IT Risk, Security & Cloud Infrastructure Manager
Indexed description
Job Purpose:
This role serves as the process owner of all assurance activities related to the availability, integrity, and confidentiality of customer, business partner, employee, and business information in compliance with the organisation's information security policies. A key element of the role is working with management to determine acceptable levels of risk for the organisation. This position is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. The role will also be responsible for the implementation of different security solutions to ensure compliance with the different applicable security and risk standards in the Kingdom of Saudi Arabia and other geographies that we will operate in.
Key Accountabilities:
- Develop, implement, and monitor a strategic, comprehensive enterprise information security
- and IT risk management program
- Full abreast with the SAMA IT risk framework and ensure all implementation is in full compliance with the framework, regulations, and guidelines
- Work directly with the business units to facilitate risk assessment and risk management processes
- Develop and enhance an information security management framework
- Understand and interact with related disciplines through committees to ensure the consistent
- application of policies and standards across all technology projects, systems, and services
- Provide leadership to the enterprise's information security organization
- Advise the leadership team on the appropriate administration of information security standards,
- assisting them in developing plans within their business units to manage these risks effectively
- by understanding the fundamental aspects of their business objectives.
- Partner with business stakeholders across the company to raise awareness of risk
- management concerns
- Assist with the overall business technology planning, providing current knowledge and future
- vision of technology and systems
- Manage institution-wide information security governance processes, chair the Information
- Security Advisory Committee and lead Information Security Liaisons in the establishment of an
- information security program and project priorities.
- Perform risk assessments that address security threats, changes to systems and/or
- applications, process improvement initiatives, supplier assessments (including downstream
- outsourcers) and other requests from the business.
- Develop and implement a comprehensive cloud strategy, selecting between public, private, or hybrid cloud models
- Oversee the allocation of compute, storage, and networking resources using Infrastructure as
- Code (IaC) to ensure consistency and prevent & configuration drift".
- Monitor cloud usage and spending to identify underutilized resources, right-sizing instances to
- ensure the cloud investment remains cost-effective.
- Establish real-time monitoring and alerting systems to proactively detect and resolve
- performance bottlenecks or system failures.
- Implement robust security protocols, including Identity and Access Management (IAM), data
- encryption, and regular audits to maintain compliance with industry standards
- Establish annual and long-range security and compliance goals, define security strategies,
- metrics, reporting mechanisms and program services; and create maturity models and a
- roadmap for continual program improvements.
- Mature and operationalise various GRC capability areas such as enterprise security risk
- management, compliance management, policy management, 3rd party risk management, and
- metrics and reporting.
- Drive remediation activities from identification, remediation plan, and closure. Hold owners
- accountable for delivery of remediation solutions within the agreed upon/reasonable SLA.
- Manage BCP/DRP and Incident Response procedures, tests, and audits.
- Interface with internal and external auditors to articulate security controls when appropriate.
- Assess and communicate all security risks associated with purchases or practices performed
- by the company.
- Work with internal stakeholders across the business to identify, assess, report, track, and
- remediate risks and support the development of risk mitigation strategies.
- Make risk-based decisions and trade-offs impacting annual investment strategies and project
- prioritisation.
- Maintain a strong understanding of risk management methodologies and frameworks.
- Understand business processes, regulations, and controls and develop meaningful tests to
- ensure controls are operating effectively.
- Perform operational deep dives on compliance-related processes and systems.
- Identify, gather, track, and report key risk indicators.
- Work with partners to identify the root cause of issues.
- Identify potential risks and develop protocols that staff must follow to reduce or manage those risks.
- Implementing and overseeing the organisation’s cybersecurity program
- Aligning cybersecurity and business objectives
- Maintain PCI compliance of the organisation.
- Working closely with the cybersecurity team
- Monitoring Incident Response Activities
- Managing business continuity and disaster recovery
- Managing the governance and setup of Cloud Infrastructure
- Promoting a culture of strong information security
- Managing vendor relationships
- Utilising cybersecurity budgets effectively
- Providing awareness and training
Job Requirements:
- Professional security management certification is mandatory (CISSP/CCSP/CISM/CISA)
- Degree in business administration or a technology-related (computer science or Computer Engineering) field required.
- 7+ years of experience in Information/Cybersecurity or IT Risk Management
- Strong knowledge of Cloud computing/Elastic computing across virtualised environments
- Minimum of 7 years of experience in a combination of risk management, information security and IT jobs
- Knowledge of common information security management frameworks, such as ISO/IEC 27001 and NIST.
- Excellent written and verbal communication skills and high level of personal integrity
- Innovative thinking and leadership with an ability to lead and motivate cross- functional, interdisciplinary teams
- Experience with contract and vendor negotiations and management, including managed services.
- Specific experience in Agile (scaled) software development or other best-in-class development practices.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search