Job Purpose:
This role serves as the process owner of all assurance activities related to the availability, integrity, and confidentiality of customer, business partner, employee, and business information in compliance with the organisation's information security policies. A key element of the role is working with management to determine acceptable levels of risk for the organisation. This position is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. The role will also be responsible for the implementation of different security solutions to ensure compliance with the different applicable security and risk standards in the Kingdom of Saudi Arabia and other geographies that we will operate in.
Key Accountabilities:
Develop, implement, and monitor a strategic, comprehensive enterprise information securityand IT risk management program Full abreast with the SAMA IT risk framework and ensure all implementation is in full compliance with the framework, regulations, and guidelines Work directly with the business units to facilitate risk assessment and risk management processes Develop and enhance an information security management framework Understand and interact with related disciplines through committees to ensure the consistentapplication of policies and standards across all technology projects, systems, and services Provide leadership to the enterprise's information security organization Advise the leadership team on the appropriate administration of information security standards,assisting them in developing plans within their business units to manage these risks effectivelyby understanding the fundamental aspects of their business objectives. Partner with business stakeholders across the company to raise awareness of riskmanagement concerns Assist with the overall business technology planning, providing current knowledge and futurevision of technology and systems Manage institution-wide information security governance processes, chair the Information Security Advisory Committee and lead Information Security Liaisons in the establishment of aninformation security program and project priorities. Perform risk assessments that address security threats, changes to systems and/orapplications, process improvement initiatives, supplier assessments (including downstreamoutsourcers) and other requests from the business. Develop and implement a comprehensive cloud strategy, selecting between public, private, or hybrid cloud models Oversee the allocation of compute, storage, and networking resources using Infrastructure as Code (IaC) to ensure consistency and prevent & configuration drift". Monitor cloud usage and spending to identify underutilized resources, right-sizing instances toensure the cloud investment remains cost-effective. Establish real-time monitoring and alerting systems to proactively detect and resolveperformance bottlenecks or system failures. Implement robust security protocols, including Identity and Access Management (IAM), dataencryption, and regular audits to maintain compliance with industry standards Establish annual and long-range security and compliance goals, define security strategies,metrics, reporting mechanisms and program services; and create maturity models and aroadmap for continual program improvements. Mature and operationalise various GRC capability areas such as enterprise security riskmanagement, compliance management, policy management, 3rd party risk management, andmetrics and reporting. Drive remediation activities from identification, remediation plan, and closure. Hold ownersaccountable for delivery of remediation solutions within the agreed upon/reasonable SLA. Manage BCP/DRP and Incident Response procedures, tests, and audits. Interface with internal and external auditors to articulate security controls when appropriate. Assess and communicate all security risks associated with purchases or practices performedby the company. Work with internal stakeholders across the business to identify, assess, report, track, andremediate risks and support the development of risk mitigation strategies. Make risk-based decisions and trade-offs impacting annual investment strategies and projectprioritisation. Maintain a strong understanding of risk management methodologies and frameworks. Understand business processes, regulations, and controls and develop meaningful tests toensure controls are operating effectively. Perform operational deep dives on compliance-related processes and systems. Identify, gather, track, and report key risk indicators. Work with partners to identify the root cause of issues. Identify potential risks and develop protocols that staff must follow to reduce or manage those risks. Implementing and overseeing the organisation’s cybersecurity program Aligning cybersecurity and business objectives Maintain PCI compliance of the organisation. Working closely with the cybersecurity team Monitoring Incident Response Activities Managing business continuity and disaster recovery Managing the governance and setup of Cloud Infrastructure Promoting a culture of strong information security Managing vendor relationships Utilising cybersecurity budgets effectively Providing awareness and training
Job Requirements:
Professional security management certification is mandatory (CISSP/CCSP/CISM/CISA) Degree in business administration or a technology-related (computer science or Computer Engineering) field required. 7+ years of experience in Information/Cybersecurity or IT Risk Management Strong knowledge of Cloud computing/Elastic computing across virtualised environments Minimum of 7 years of experience in a combination of risk management, information security and IT jobs Knowledge of common information security management frameworks, such as ISO/IEC 27001 and NIST. Excellent written and verbal communication skills and high level of personal integrity Innovative thinking and leadership with an ability to lead and motivate cross- functional, interdisciplinary teams Experience with contract and vendor negotiations and management, including managed services. Specific experience in Agile (scaled) software development or other best-in-class development practices.
