Source description
About the role
Responsibilities: 1. Build and lead the strong team for IT Risk Management, IT Compliance and SOC. 2. Adhere and promote the information security policy awareness and best practices in the company. 3. Lead the ISO 27001 Implementation and ensure its compliance. 4. Based on ISMS monitoring results, evaluate & recommend for IS policy change and new information security countermeasures. 5. Recommended security controls as per ISO 27001 standard 6. Establish Data Security controls. 7. Standardization and modernize IT and Cybersecurity practices as per global standard. 8. Conduct security review of the new requirement/projects to ensure required security controls are incorporated in the IT solution. 9. Conduct technical review of Information System which includes system hardening, access controls, privilege access, exceptional access granted, identify obsolete configuration, etc. Post Technical review recommend the cyber security controls. 10. Conduct business and technical functions risk assessment to identify, evaluate & analyse risk and recommend the remediation actions. 11. Review MSA/SoW/NDA, Contractual requirements of customers and vendors and advise on information security compliance. 12. Facilitate external audit and ensure timely closure. 13. Lead and oversee information security budget and staffing. 14. Acquire and manage the necessary resources, including leadership support, financial resources, and key security personnel, to support information technology (IT) security goals and objectives and reduce overall organizational risk. 15. Recommend resource allocations required to securely operate and maintain an organization’s cybersecurity requirements. 16. Develop policy, programs, and guidelines for implementation. 17. Establish Information Security Policy in the company. 18. Oversee policy standards and implementation strategies to ensure procedures and guidelines comply with cybersecurity policies 19. Establish a risk management strategy for the organization. 20. Advise management on risk levels and security posture. 21. Make recommendations regarding the selection of cost-effective security controls to mitigate risk. 22. Provides cybersecurity recommendations to leadership based on significant threats and vulnerabilities 23. Ensure that cybersecurity requirements are integrated into the continuity planning for that system and/or organization(s). 24. Establish acceptable limits for the software application, network, or system usage. 25. Provide advice and input for Disaster Recovery, Contingency, and Continuity of Operations Plans. Knowledge: 1. Knowledge of ISO 27001 or PCI DSS Standards & Controls 2. Drafting / implementing ISMS / Information Security Policy 3. Strong Knowledge on IT RISK Management 4. Knowledge of IT, Cyber Security best practices, processes, and tools
Presentation Skills, IT Risk Management, IT Compliance, Innovative Thinking, Communication, Team Management
More at rhsandbox