hireejobsgulf

Senior Analyst- IT GRC Security Risk

1.00 to 10.00 Years   Abu Dhabi, United Arab Emirates   07 Apr, 2022
Job LocationAbu Dhabi, United Arab Emirates
EducationNot Mentioned
SalaryNot Mentioned
IndustryOther Business Support Services
Functional AreaNot Mentioned

Job Description

Company DescriptionReady to join our exciting transformation at the biggest bank in the Middle East? Now is your chance! Bybeing part of our journey here at FAB, you can make a real impact on customers, employees, shareholders and communities.In return, you?ll have everything you need to be part of the #growstronger movement. If you?re looking for a career that willhelp you stand out, kindly apply.

  • Plan, design and implement an overall security and vulnerability risk management process for the organization, along with related technologies.
  • Perform process-level walkthroughs, control testing and reviews for the identification and assessment of IT security risks and controls
  • Effectively communicate key risks, findings, and recommendations for improvement with key stakeholders.
  • Maintain risk register and develop IT Risk Management metrics and reports for consumption by operational, remediation and senior management teams.
  • Monitor remediation progress on internal, external and regulatory audit findings related to IT vulnerabilities
  • Consult the business and IT vulnerability risk owners to develop corrective action plans
  • Drive and/or execute IT and security vulnerability risk governance activities across IT and Information Security functions.
  • Conduct trend analyses to determine cause and impact of security issues, while determining lessons learned and corrective and improvement approaches.
  • Liaise with business, technology, and information security teams to determine corrective and process improvement solutions that do not compromise business needs.
Governance:
  • Advise on the optimization of security and vulnerability risk management processes and practices
  • Provide regular reporting on the progress of security vulnerability risk remediation activities
  • Support the governance of security risk and vulnerability management exceptions
  • Provide remediation progress reports and KPIs/KRIs for specific technology and IT Service Line domains, as well as against regulatory compliance plans
  • Participate in relevant technology compliance project committees (e.g. PCI DSS) to ensure adequate and timely risk governance, reviews, and reporting
Risk management and control:
  • Collaborate with IT Service teams to determine reporting and metrics requirements, while also sharing related information to IT and Information Security Leadership.
  • Review and assesses relevant risk management policies and protocols, suggest recommendations, and implement necessary modifications and improvements.
  • Recommend measures to manage and remediate security vulnerabilities and reduce potential impact to a level within the organization?s risk appetite, and/or in line with related remediation SLAs.
  • Build a strong partnership with technical teams to promote best practices for managing vulnerabilities in an agile manner and within cloud solutions.
  • Support the preparation of risk and vulnerability management dashboards.
  • Support the incident response and architecture review processes whenever security expertise is required.
  • Partner with key technology managers and risk teams to oversee and manage various risk programs across the organization.
Job Context:
  • Availability to work and support teams across different time zones
  • Ability to work with and drive results with remote teams.
  • Understanding of IT and Cloud best practices, methodologies, and regulations.
  • Strong understanding of security vulnerability types, management solutions, and related governance and remediation best practices.
  • Ability to translate security concepts into language that is meaningful to various audiences, including business and technical leaders.
QualificationsQualifications
  • Bachelor?s degree, preferably in Information Technology, Engineering/Computing
  • Professional IT Audit Certification - E.g. CISA, ISO 20000 LA/LI, 27000 LA/LI
  • Professional IT Security Certification ? E.g. CISSP, CISM, ISO 27000 series LA/LI
  • Professional IT Service Management Certification ? E.g. ITIL v3 Expert, ISO20000 LA
Experience
  • 10+ years of experience in IT risk and incident management
  • Prior experience of vulnerability management methodologies and remediation methods
  • Experience in conducting risk assessments
  • Prior experience in the banking sector
  • Prior experience in working with systems such as Archer, Jira, Service Now, or any other IT-GRC and Service Management platform.
  • Prior experience in working with vulnerability management solutions.
Skills
  • Strong stakeholder and people management skills
  • Strong analytical skills with attention to detail
  • Strong time management skills
  • Strong dispute management skills
  • Ability to cope, prioritize and track great workload
  • Good writing, communications & presentation skills
  • Results oriented, driving activities to their closure while coordinating across teams.

Keyskills :

APPLY NOW

Related Jobs

© 2023 HireeJobsGulf All Rights Reserved