الغرض من الوظيفة:
يعمل هذا الدور كمسؤول عن جميع أنشطة ضمان الجودة المتعلقة بتوافر وسلامة وسرية معلومات العملاء وشركاء الأعمال والموظفين ومعلومات العمل، وذلك وفقاً لسياسات أمن المعلومات في المؤسسة. يتمثل أحد العناصر الرئيسية لهذا الدور في العمل مع الإدارة لتحديد مستويات المخاطر المقبولة للمؤسسة. هذا المنصب مسؤول عن إنشاء وصيانة برنامج لإدارة أمن المعلومات على مستوى الشركة لضمان حماية أصول المعلومات بشكل كافٍ. كما سيكون الدور مسؤولاً عن تنفيذ حلول أمنية مختلفة لضمان الامتثال لمعايير الأمن والمخاطر المختلفة المعمول بها في المملكة العربية السعودية والمناطق الجغرافية الأخرى التي نعمل بها.
المسؤوليات الرئيسية:
تطوير وتنفيذ ومراقبة برنامج استراتيجي وشامل لأمن المعلومات وإدارة مخاطر تقنية المعلومات على مستوى المؤسسة. الإلمام الكامل بإطار عمل إدارة مخاطر تقنية المعلومات الخاص بـ "ساما" (SAMA) وضمان أن جميع عمليات التنفيذ تتوافق تماماً مع إطار العمل واللوائح والمبادئ التوجيهية. العمل مباشرة مع وحدات الأعمال لتسهيل عمليات تقييم المخاطر وإدارتها. تطوير وتعزيز إطار عمل لإدارة أمن المعلومات. فهم والتفاعل مع التخصصات ذات الصلة من خلال اللجان لضمان التطبيق المتسق للسياسات والمعايير عبر جميع المشاريع والأنظمة والخدمات التقنية. توفير القيادة لمؤسسة أمن المعلومات الخاصة بالشركة. تقديم المشورة لفريق القيادة بشأن الإدارة المناسبة لمعايير أمن المعلومات، ومساعدتهم في وضع خطط ضمن وحدات أعمالهم لإدارة هذه المخاطر بفعالية من خلال فهم الجوانب الأساسية لأهداف أعمالهم. الشراكة مع أصحاب المصلحة في الأعمال عبر الشركة لرفع الوعي بمخاوف إدارة المخاطر. المساعدة في التخطيط العام لتكنولوجيا الأعمال، وتقديم المعرفة الحالية والرؤية المستقبلية للتكنولوجيا والأنظمة. إدارة عمليات حوكمة أمن المعلومات على مستوى المؤسسة، ورئاسة اللجنة الاستشارية لأمن المعلومات وقيادة مسؤولي الاتصال بأمن المعلومات في إنشاء برنامج أمن المعلومات وأولويات المشروع. إجراء تقييمات المخاطر التي تعالج التهديدات الأمنية، والتغييرات على الأنظمة و/أو التطبيقات، ومبادرات تحسين العمليات، وتقييمات الموردين (بما في ذلك الجهات الخارجية) والطلبات الأخرى من العمل. تطوير وتنفيذ استراتيجية سحابية شاملة، والاختيار بين النماذج السحابية العامة أو الخاصة أو الهجينة. الإشراف على تخصيص موارد الحوسبة والتخزين والشبكات باستخدام البنية التحتية ككود (IaC) لضمان الاتساق ومنع انحراف التكوين. مراقبة استخدام السحابة والإنفاق لتحديد الموارد غير المستغلة، وتعديل حجم الحالات لضمان بقاء الاستثمار السحابي فعالاً من حيث التكلفة. إنشاء أنظمة مراقبة وتنبيه في الوقت الفعلي لاكتشاف وحل اختناقات الأداء أو أعطال النظام بشكل استباقي. تنفيذ بروتوكولات أمنية قوية، بما في ذلك إدارة الهوية والوصول (IAM)، وتشفير البيانات، وعمليات التدقيق المنتظمة للحفاظ على الامتثال لمعايير الصناعة. وضع أهداف أمنية وامتثالية سنوية وطويلة الأمد، وتحديد