Responsibilities
- Develop, implement, and maintain the organization's Information Security strategy, policies, procedures, and controls.
- Establish and continuously improve the Information Security Management System (ISMS) in accordance with ISO/IEC 27001.
- Ensure compliance with QCB regulations, NCSA requirements, NIST Cybersecurity Framework, PCI DSS, and other applicable regulatory standards.
- Identify, assess, and manage information security and cybersecurity risks and maintain the Information Security Risk Register.
- Conduct and oversee security risk assessments, vulnerability assessments, penetration testing, and control reviews.
- Lead and manage information security incidents, including investigation, response, reporting, and post-incident corrective actions.
- Oversee security monitoring, logging, and cybersecurity controls, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.
- Develop and maintain information security policies, standards, procedures, and security KPIs.
- Manage third-party and vendor security risks, including security assessments and compliance reviews.
- Coordinate internal and external security audits and regulatory examinations.
- Provide regular information security reports, risk updates, KPIs, and recommendations to senior management and the Board.
- Develop and deliver information security awareness and training programs across the organization.
- Ensure information security requirements are incorporated into Business Continuity and Disaster Recovery plans.
- Stay updated on emerging cybersecurity threats, regulatory requirements, and industry best practices.
Desired Candidate Profile
Qualifications
- Bachelor's degree in information security, Cybersecurity, Computer Science, Information Technology, or a related field, master's degree is preferred.
- 10 15 years of experience in IT and Information Security, with 5 7 years in a senior or leadership security role.
- Experience working within financial institutions, banking, or other highly regulated environments.
- Strong knowledge and practical experience with QCB regulations, NCSA requirements, ISO/IEC 27001, PCI DSS, and NIST.
- CISSP certification is mandatory or strongly preferred.
- Additional certifications such as CISM, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, or PCI DSS certifications are an advantage.
- Strong understanding of cybersecurity governance, risk management, compliance, and security controls.
- Hands-on knowledge of enterprise security technologies, including SIEM, EDR/XDR, IAM/PAM, DLP, firewalls, IDS/IPS, and WAF.
- Experience managing security incidents, audits, penetration testing, vulnerability assessments, and third-party security risks.
- Strong leadership, communication, stakeholder management, and presentation skills.
- Ability to communicate effectively with senior management and Board-level stakeholders.
- High level of integrity, independence, analytical thinking, and professional judgment.