To help us improve your experience of our site , we are undertaking a short survey to get to know you better. It only takes one minute, so please click here and tell us about yourself.
This full-time position line reports to the IT Director and is responsible for the management of technology security risk regionally, providing guidance on security matters relating to Application and IT Infrastructure management. The position will liaise closely with the Regional business Security Director, CTO Security and Regional IT Risk teams.
Job Responsibilities:
Develop and implement security strategy for Regional IT in line with the global strategy
Ensure regional compliance of IT with the global security policy and standards framework.
Deploy, and adhere to the efficient operation of the information risk management programme
Assist with the design of secure applications as well as infrastructure in line with the Technical Standards laid out in the Information Security Policies & Standards framework.
Responsible to test availability and continuity of IT services by continually validating business continuity and disaster recovery processes
Responsible for managing operational security of IT Strategy SAP solutions in the new consolidated SAP solution landscape
Implement and monitor Security Baseline Controls and relevant security standards
Develop IT security and risk mindset, and support the Information Security Awareness Programme
Own the ITIL Security Process, and ensure that Security is implemented in all ITIL processes
Undertake Technical Security Reviews
Review security incidents, advise on mitigation and track progress
Main Accountabilities:
Strategising:
o To coordinate, align and justify an Infrastructure IT Security Road Map for Asia AMET (Africa, Middle East, Turkey) through work with Regional ISO, Regional Architecture and Infrastructure Towers.
Planning and Budgeting:
o To ensure the Roadmap driven IT Security programme is aligned with the Global, Regional IT SIA programme and IT Strategy; to ensure the regional programme initiatives are included in the annual plan and budget of the Operating Clusters and Companies.
o To ensure the programme has the requisite budget.
Business Case Justification:
o To ensure the VP Asia AMET Infrastructure is supported with business justification of all initiatives so that the proposed Infrastructure Security programme is supported by the IPI and there is adequate resource to implement the projects
o To create a business justification for all security related aspects of Regional/Global projects and to assist Business Partners and Service delivery in assessing full cost profiles on security items for the various projects under their control
Programme Implementation;
o To ensure full delivery of the programme, in time and in budget within the agreed quality parameters; to continually assist in the benefit analysis of the projects
Services Delivery:
o Ensure secure services are implemented in line with the corporate Security Policies & Standards framework
o Operate a security management process (ITIL) within Service Management
o Monitor security incidents, advise on mitigation, report and escalate
o Provide regular reports to the regional IT Management and the Regional Information Security Manager on: the status of security programme deployment using approved metrics and all information security policy violations & exceptions all security incidents
Governance Processes:
o To evaluate and advise on the IT infrastructure change programme initiatives for compliance to security policy and architecture.
o To actively contribute to the global and regional security governance process.
Development of the Function and Personnel:
o To ensure personnel in the retained regional infrastructure security organisation are managed and developed to their full potential in their functional skill areas as well as in their competencies in accordance with personnel development guidelines.
Technical Skills:
The primary skill set for this role is in the realm of Technology Risk Management therefore requires experience in the deployment and subsequent management of large-scale IT risk management processes and products.
Able to rapidly determine key issues within IT systems and business applications with regard to information risks and their mitigation
Establishes continuous process for IT risk management and compliance monitoring across the organisation
Establishes target risk profiles for IT Operations within the overall corporate context
Able to articulate the relevance of information security policies, standards and baselines to technology and business process owners