- Lead the Information Security Risk Management Framework (ISRMF) aligned with:
- NIST Cybersecurity Framework
- ISO/IEC 27001 / 27005
- Local banking cybersecurity guidelines
- Conduct risk assessments/threat models to identify potential vulnerabilities and threats to the organization’s technology systems and data.
- Review the architecture for new solutions to ensure the security, resilience and compliance requirements for such systems are met.
- Update IT Risk Tracker and NI Heatmap for security risks
- Conduct Technology Thematic reviews as part of the Risk Assurance plan for the company.
- Plan and manage Compliance, Audits, Risk assessments and Information Security Governance.
- Keeping abreast of changes in technology and regulations that may impact the organization’s risk profile.
- finding the best way to secure the IT infrastructure of an organization
- Perform reviews of risk assessment of projects, new or change initiatives, introduction of new products, services or systems and identify potential risks and provide risk mitigating control recommendations using a unified risk assessment standard across Group.
- Escalate and record Items for Management Attention
- Follow up with named stakeholders for known risk issues, ensuring timely closure or escalation where risks cannot be closed.
- Participate in new initiatives (e.g., product, services, solutions, system launches, etc.) to identify risks arising out of changes and recommend for suitable controls and identify, assess, control and monitor risks related to operational nature
|