VACANCY ANNOUNCEMENT
Internal /External
Job title : Information Security Risk Officer
Department : Information Security
Reporting Line : Chief Information Security Officer
Location : Douala
Number of Position : 01
Roles & Responsibilities
- 1. Provide highly skilled, specialist services to produce security risk management policies, framework in line with industry standards.
- 2. Identify and build processes for risk identification, registration and tracking for remediation.
- 3. Review current business processes and technological processes to ensure security requirements are embedded as part of business as usual activity.
- 4. Quantify identified risks and associated impacts and ensure prioritization of risk remediation program.
- 5. Ensuring security compliance to industry mandated standard and regulatory requirements through periodic assessment on information assets to minimize risks in UBA and across subsidiaries.
- 6. Conduct training for in-country information security heads on security risk assessment methodology, 3rd party assessment and processes, policy waivers etc.
- 7. Develop and maintain an executive centralized risk dashboard for group, Regional and subsidiaries reporting for all medium to high risk. Heat Maps, Top Risk trend etc.
- 8. Reviewing the payment infrastructure technology infrastructure and identifying where critical gaps exist and recommend remediation actions.
- 9. Perform internal risk assessment as part of Swift CSP and that of payment systems on payment infrastructure i.e. Cardholder environment as per PCI-DSS mandatory requirement.
- 10. Perform internal risk assessment based on ISO 27001 mandatory requirement standards yearly to ensure compliance and maintain certification.
- 11. Perform maturity assessment based on industry standards on security compliance standards
- 12. To serve as subject matter expert on issues relating to Information Security risks
- 13. Delegate, Empower, Motivate and develop subordinate team members/staff
- 14. Manage Policy waivers by following up on all waiver requests to an acceptable conclusion.
- 15. Responsible for providing work around controls to compensate for granted policy waivers.
- 16. Championing the course of information security awareness for staff as and customers across the group
- 17. Responsible for conducting 3rd Party security due diligence to ensure UBA’s security policies and standards are met by all suppliers across the UBA group.
- 18. Develop appropriate metrics for measuring the effectiveness of the risk management program in achieving the acceptable risk and impact levels.
- 19. Mature the information security risk management function.
Knowledge & Skills
- ▪️ Information Security and Risk Management
- ▪️ Information Security Awareness
- ▪️ Knowledge of payment products and their dependencies
- ▪️ Knowledge of Information security audit and review
- ▪️ Knowledge of Data Communications
- ▪️ Knowledge of Incident response and control
- ▪️ In-depth use of Security Assessment tools
- ▪️ IS security Product Knowledge
- ▪️ Knowledge of Cryptography
- ▪️ PCI DSS controls. SWIFT CSP, ISO Standards
- ▪️ Ability to work in a Multicultural Environment
- ▪️ Proven track record of achieving results and managing teams.
- ▪️ Ability to build rapport with Senior Executives and Cluster/Regional Managers
- ▪️ Constructively manage all stakeholders and break barriers
- ▪️ Ability to build and lead effective and successful teams
- ▪️ Analytical thinker combined with skills of thinking outside the box
- ▪️ Ability to effectively use technology to leapfrog the competition
- ▪️ Withstanding pressure without it having effect on efficiency or quality
- ▪️ Open to change and ability to create and drive change
- ▪️ Ability to deal with ambiguity and a changing environment
- ▪️ Strong analytical and diagnostic skills
Qualification
- ▪️ Bachelor’s Degree in Computer Science, System Engineering or Application Engineering
- ▪️ Industry Certified Security Professional, Professional Security Certification is preferred (e.g., CISSP, CISA, ISO-27001 LI/LA, etc.), PCI DSS and ISO 2700x, SWIFT CSP
- ▪️ Relevant Security Experience, at least 05 years in Risk Assessment, Remediation and Compliance.
- ▪️ Project Management Experience
Application submission
Candidates should send their resume and motivation letter to hcmrecruitcameroon@ubagroup.com, with the heading “Information Security Risk Officer”. Later April 12, 2024
Only shortlisted candidates will be contacted to proceed to the interview stage.
| (c) http://minajobs.net