Job Purpose: 

The role holder will be responsible for defining and running the service management framework of the Group Information Security organization in order to ensure optimal performance of the Information Security function. The role holder will establish the measuring, monitoring and reporting standards for Information Security services and establish robust internal & external stakeholder engagement.

Job Responsibilities/ Accountabilities:

  • Define a security service assurance model for Group Information Security services
  • Develop and establish service standards for services offered by Group Information Security to technical and business stakeholders
  • Develop metrics and monitoring thresholds and reporting for the Group Information Security function. This includes people functions, projects, internal services, vendors, operations etc.
  • Define a GIS reporting framework for Group and Subsidiaries, relevant to various stakeholders and governance committees, including but not limited to Board, Exco, MDs of Subsidiaries, CIOs and Business Unit Heads, business and operational teams.
  • Measure, track and report on performance of programme delivery, projects and roadmap activities delivered by Group Information Security teams (Cyber Defence Operations, Enterprise Security Architecture)
  • Define SLAs (Service Level Agreements) for services offered by Group Information Security and by outsourced suppliers, and manage and report on SLA achievement
  • Work with the Group Information Security teams to define and measure their process outputs and establish regular reporting of the same.
  • Develop and provide regular reports on the effectiveness of Group Information Security management to Senior Management and manage and track the outcomes related to security.
  • Setup and manage internal and external stakeholder forums & meetings for deliberation on service outcomes, and track the outcomes.
  • Track and monitor vendor and partner service deliverables and SLAs, and report on deviations to agreed service levels.
  • Conduct regular benchmarking with industry peers on service standards, for improvements and adoption within the Bank
  • Group Information Service management across at least 13 domains in all the Technology functions and in at least 7 markets of Equity Group

Qualifications

Knowledge and Experience

  • Bachelor’s Degree in Information Technology, Information Security, Engineering or similar area of study
  • Hold relevant industry certifications (ISO 27001, ITIL etc.)
  • Minimum 6 years of experience in Information Technology.
  • Knowledge of information security operations and concepts such as cyber-attacks and techniques, threat vectors, risk management, incident management etc.
  • Experience with industry standard frameworks (ISO 27000, ITIL, NIST, PCI DSS).
  • Experience in project & vendor management
  • Ability to effectively provide briefings to business and technical stakeholders on Information Security performance

Key Critical Competencies

  • Excellent in preparation of reports, dashboards and documentation
  • Excellent communication and leadership skills
  • Ability to handle high pressure situations with key stakeholders
  • Good analytical skills; ability to provide intuitive reports & dashboards from a variety of data sources.
  • Good problem solving and Interpersonal skills
  • Good knowledge of Bank’s infrastructure, networks and systems

Follow Us on Social Media