|
||||||||||||||||||
الوصف الوظيفي Create and maintain Statement of Applicability to determine, document and establish controls of information security required as per ISO 27001 standard for enterprise Injazat. Document information security policies, processes and procedures by assigning ownership, mapping controls to key business areas and objectives and manage the policy development life cycle process by handling policy exceptions. Recommends and influences new or existing information security processes, procedures and methodologies. Responsible to maintain and protect the confidentiality, integrity and availability (CIA) Determines strategic and tactical compensating security controls that are required to Assists in managing and maintaining Injazat Enterprise Business Continuity Management Oversee and assist in monitoring of the organisation IT systems by assessing risks Governance, Risk and Compliance Maintain and manage the Risk Management framework that establishes structure and Reduce the risk of security threats, poor or misaligned security practices and operational Develop and maintain a consolidated catalogue that demonstrates the compliance quotient for all applicable standards and frameworks like ISO and local regulations like Mubadala, NESA, ADSIC and NCEMA Assessments, Audits and Certifications Conducts benchmark exercises by comparing, measuring and documenting the differences between requirements, specifications, frameworks or standards and present practice. Documents and/or reports compliance review results and follows up to ensure preventive Initiate vulnerability assessments periodically as a proactive approach by identifying Conducts high level gap analysis to gauge information security outlook of business units and enterprise environment. Ensure compliance through adequate training and awareness programs and periodic internal Consulting and Professional services Engages with client to assess information security requirements, align to available service offerings or identify re-use opportunities. Identifies and documents where the business requirements match standard offerings, Provides solution consulting to clients, Injazat delivery groups and /or other team members Evaluates the effectiveness, strengths, weaknesses, opportunities and threats of existing infrastructure and applications. Facilitates clients with current statement assessments, gap analysis and implementing المهارات Bachelor’s degree in Computer Science, Information Systems Management or related field. (7-10) years of experience in computing or related area with a focus on technology, management, policy and security. Professional information and IT security certifications such as CISSP/GIAC/SSCP/ CISA/ ISO 27001/ COBIT. Excellent command of English Language and Communication Skills. Strong Planning and Organization Skills. Demonstrated ability to work under pressure, ability to prioritize to ensure positive results of the assigned opportunities. High level of commitment to achieve optimum results. Experience in Microsoft Office تفاصيل الوظيفة https://www.bayt.com/ar/uae/jobs/information-security-professional-senior-uae-national-3841775/ |
||||||||||||||||||