Ensuring the confidentiality, integrity, and availability of Corporate Center sensitive information;
Contribute to building digital resilience and ensure business continuity in the face of cyber threats and disruptions;
Implement controls that protect the information systems and data from unauthorized access, information leakage;
Conducting regular information security assessments and threat modeling exercises to identify potential security risks and recommend remediation measures;
Maintaining incident response plans and procedures to ensure a timely and effective response to security incidents, data breaches, and cyber-attacks;
Contribute to the development and maintaining information security policies, procedures, guidelines, and requirements for projects, products and services;
Providing and maintaining an enterprise Information Security awareness program
Information Security reporting, KPI monitoring for Corporate Center on a regular basis and upon request;
Providing technical guidance and support to business units and project teams to ensure that security requirements and controls are integrated into digital transformation initiatives and new technology deployments;
Work closely with the IT team, external service providers, and consultants to provide necessary security controls;
Understanding and communicating legal and regulatory requirements on Information Security and IT;
May serve as a resource to others in the resolution of complex security and IT problems and issues;
Namizədə tələblər
Relevant academic qualifications, a university degree in Information Security, Informatics, Computer Science, and Management of Information Systems;
Minimum 3 years of professional work experience in information security and IT;
Good Understanding of OSs, Microsoft AD, Networking, Firewalls, Cloud Security, Data Privacy, Virtualization, and Security Controls. DLP, MDM solutions knowledge is an advantage;
Understanding of Information Security standards and regulations such as ISO 27k family, NIST CSF, COBIT, PCI DSS and etc.;
Understanding of concepts related to information systems, including security and control risks such as logical and physical access security, change management, information security and privacy, business recovery practices and network technology;
CompTIA Security+ or other relevant security certification or vendor-specific security certification is an advantage
Financial Industry knowledge is an advantage;
Confident written and verbal communication skills along with the ability to present technical information to both technical and non-technical audiences.