DexNova is a Professional Services firm operating in the knowledge industry and dedicated to building excellent delivery capability in organisations across Africa through Professional Training and Certifications. We are Certified Education Provider…
Job Summary:
- The Chief Information Security Officer (CISO) is responsible for establishing and maintaining a corporate-wide information security management program to ensure that information assets are adequately protected. The role serves as the process owner of all assurance activities related to the availability, integrity and confidentiality of customer, business partner, employee and business information in compliance with the organization's information security policies. A key element of the CISO's role is working with executive management to determine acceptable levels of risk for the organization.
Job Responsibilities:
- Develop, implement and monitor a strategic, comprehensive enterprise information security and IT risk management program.
- Provide leadership to the Bank's information security organization.
- Work directly with the business units to facilitate risk assessment and risk management processes.
- Understand and interact with related disciplines to ensure the consistent application of policies and standards across all technology projects, systems and services.
- Partner with business stakeholders across the company to raise awareness of risk management concerns.
- Assist with the overall business technology planning, providing a current knowledge and future vision of technology and systems.
- Provide guidance and advice to the management and board on cyber security regulations issued by the regulators from time to time.
- Act as a liaison between the regulators and the bank in matters pertaining to IT and cyber security.
- Manage day-to-day cybersecurity activities and the mitigation of cybersecurity risks in the Bank.
- Develop, oversee and implement the cybersecurity programme and strategy as approved by the Board.
- Ensure that the Bank maintains an updated record of its users, devices, applications and their relationships, including but not limited to; Software and hardware asset inventory & Network utilization and performance data
- Ensure that information systems meet the needs of the Bank, and the ICT strategy, in particular information system development strategies, comply with the overall business strategies, risk appetite and ICT risk management policies of the Bank.
- Design cybersecurity controls with the consideration of users at all levels of the organization, including internal (i.e., management and staff) and external users (i.e., contractors/consultants, business partners and service providers).
- Organize cybersecurity related trainings to improve technical proficiency of staff.
- Ensure that regular and comprehensive cyber risk assessments are conducted.
- Ensure that adequate processes are in place for monitoring IT systems to detect cybersecurity events and incidents in a timely manner.
Job Qualification & Requirements:
- Degree in a computer/ technology related field or business management.
- Professional security management certification
- Minimum of 10 years of experience in a combination of risk management, information security and IT roles
- Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST.
- Experience in Disaster recovery planning, security architecture development, network security and firewall management, identity management, crisis response and remediation, mobile and remote device management, data and information management (classification, retention and destruction).application and database security.
- Excellent written and verbal communication skills and high level of personal integrity
- Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams
- Experience with contract and vendor negotiations and management including managed services.
- Specific experience in Agile (scaled) software development or other best in class development practices.
- Experience with Cloud computing/Elastic computing across virtualized environments.
Method of Application
Signup to view application details.
Signup Now