وصف الوظيفة
الوصف
الغرض من الوظيفة: تنفيذ أنشطة إدارة مخاطر التقنية من خلال تقييم المخاطر وتقديم الاستشارات حسب الطلب لتحسين معالجة مخاطر التقنية.
1.القيام بصورة مباشرة بتقييمات مخاطر التقنية المستقلة في السيناريوهات التالية:
a.مشروعات التقنية والتحول الرقمي.
b.مراجعات فاعلية وظيفة الخط الأول لضوابط مخاطر التقنية
c.عند الطلب عقب الحوادث التقنية.
2.مساعدة مالكي المخاطر في تصميم وتنفيذ خطط معالجة مخاطر التقنية من خلال تقديم الخبرة (تقنية، وظيفية وإجرائية) وتقديم الإرشاد لاتخاذ قرارات قائمة على المخاطر.
3.تحديد مخاطر التقنية والتحقق منها عند مراجعة تقارير التدقيق الداخلية والخارجية وملاحظات مخاطر التقنية والحوادث التقنية والمساهمة في خطط العمل المرتبطة بها للتخفيف منها.
4.التعامل مع جميع أنشطة إدارة مخاطر التقنية بما في ذلك مراجعة وتقييم ملاحظات المخاطر المختلفة وضمان تحديثاتها ذات الصلة في سجل المخاطر المركزي، وإبلاغ وإبلاغ مالكي المخاطر بالمخاطر التقنية ذات الصلة، والتنسيق مع الأطراف المعنية المختلفة حول خطط التخفيف من المخاطر.
5.تحديث مجموعة وثائق إدارة مخاطر التقنية المختلفة
6.تقييم كفايات المقاييس ونكبات مؤشرات المخاطر الرئيسية لمراقبة فاعلية الضوابط وضمان التخفيف الصحيح للمخاطر.
7.المساهمة مع الأقسام ذات الصلة لتحديد المخاطر والفجوات الإشعار المبكر للمخاطر التقنية التي قد تنشأ من أي تغيير في الأنظمة والخدمات والعمليات أو الإجراءات.
السياسات والعمليات والإجراءات
اتباع جميع سياسات القسم والعمليات والمعايير والإجراءات والتعليمات التشغيلية حتى يتم العمل بشكل محكم ومتسق
8.المساعدة في تعريف وصيانة وت enriquec التوثيقات لمقاييس إدارة مخاطر التقنية والتدرج والخطورة وكذلك ممارسة تقنيات إدارة مخاطر التقنية بمهارة والتي صُمِّمت لضمان التقاط وإدارة جميع مخاطر التقنية بشكل كافٍ. علاوة على ذلك، إعداد مواد تدريبية وتنفيذ أنشطة اتصالات بما يتوافق مع الأطراف المعنية لتحسين العقلية والمعرفة.
9.تتبع ومتابعة مع خط الدفاع الأول للمخاطر التقنية، التي ما زالت قيد التقييم في سجل المخاطر المركزي.
10.المساعدة في مراجعة خطط المعالجة المختلفة المرتبطة بإدارة مخاطر التقنية بالتعاون مع الأطراف المعنية قبل التقديم للجنة المختصة لضمان استجابة فعالة للمخاطر التقنية المحددة.
السياسات والعمليات والإجراءات
11.اتباع جميع سياسات القسم والعمليات والمعايير والتعليمات ذات الصلة لضمان إجراء العمل بطريقة محكومة ومتسقة
العمليات اليومية
12.اتباع العمليات اليومية المرتبطة بالوظائف الخاصة في قسم الأمن وإدارة مخاطر التقنية لضمان استمرارية العمل
الامتثال
13.الامتثال لجميع التنظيمات المصرفية المعمول بها، وقوانين البنوك، ولوائح مكافحة غسل الأموال والسياسات الداخلية الخاصة بالبنك والمؤسسة القيمية من أجل الحفاظ على الوضع القانوني السليم للمصرف وتخفيف أي مخاطر محتملة
المؤهلاتالمؤهلات والخبرة
§بكالوريوس في الهندسة، علوم الحاسوب، تكنولوجيا المعلومات أو ما يعادلها.
§للضابط 3 – 5 سنوات في تكنولوجيا المعلومات، تدقيق تكنولوجيا المعلومات داخلي أو خارجي أو تخصص مشابه بخلفية في إدارة المخاطر.
