Job Description
Performing activities regarding governance of Company Information Security efforts towards protecting information and information systems. Maintain and enforce the information security policy, monitor compliance directly or in coordination with the Information Security Assurance and Information Protection team. Track risks and compliance items and perform security planning requirements as directed by the management. Maintain all the relevant governance information security policies and procedures in accordance with the good practice and regulatory requirements.
Activity: Risk and compliance
Responsibility:
• Lead the risk assessment of information security risks in accordance with policies and procedures in defined intervals within Company.
• Review the information security risk treatment plan.
• Check compliance with information security requirements.
Activity: Policies and procedures development and enforcement
Responsibility:
• Lead development, implementation, enforcement and reviews of governing information security policies and procedures and track compliance with the regulatory and other international information security standards.
Activity: Security Planning
Responsibility:
• Lead development, review and acceptance of security plans with the stakeholders.
• Lead identification, implementation and assessment of the common security controls.
Activity: Security Awareness
Responsibility:
• Positively contribute to the establishment and maintenance of a robust security culture within Company . Conducts investigation interviews as required.
Skills
Technical Competency
• Information Security governance
• Incident handling and management
• Knowledge of Information Security frameworks and standards
• Communications Security Management
• Compliance
• Computer Network Defense
• Configuration Management
• Encryption
• Identity Management
• Information Assurance
• Information Resources Strategy and Planning
• Asset management
• Information Systems/ Network Security
• Information Security Architecture
• Risk Management
• Technology Awareness
• Vulnerabilities Assessment
Behavioral Competency
Core Competencies:
• Respect for Safety and Security
• Integrity and Transparency
• Communication Effectiveness
• Results Focus: Working effectively and efficiently
• Teamwork
• Accountability
• Customer Focus