Manager Information Security - Emirati Talent
Commercial Bank International · Sharjah Emirate, United Arab Emirates
قدّم وتابع مع أبلاي إيدجJob Purpose: The Information Security - Manager will work directly under the Head of Information Security and s/he will be responsible for developing and implementing the security measures that keep the Bank's information assets safe. Working with IS management, the IS Manager will identify gaps in existing IS policies/ standards/ guidelines/ procedures and recommend updates to bring them into alignment with regulatory requirements, leading practices, and industry standards. Duties and Responsibilities: a) Assists in the development of the information security strategy and roadmap for all security technology domains b) To manage end-to-end security projects (UAE IA (NESA) Assessment, PCI DSS, SWIFT Controls, VAPT etc.) c) To verify and validate the closures of the gaps identified during various regulatory assessments & audits and can recommend alternative solutions in case of limitation in closing any of the observations mainly to security projects in first point d) Act as the Information Security lead for technology, digital transformation, cloud, infrastructure, application, and business projects. e) Manage multiple security and compliance projects simultaneously, prioritizing activities based on business impact and risk. f) Ensure information security requirements are identified and addressed during project initiation, planning, design, implementation, testing, and go-live. g) Coordinate with PMO and business project managers to ensure information security activities are integrated into overall project plans. h) Review project proposals, business requirements from an information security and risk perspective. i) Monitor information security trends internal and external to the Bank and keep IS management informed about information security related issues and activities affecting the Bank. j) Establish credibility and maintain strong working relationships with groups involved in information security matters (Internal Audit, Fraud, Physical Security, IT, External Audit, etc.). After the audit/ review, ensure that exceptions are tracked to closure on a timely basis. k) Monitor and assess compliance with applicable information security laws, regulations, contractual obligations, and industry requirements. l) Monitor security-related project deliverables, milestones, and dependencies and provide status reporting to project and executive stakeholders. m) Ensure security controls are mapped to relevant regulatory and compliance requirements. n) Advise the IS management on risk issues that are related to information security and recommend actions in support of the Banks wider risk management programs. o) Develop, implement, and continuously improve existing Information Security policies, standards, guidelines, procedures, processes, and forms as needed. p) Assist Bank’s departments or units as necessary to investigate security breaches and pursue associated disciplinary and legal matters. q) Manage the development and delivery of security awareness and training programs. r) Review security questionnaires, certifications, audit reports, and contractual security requirements s) Establish risk-based processes for third-party due diligence, onboarding, assessment, approval, monitoring, renewal, and offboarding. t) Develop and maintain standardized security questionnaires and assessment templates. u) Research security standards, security systems and authentication protocols, making recommendations to IS management as appropriate v) Contributes to team effort by accomplishing related results as needed. w) other duties as may be assigned by IS management. Education Level Required: Bachelor’s degree Professional / Technical Qualifications / Diplomas: CISM/ CRISC CISA/CISSP certification Experience: 10 - 12 years’ experience in related industry Skills Required for the Job: • In-depth knowledge and understanding of information security and technology infrastructure. • In-depth experiences in NESA requirements Implementation • In-depth experiences in developing information security policies in line with NESA Requirements • Creative thinking – able to look at alternatives and consider new ways building a conceptual framework on solving the problem. • Great communication skills. Should be able to communicate with senior non technical users without using technical language. • Ability to adapt to a fast-moving IT landscape and keep pace with latest thinking and new security technologies. • Multi-tasking – can manage several concurrent projects and prioritize demands.