Seller did not upload any pictures
Information Security Officer Wanted
Price
Free
Category
Listing ID
#1980
Viewed
465x
Publish date
February 26, 2018
Description
Information Security Officer
Introduction
Implementation, management and compliance of a comprehensive Information Technology security program with the Information Technology lines of business to protect their applications and supporting infrastructure from both internal and external threats toward zero downtime and zero audit findings. Management of IT risk and compliance in alignment with IT strategy. Single point of contact for IT security risks, incidents and internal controls within the Group.
Description
Implementation, management and compliance of a comprehensive Information Technology security program with the Information Technology lines of business to protect their applications and supporting infrastructure from both internal and external threats toward zero downtime and zero audit findings. Management of IT risk and compliance in alignment with IT strategy. Single point of contact for IT security risks, incidents and internal controls within the Group.
Key Responsibilities and Deliverables:
Provide IT Security strategy, consulting proactively and on a project risk
Develop and manage a roadmap for information security related to internal controls, compliance, regulatory and a proactive risk mitigation plan for the Technology department
Develop and implement IT Security strategy, policies and standards that supports and enables business strategy at the strategic planning, tactical and operational business unit levels
Build business relationships with key stakeholders to proactively consult and mitigate security threats
Research and develop a knowledge base of the IT threat landscape, security trending, regulatory requirements, mobile and other new technologies and best practices to mitigate and plan against threats
Provide ad-hoc consulting and engagement with various business units. Not limited to investigation, RFI, RFQ, selection and assessments of current technologies. Benchmark best of breed security practises
Change manage and measure the adoption of IT Security solutions e.g. logical access management or e.g. IT Security risk assessments and penetration tests toward zero audit findings
Advise IT business partners on regulatory, compliance (POPI, PAIA etc) and/or legal requirements as it relates to securing of data as well as project manage internal controls to mitigate threats
Establish relevant internal control metrics and audits to measure outcomes and performance related to security
Implement standards toward zero downtime and zero audit findings. Develop an internal security audit framework
Identify, Assess and remediate Technology and IT Security Risks
Formulate a repository for all security related documentation. Maintain a risk register and IT risk management schedule
Conduct reviews of applications, systems, infrastructure, databases and processes as required
Contribute to project risk management consulting and technical reviews
Ongoing management of general control reviews, technical system reviews including Penetration Test Team
Co-ordinate and track the implementation of remediation plans
Participate in incidents and consult with disciplinary and legal matters
Drive audit framework
Manage the audit framework. Logical access, physical access, change management, security controls (hardware, software and data levels). Implement additional processes, such as Segregation of Duties, Password Safes and Audit trails, to address the risk posed by privileged IT users
Implement and validate reviews according to policies and standards set out (across PM Lifecycle and SDLC)
Assist with implementation of IT Security Policies, Standards and Guidelines
Annual review of IT Security Policies, Standards and Guidelines according to technology objectives
Form a communicate plan for the requirements for compliance to the IT Security Policies, Standards and Guidelines to the relevant parties within IT. Escalate non-compliance matters to CIO
Formulate vendor/supplier standards for information security
Contribute and formalise a documented outcome for Due diligence, RFI, RFP processes
Conduct regular (minimum annual) reviews for security review for vendors or technology suppliers
Maintain and manage and consult on matters relating to BCP, DR and high availability.
Ensure an updated 2 year plan on DR and related reporting
Profile
IT related Bachelor Degree or Degree in Computer Science
Security related certification
To Apply, please send the word "START" followed by your email address to 35543 and you will be registered in our database.
Introduction
Implementation, management and compliance of a comprehensive Information Technology security program with the Information Technology lines of business to protect their applications and supporting infrastructure from both internal and external threats toward zero downtime and zero audit findings. Management of IT risk and compliance in alignment with IT strategy. Single point of contact for IT security risks, incidents and internal controls within the Group.
Description
Implementation, management and compliance of a comprehensive Information Technology security program with the Information Technology lines of business to protect their applications and supporting infrastructure from both internal and external threats toward zero downtime and zero audit findings. Management of IT risk and compliance in alignment with IT strategy. Single point of contact for IT security risks, incidents and internal controls within the Group.
Key Responsibilities and Deliverables:
Provide IT Security strategy, consulting proactively and on a project risk
Develop and manage a roadmap for information security related to internal controls, compliance, regulatory and a proactive risk mitigation plan for the Technology department
Develop and implement IT Security strategy, policies and standards that supports and enables business strategy at the strategic planning, tactical and operational business unit levels
Build business relationships with key stakeholders to proactively consult and mitigate security threats
Research and develop a knowledge base of the IT threat landscape, security trending, regulatory requirements, mobile and other new technologies and best practices to mitigate and plan against threats
Provide ad-hoc consulting and engagement with various business units. Not limited to investigation, RFI, RFQ, selection and assessments of current technologies. Benchmark best of breed security practises
Change manage and measure the adoption of IT Security solutions e.g. logical access management or e.g. IT Security risk assessments and penetration tests toward zero audit findings
Advise IT business partners on regulatory, compliance (POPI, PAIA etc) and/or legal requirements as it relates to securing of data as well as project manage internal controls to mitigate threats
Establish relevant internal control metrics and audits to measure outcomes and performance related to security
Implement standards toward zero downtime and zero audit findings. Develop an internal security audit framework
Identify, Assess and remediate Technology and IT Security Risks
Formulate a repository for all security related documentation. Maintain a risk register and IT risk management schedule
Conduct reviews of applications, systems, infrastructure, databases and processes as required
Contribute to project risk management consulting and technical reviews
Ongoing management of general control reviews, technical system reviews including Penetration Test Team
Co-ordinate and track the implementation of remediation plans
Participate in incidents and consult with disciplinary and legal matters
Drive audit framework
Manage the audit framework. Logical access, physical access, change management, security controls (hardware, software and data levels). Implement additional processes, such as Segregation of Duties, Password Safes and Audit trails, to address the risk posed by privileged IT users
Implement and validate reviews according to policies and standards set out (across PM Lifecycle and SDLC)
Assist with implementation of IT Security Policies, Standards and Guidelines
Annual review of IT Security Policies, Standards and Guidelines according to technology objectives
Form a communicate plan for the requirements for compliance to the IT Security Policies, Standards and Guidelines to the relevant parties within IT. Escalate non-compliance matters to CIO
Formulate vendor/supplier standards for information security
Contribute and formalise a documented outcome for Due diligence, RFI, RFP processes
Conduct regular (minimum annual) reviews for security review for vendors or technology suppliers
Maintain and manage and consult on matters relating to BCP, DR and high availability.
Ensure an updated 2 year plan on DR and related reporting
Profile
IT related Bachelor Degree or Degree in Computer Science
Security related certification
To Apply, please send the word "START" followed by your email address to 35543 and you will be registered in our database.
