cyber-attacks or other security breaches and following upon remediation of vulnerabilities.
- Developing security awareness training programs for employees on topics such as social engineering, phishing scams, malware infections, and data loss prevention methods and others.
- Working and managing external security providers such as auditors and consultants.
- Making sure that security measures are adequate and provide continuous reports.
- Performing security assessments on hardware and software applications to identify any vulnerabilities that could be exploited by hackers or malicious insiders.
- Creating and maintaining a Disaster Recovery Plan (DRP) to ensure that business operations can be restored after a disaster such as a fire or flood.
- Performing risk assessments and following up on implementation of controls.
- Monitoring compliance with information security policies and procedures and taking corrective action as necessary.
- Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity or any related field.
- A minimum of 4 - 6 years of experience.