hireejobsgulf

Analyst (Information Security), Information Security Office

1.00 to 10.00 Years   Pakistan   18 Aug, 2022
Job LocationPakistan
EducationNot Mentioned
SalaryNot Mentioned
IndustryOther Business Support Services
Functional AreaNot Mentioned

Job Description

Entity: Aga Khan UniversityLocation: KarachiIntroduction to the Aga Khan University: The Aga Khan University is a private, international university committed to international standards of excellence in teaching, research and service. Its teaching hospital, the Aga Khan University Hospital has been accredited by the prestigious Joint Commission International for achieving the highest international healthcare standards.Job Role / Responsibilities:Reporting to the Manager, AKU Global InformationSecurity you will be responsible to assist in managing the global information security and to protect AKU?s enterprise infrastructure, information and business continuity globally through strong and effective security practices. You would also need to ensure that adequate and effective security processes and controls are followed and aligned to deliver compliance with security policy and regulatory requirements of each region.Specifically, you will be responsible for;

  • assisting in preparation, assessment and enforcement of information security policies, standards, guidelines and procedures to ensure ongoing maintenance of security for all campuses
  • performing technology and information security risk assessments
  • performing IS policy and procedures gap assessments against information security, regulatory requirements and governance standards. For example ISO27001:2013, COBIT, PCI-DSS etc
  • ensuringthat information security policy and relevant procedures are updated, reviewed and approved by the management at the defined frequency
  • liaisingwith IT and internal/external audit teams during information systems audit. Work as a central point of contact from IT to ensure appropriate flow of information to audit team with any delay
  • working with IT team for successful closure of the audit observations for all campuses
  • performing internal assessments and identifyinggaps in current documentation and operations. Working with IT teams to fix these gaps
  • working closely with internal audit department to ensure information security requirements are incorporated in organizational policies and procedures
  • preparinginformation awareness and training material and assist in organizing information security trainings and campaigns for AKU staff
  • actively participatingin the Security Incident Response Team (SIRT)
  • performing and maintaining information/data classification policy and procedure
  • educatingIT and business users and ensuringall critical information assets are classified properly
  • reviewing audit logs for critical applications, databases, OS and networks
  • participatingin planning and implementation of AKU-wide security awareness and education programs that are aligned with global security policy, standards, regulatory requirements, and industry practices
  • working with other departments such as internal audit and vendors to supervise AKU-wide information security requirements are incorporated into the rollout of new systems.
Eligibility Criteria / Requirements:
  • Bachelor?s degree or equivalent in Computer Science, Computer Engineering, Information Security or related field. Advance degree highly preferred
  • at least five (5) years of hands-on experience in Information Security risk assessments, policies and procedures, information systems audit, regulatory compliance etc
  • relevant certifications e.g. CISA, CISM, CISSP etc. would be a plus
  • Knowledge of Information Security and IT standards including but not limited to ISO 27001, COBIT, HIPAA, NIST, ITIL etc
  • ensure all IT and Information Security programs and policies are in compliance with applicable privacy and identity theft laws and other regulations
  • knowledge and experience of preparing business continuity plan and IT disaster recovery plan
  • ability to work with third party firms and consultants to conduct independent security audits
  • experience in any Big 4 professional services firm would be a plus
  • ability to perform risk assessments, critical practice assessments and identify information security weaknesses and/or gaps in the current operations is a must
  • understands the business activities performed by AKU, and based on this understanding, suggests appropriate information security solutions that adequately protect these activities AKU- wide.

Keyskills :

APPLY NOW

Related Jobs

© 2023 HireeJobsGulf All Rights Reserved