Senior Manager Cyber Org Alignment & Compliance.ISG - Information Security Program
Other Jobs To Apply
No other job posts for this day.
<p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Job Purpose</strong></span></span><br><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">The Information Security Cyber Organization Alignment role is focused on the strategic alignment of information security practices with the bank’s overall risk management strategy, compliance requirements, and governance frameworks. The role focuses on driving Information Security Governance, Risk, and Compliance (GRC) initiatives to strengthen the bank’s security posture while ensuring alignment with regulatory and business objectives. through effective processes i.e., risk tracking, compliance monitoring, RCSA, evaluating exceptions, and ensuring accurate reporting. The role ensures the right level of governance is in place and drives continuous improvement in risk management processes. The role leverages automation to streamline processes and enhance risk visibility across Information Security Group through managing GRC solutions</span></span><br><br><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Key Result Areas</strong></span></span><br> </p><figure class="table"><table border="1" cellspacing="0" cellpadding="0" width="751" style="border-collapse: collapse; border-width: medium; border-style: none; border-color: currentcolor; border-image: initial;"><tbody><tr style="height: 15pt;"><td width="716" valign="top" style="border: 1pt solid windowtext; height: 15pt; padding: 0in 5.4pt; width: 537.15pt;"><p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Governance, Risk, Compliance:</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure compliance with policies, regulatory requirements, and industry standards.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Identify, assess, and manage information security risks.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure adherence to internal and external compliance requirements.</span></span></li></ul><p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Policy Exception Management:</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Develop and maintain a comprehensive process for managing policy exceptions, including documentation, expiration date and approval workflows.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure all policy exceptions are properly documented, reviewed, and approved in accordance with organizational standards.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Perform risk assessments for proposed policy exceptions to evaluate their potential impact on compliance and security. </span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Work with stakeholders to communicate policy exception process, develop compensating controls for policy exceptions, and ensure timely closure.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Regularly review and monitor granted exceptions to ensure compliance with the terms and conditions.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Conduct periodic audits to assess compliance with approved exceptions and identify deviations for remediation. </span></span></li></ul><p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Risk Control Self Assessments </strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Coordinate and ensure regular risk control self-assessments across various business units to identify and evaluate potential risks.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Compile and analyze assessment results and prepare detailed reports with actionable insights and recommendations.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Perform follow-ups to verify the effectiveness of implemented controls and risk mitigation measures.</span></span></li></ul><p> </p><p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Offshoring Reporting</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Maintain accurate and timely reporting of offshoring activities</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure alignment with regulatory reporting requirements, and supporting the organization’s compliance posture concerning offshore operations</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Establish streamlined reporting mechanisms that meet both internal and external requirements.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Assess and manage the risks associated with offshoring arrangements. Ensure that appropriate controls and mitigations are in place to address any regulatory or compliance risks tied to offshore activities.</span></span></li></ul><p> </p><p><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>ISG Service Portfolio Management:</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Develop and maintain a comprehensive service catalog that accurately reflects the services offered by ISG. Regularly review and update the service catalog to ensure it aligns with business needs and technological advancements.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Monitor the performance of ISG services to ensure they meet established service level agreements (SLAs) and key performance indicators (KPIs).</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Compliance Management </strong></span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Oversee the implementation and management of information security compliance across the bank, ensuring alignment with regulatory requirements and industry standards</span></span></li><li>I<span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">dentify relevant regulatory obligations related to information security and ensure appropriate actions are taken to meet these requirements.</span></span></li><li><p style="line-height: 107%;"><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;">Manage</span></span> <span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;">and</span></span> <span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;">track co</span></span>mp<span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;">liance incidents and exceptions, ensuring pr</span></span>o<span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;">per documentation and resolution through GRC systems.</span></span></p></li></ul><p style="line-height: 107%;"><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt; line-height: 107%;"><strong>GRC Function Automation: </strong></span></span></p><ul style="list-style-type: disc;"><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Be the owner of the bank’s GRC platform for ISG and oversee the management of the bank’s IS GRC solution. </span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Oversee the administration, configuration, and maintenance of the GRC platform to ensure optimal performance and availability</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Enable centralized knowledgebase and GRC solution to automate Information Security activities and governance process with a centralized risk register, risk reports and dashboards related to overall risk posture for specific location and business unit. </span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Automate the GRC functions and reduce manual efforts to provide near real time insights into risks by performing quantitative and qualitative assessments. </span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Support local CISO’s / IS SPOCs in regulatory audit discussion and data required from ISG and enabling the local CISOs with Archer access to onboard the open issues for centralized tracking and governance.