§للضابط الأعلى 5 – 8 سنوات في تكنولوجيا المعلومات، تدقيق تكنولوجيا المعلومات داخلي أو خارجي أو تخصص مشابه بخلفية في إدارة المخاطر.
§معرفة جيدة ببيئة أعمال البنوك، وضوابط التكنولوجيا وإدارة المخاطر.
§معرفة وخبرة مع واحد على الأقل من أُطر إدارة المخاطر: ISO31K، FAIR.
§شهادات صناعية ذات صلة موصى بها، بما في ذلك على سبيل المثال لا الحصر:
·مدير مخاطر ISO 27005
·IT Infrastructure Library (ITIL) Foundation.
·شهادة GIAC Critical Controls (GCCC).
·Certified Information System Auditor (CISA)
· Certified Risk and Information Systems Control (CRISC)
Job description
Description
Job Purpose: To execute the Technology Risk Management activities by evaluating risks and providing on demand advisory to improve technology risk remediation.
1.Perform directly to rollout independent Technology Risk Assessments in the following scenarios:
a.Technology Projects and Digital Transformation.
b.Reviews of First Line Function effectiveness for Technology Risk controls
c.On demand following technology incidents.
2.Assist risk owners on design & implementation of Technology Risk Remediation Plans by providing expertise (Technical, functional and procedural) and provide guidance for risk based decisions.
3.Identify and validate Technology Risks upon reviewing Internal & External Audit Reports, Technology Risk Notes, Technology Incidents and contribute to their associated action plans to mitigate the same.
4.Handle all of the Technology Risk Management Activities including but not limited to reviewing & qualifying the different risk notes and ensuring the relevant updates are reflected in the central risk register, communicating and notifying risk owners with relevant technology risks, coordinating with the relevant stakeholders on the different risk remediation plans.
5.Update the different Technology Risk Management Documentation Corpus
6.Assessment of metrics and Key Risk Indicators breaches to monitor the effectiveness of the controls and ensure proper risk mitigation.
7.Contribute with relevant departments to identify risks, risk gaps and early warning signals for Technology Risks that could arise from any change in systems, services, processes or procedures.
Policies, Processes, and Procedures
Follow all relevant department policies, processes, and standards operating procedures and instructions so that work is carried out in an controlled and consistent manner
8.Assist in defining, maintaining and enriching Technology Risk Managements’ Metrics, Taxonomy and Severity Scale as well as proficiently practice Technology Risk Management techniques, methods and tools that were designed to ensure that all Technology risks are adequately captured and managed. Moreover, prepare training materials and carry out communications activities in alignment with relevant stakeholders in order to improve mindset and knowledge.
9.Track and follow up with 1st Line of Defense of the Technology risks, which are still under assessment in the centralized risk register.
10. Assist in reviewing the different risk treatment plans related to Technology Risk Management in cooperation with relevant stakeholders prior submitting to the relevant committees, to ensure effective response to identified technology risks
Policies, Processes, and Procedures
11.Follow all relevant department policies, processes, and standards operating procedures and instructions so that work is carried out in an controlled and consistent manner
Day-to-Day Operations
12.Follow the day-to-day operations related to own jobs in the Security & Technology Risk Management department to ensure continuity of work
Compliance
13.Comply with all relevant CBE regulations, banking laws, AML regulations and internal CIB policies and code of conduct in order to maintain CIB’s sound legal position and mitigate any potential risks
QualificationsQualification & Experience
§Bachelor of Engineering, Computer Science, Information Technology or its equivalent.
§For Officer 3 – 5 years in Information Technology, internal or external IT audit or a related discipline with Risk Management background.
§For Senior Officer 5 – 8 in Information Technology, internal or external IT audit or a related discipline with Risk Management background.
§Good knowledge of the Banking business environment, technology controls and Risk Management.
§Knowledge & experience with at least one of the Risk Management Framework: ISO31K, FAIR.
§Recommended relevant industry certifications, including but not limited to:
·Risk Manager ISO 27005
·IT Infrastructure Library (ITIL) Foundation.
·GIAC Critical Controls Certification (GCCC).
·Certified Information System Auditor (CISA)
· Certified Risk and information Systems Control (CRISC)