الاستراتيجيات الأمنية، والمقاييس، وآليات إعداد التقارير وخدمات البرنامج؛ وإنشاء نماذج النضج وخارطة طريق للتحسينات المستمرة للبرنامج. تطوير وتفعيل مجالات قدرات الحوكمة والمخاطر والامتثال (GRC) المختلفة مثل إدارة مخاطر أمن المؤسسة، وإدارة الامتثال، وإدارة السياسات، وإدارة مخاطر الطرف الثالث، والمقاييس وإعداد التقارير. قيادة أنشطة المعالجة من التحديد وخطة المعالجة والإغلاق. إلزام المالكين بتقديم حلول المعالجة ضمن اتفاقية مستوى الخدمة المتفق عليها/المعقولة. إدارة إجراءات استمرارية الأعمال/التعافي من الكوارث (BCP/DRP) والاستجابة للحوادث، والاختبارات، وعمليات التدقيق. التواصل مع المدققين الداخليين والخارجيين لتوضيح الضوابط الأمنية عند الاقتضاء. تقييم وتوصيل جميع المخاطر الأمنية المرتبطة بالمشتريات أو الممارسات التي تقوم بها الشركة. العمل مع أصحاب المصلحة الداخليين عبر الأعمال لتحديد وتقييم والإبلاغ عن وتتبع ومعالجة المخاطر ودعم تطوير استراتيجيات تخفيف المخاطر. اتخاذ قرارات ومقايضات قائمة على المخاطر تؤثر على استراتيجيات الاستثمار السنوية وترتيب أولويات المشاريع. الحفاظ على فهم قوي لمنهجيات وأطر إدارة المخاطر. فهم عمليات الأعمال واللوائح والضوابط وتطوير اختبارات ذات مغزى لضمان عمل الضوابط بفعالية. إجراء عمليات فحص دقيقة للعمليات والأنظمة المتعلقة بالامتثال. تحديد وجمع وتتبع والإبلاغ عن مؤشرات المخاطر الرئيسية. العمل مع الشركاء لتحديد السبب الجذري للمشكلات. تحديد المخاطر المحتملة وتطوير البروتوكولات التي يجب على الموظفين اتباعها لتقليل هذه المخاطر أو إدارتها. تنفيذ والإشراف على برنامج الأمن السيبراني للمؤسسة. مواءمة الأمن السيبراني وأهداف العمل. الحفاظ على امتثال المؤسسة لمعيار (PCI). العمل عن كثب مع فريق الأمن السيبراني. مراقبة أنشطة الاستجابة للحوادث. إدارة استمرارية الأعمال والتعافي من الكوارث. إدارة حوكمة وإعداد البنية التحتية السحابية. تعزيز ثقافة قوية لأمن المعلومات. إدارة علاقات الموردين. استخدام ميزانيات الأمن السيبراني بفعالية. توفير الوعي والتدريب.
متطلبات الوظيفة:
شهادة مهنية في إدارة الأمن إلزامية (CISSP/CCSP/CISM/CISA). درجة علمية في إدارة الأعمال أو مجال متعلق بالتكنولوجيا (علوم الكمبيوتر أو هندسة الكمبيوتر) مطلوبة. خبرة تزيد عن 7 سنوات في مجال أمن المعلومات/الأمن السيبراني أو إدارة مخاطر تقنية المعلومات. معرفة قوية بالحوسبة السحابية/الحوسبة المرنة عبر البيئات الافتراضية. خبرة لا تقل عن 7 سنوات في مزيج من إدارة المخاطر وأمن المعلومات ووظائف تقنية المعلومات. معرفة بأطر إدارة أمن المعلومات الشائعة، مثل ISO/IEC 27001 وNIST. مهارات تواصل كتابية ولفظية ممتازة ومستوى عالٍ من النزاهة الشخصية. تفكير ابتكاري وقيادة مع قدرة على قيادة وتحفيز فرق متعددة الوظائف وتخصصات مختلفة. خبرة في مفاوضات العقود والموردين وإدارتها، بما في ذلك الخدمات المدارة. خبرة محددة في تطوير البرمجيات الرشيقة (Agile) أو غيرها من أفضل ممارسات التطوير.