</span></span></li><li><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure that the solution is effectively used to support the organization’s information security governance, risk, and compliance activities</span></span></li></ul></td></tr></tbody></table></figure><p> </p><p> </p><p> </p><p> </p><p> </p><figure class="table"><table border="1" cellspacing="0" cellpadding="0" width="751" style="border-collapse: collapse; border-width: medium; border-style: none; border-color: currentcolor; border-image: initial;"><tbody><tr><td width="716" valign="top" style="border-width: 2.25pt 2.25pt medium medium; border-style: solid solid none none; border-color: windowtext windowtext currentcolor currentcolor; padding: 0in 5.4pt; width: 537.15pt;"><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Operating Environment, Framework and Boundaries, Working Relationships</strong></span></span></td></tr><tr><td width="716" valign="top" style="border-width: 1pt 2.25pt; border-style: none solid solid; border-color: currentcolor currentcolor windowtext; padding: 0in 5.4pt; width: 537.15pt;"><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Operating environment: </strong>All the locations where </span></span><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Mashreq Bank </span></span><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">is operational</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Frameworks</strong>: Information security policy manual, regulations, industry best practices and contractual requirements. </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Working Relationship</strong>: All Business, Governance, Enabling and Control groups. </span></span></li></ul><p> </p></td></tr><tr><td width="716" valign="top" style="border-width: medium 2.25pt 1.5pt medium; border-style: none solid solid none; border-color: currentcolor windowtext windowtext currentcolor; padding: 0in 5.4pt; width: 537.15pt;"><h1><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Problem Solving</strong></span></span></h1></td></tr><tr><td width="716" valign="top" style="border-width: medium 2.25pt; border-style: none solid; border-color: currentcolor windowtext; padding: 0in 5.4pt; width: 537.15pt;"><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ability to enable framework, solution, and processes for proactive management of information security risks </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ability to understand regulatory language, can take decisions on applicability, compensating controls and residual risk. </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ability to derive residual risk and control based on defense – in depth strategy and systemic risk while taking risk and control decisions. </span></span></li></ul><p> </p></td></tr><tr><td width="716" valign="top" style="border-width: 1.5pt 2.25pt 1.5pt medium; border-style: solid solid solid none; border-color: windowtext windowtext windowtext currentcolor; padding: 0in 5.4pt; width: 537.15pt;"><h1><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Decision Making Authority & Responsibility</strong></span></span></h1><p> </p></td></tr><tr><td width="716" valign="top" style="border-width: medium 2.25pt; border-style: none solid; border-color: currentcolor windowtext; padding: 0in 5.4pt; width: 537.15pt;"><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Consult and validate recommendations to mitigate information security risks</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Consult and provide recommendations to mitigate the risk to a level aligned with the risk appetite of the bank. </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Assure compliance with regulatory expectation and avoid regulatory penalties.</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Confirm adequacy of the controls against internal information security policy, standards and applicable regulatory requirements.</span></span></li></ul><p style="margin-left: 0.25in; text-align: justify;"> </p></td></tr><tr><td width="716" valign="top" style="border-width: 1.5pt 2.25pt 1.5pt medium; border-style: solid solid solid none; border-color: windowtext windowtext windowtext currentcolor; padding: 0in 5.4pt; width: 537.15pt;"><h1><span style="font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Knowledge, Skills, and Experience</strong></span></span></h1></td></tr><tr style="height: 92.1pt;"><td width="716" valign="top" style="border-width: medium 2.25pt 1pt; border-style: none solid solid; border-color: currentcolor windowtext windowtext; height: 92.1pt; padding: 0in 5.4pt; width: 537.15pt;"><p><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Essential knowledge</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Have around 10+ years of experience in a Banking environment and over 3 years of experience in information security. </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Familiarity with information security technologies, risk, threat and vulnerability assessments, and security measures. </span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Experience with governance, risk management, and compliance frameworks (e.g., ISO 27001, NIST, GDPR, PDPL).</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Hold professional certifications (e.g., CISA, CISM, CISSP, CRISC)</span></span></li></ul><p><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Skills and Application </strong></span></span></p><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Strong communication and interpersonal skills.</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ability to manage multiple projects and priorities.</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Proficiency in security tools and technologies.</span></span></li></ul><p><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;"><strong>Strategic Insight</strong></span></span></p><ul style="list-style-type: disc;"><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Foster a culture of security awareness and compliance within the organization.</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Continuously improve the information security posture of the organization.</span></span></li><li><span style="color: black; font-family: " 29lt="" bukra",="" sans-serif;"=""><span style="font-size: 8pt;">Ensure that information security risks are effectively managed and mitigated.</span></span></li></ul><p><span> </span></p></td></tr></tbody></table></figure><p><br> </p><p> </p> <br><div> The leading financial institution in MENA </div> <div> <span>While more than half a century old, we proudly think like a challenger, startup, and innovator</span> </div> <div> <span>in banking and finance, powered by a diverse and dynamic team who put customers first.</span> </div> <div> <span>Together, we pioneer key innovations and developments in banking and financial services.</span> </div> <div> <span>Our mandate? To help customers find their way to Rise Every Day, partnering with them through</span> </div> <div> <span>the highs and lows to help them reach their goals and unlock their unique vision of success.</span> </div> <div> <span>Delivering superior service to clients by leading with innovation, treating colleagues with dignity and fairness while pursuing opportunities that grow shareholders value. </span> </div> <div> <span>We actively contribute to the community through responsible banking in our mission to inspire more people to Rise.</span> </div>