Information Security & Operational Risk Officer
To assist in implementing and maintaining the required and internationally accepted standard of information security controls across the company's IT infrastructure. To conduct the security audits and risk assessment program, and review compliance with the information security policies and associated procedures. To handle the development, implementation, operation, maintenance, and support of information security policies, standards, guidelines, and procedures that enhance the level of security over the business's information assets, and reduce the probability of loss.
To handle the requirements of the Bahrain Personal Data Protection Law (PDPL). In addition, the role holder will be responsible for implementing and monitoring adherence to the company's operational risk management strategy and business objectives, and for ensuring that operational risk issues are identified and escalated to the appropriate level for consideration and approval.
1. Operational Risk Management
- Establish the required policies and procedures to manage operational risks.
- Establish and roll out the risk control self-assessment and key risk indicator framework.
- Handle the implementation of the operational risk management framework across the company in order to reduce the company's operational risk exposure.
- Establish the required policies and procedures to manage the information security framework.
- Enforce the information security policies, procedures, controls, and standards.
- Assist in the development and implementation of information security policies and procedures.
- Lead ISO 27001 compliance, ensuring year-round task completion by respective stakeholders.
- Assist in information security training and oversight for company employees.
- Handle information security risk assessments and security audits.
- Monitor compliance with information security policies and procedures, referring problems to the appropriate department manager.
- Monitor internal control systems to ensure that appropriate access levels are maintained.
- Provide expert advice on all aspects of information security and risk management to the management and staff of the company.
- Educate employees on information security and risk management matters, including the criticality of compliance with information security program requirements.
- Maintain awareness of changes in security risks, security measures, and computer systems.
- Conduct periodic operational risk and information security training for new and existing staff (at least annually).
- Perform quarterly Operational Risk training for new joiners.
- Assume responsibility as project leader for special projects and provide valuable insights to the management.
- Assist and participate in special projects concerning information security, including testing and implementation of security software enhancements.
- Maintain a broad knowledge of state-of-the-art technology, equipment, and/or systems.
- Handle the requirements of the Bahrain Personal Data Protection Law (PDPL) and coordinate with other heads of department to ensure full compliance.
- Assist in annual audit reviews by payment associations such as PCI DSS, PCI PIN, PCI 3DS, ISO 27001, client-related audits, and other regulatory bodies.
- Evaluate the effectiveness of controls and measure whether they are meeting the standards and processes laid down by financial, regulatory, and other bodies.
- Assist in reviewing the potential risk exposure before the launch of new products/services.
- Assist in reviewing third-party contracts as and when requested.
- Assist in monitoring the disaster recovery plan and contingency planning.
- Assist…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).