Role Objective
The incumbent is responsible for operating and implementing IT security measures for the Bank s security appliances and solutions to control access and prevent unauthorized modification, destruction, or disclosure of confidential information, and maintain integrity and availability of systems and data.
Detailed Roles and Responsibilities:
- Guide the team in Installing, setting, configuring, and maintaining security appliances according to the overall objectives and policies of the Bank.
- Develop plans to safeguard the Bank s security appliances and components against accidental and/or unauthorized modification to data, disclosure of confidential information, and/or data corruption/loss.
- Develop security standards, baselines and procedures for security appliances, security devices and ensure that these standards and baselines are installed on the appliances
- Ensure that security violations are monitored and reviewed by the team which includes SOC alerts, logs and reports on a regular basis. Ensure that these are investigated, escalated to appropriate levels of management as necessary, and correctives actions are taken in a timely manner.
- Continuously assess security threats and vulnerabilities and provide recommendations to mitigate the same by ensuring security policies and procedures and control measures are implemented.
- Execute and implement the Bank s Information Technology policies and procedures, standards, and guidelines related to security of the network and communication software, hardware, and components, as well as monitor adherence to such policies and procedures, standards, and guidelines.
- Ensure that critical data transmissions are encrypted and protected from unauthorized access and/or disruptions.
- Ensure the enforcement of security controls.
- Lead the team during DR exercise and would be responsible for security appliances availability in DR site
- Ensure endpoint protection systems are Implemented, updated, maintained.
- Develop, implement, monitor and maintain network security monitoring tools to help detect security threats and vulnerabilities in a timely manner.
- Ensure high standards of confidentiality to safeguard commercially sensitive information.
- Provide timely and accurate information to the external and internal auditors and the Compliance function as and when required.
COMPETENCIES, KNOWLEDGE AND EXPERIENCE
(Competencies, knowledge, and experience needed for the satisfactory performance of the job)
a. Educational Qualifications:
- Bachelor Degree.
- Degree/Diploma in Information Technology/Security.
- At least one Professional Certification such as CISSP, CCNP etc.
- Security product specialization would be preferable
b. Experience:
- More than 10 years experience in IT Security/Information Security
- Working experience with Financial sector would be an advantage
c. Behavioral Competencies:
- Active listening skills.
- Must be a team leader and a player and should able to work under pressure.
- Ability to influence others and move the team toward a common vision or goal.
- Should be process oriented and customer focus
- Should have good verbal and written communication skills
d. Technical Competencies:
- Network and Security troubleshooting Knowledge
- Security Products Implementation and Administration experience
- Should be able to provide End user support
- Data Analysis
- Knowledge of Disaster Recovery and Business continuity
- Project Management
الهدف الوظيفي
المتولي مسؤول عن تشغيل وتنفيذ إجراءات أمن تكنولوجيا المعلومات لأجهزة وحلول أمان البنك للتحكم في الوصول ومنع التعديل غير المصرح به أو التدمير أو الكشف عن المعلومات السرية، والحفاظ على سلامة وتوافر الأنظمة والبيانات.
الأدوار والمسؤوليات التفصيلية:
- إرشاد الفريق في تثبيت وضبط وتكوين وصيانة أجهزة الأمن وفقاً للأهداف والسياسات العامة للبنك.
- وضع خطط safeguarding أجهزة وأنظمة الأمن للبنك ضد التعديل العرضي و/أو غير المصرح به للبيانات، وكشف المعلومات السرية، و/أو تلف/فقد البيانات.
- تطوير معايير أمان، ونُهج أساسية وإجراءات لأجهزة الأمن، وأجهزة الأمن والتأكد من أن هذه المعايير والخطوط الأساسية مثبتة على الأجهزة
- التأكد من أن الانتهاكات الأمنية مُراقبة ومراجعتها من قبل الفريق بما في ذلك تنبيهات SOC والسجلات والتقارير بشكل منتظم. التأكد من تحقيقها، وتصعيدها إلى المستويات المناسبة من الإدارة عند الضرورة، واتخاذ الإجراءات التصحيحية في الوقت المناسب.
- تقييم مستمر للتهديدات والثغرات الأمنية وتقديم توصيات لتخفيفها من خلال التأكد من تطبيق سياسات وإجراءات وأنظمة التحكم الأمنية.
- تنفيذ وتطبيق سياسات وإجراءات تكنولوجيا المعلومات للبنك والمعايير والإرشادات المتعلقة بأمن الشبكة وبرامج الاتصالات، والأجهزة والمكونات، إضافة إلى متابعة الالتزام بهذه السياسات والإجراءات والمعايير والإرشادات.
- التأكد من أن عمليات النقل البيانات الحرجة مشفرة ومحفوظة من الوصول غير المصرح به و/أو الانقطاعات.
- التأكد من فرض ضوابط الأمن.
- قيادة الفريق أثناء تمرين DR ويكون مسؤولاً عن توفر أجهزة الأمن في موقع DR
- التأكد من تنفيذ وصيانة أنظمة حماية نقاط النهاية.
- تطوير وتنفيذ ومراقبة وصيانة أدوات مراقبة أمان الشبكة للمساعدة في الكشف عن التهديدات والثغرات الأمنية في الوقت المناسب.
- الحفاظ على معايير عالية من السرية لحماية المعلومات الحساسة تجارياً.
- تقديم معلومات دقيقة وفي الوقت المناسب للمدققين الخارجيين والداخليين ووظيفة الامتثال عند الطلب.
الكفاءات والمعرفة والخبرة
(الكفاءات والمعرفة والخبرة اللازمة للأداء المرضي للوظيفة)
a. المؤهلات التعليمية:
- درجة البكالوريوس.
- درجة/دبلوم في تكنولوجيا المعلومات/الأمن.
- شهادة مهنية على الأقل مثل CISSP، CCNP إلخ.
- تخصص في منتجات الأمن يفضل
b. الخبرة:
- أكثر من 10 سنوات خبرة في أمن تكنولوجيا المعلومات/الأمن المعلوماتي
- الخبرة العملية مع القطاع المالي تعتبر ميزة
c. الكفاءات السلوكية:
- مهارات الاستماع النشط.
- لا بد أن يكون قائداً فريقاً ولاعباً وأن يستطيع العمل تحت الضغط.
- القدرة على التأثير في الآخرين وتحريك الفريق نحو رؤية أو هدف مشترك.
- يجب أن يكون موجهاً نحو العملية والتركيز على العميل
- يجب أن يمتلك مهارات اتصال لفظية وكتابية جيدة
d. الكفاءات التقنية:
- معرفة استكشاف أخطاء الشبكة والأمان
- خبرة في تنفيذ وإدارة منتجات الأمان
- يجب أن يكون قادراً على تقديم دعم المستخدم النهائي
- تحليل البيانات
- معرفة التعافي من الكوارث واستمرارية الأعمال
- إدارة المشاريع