Ciso
CurrentAs the CISO of the bank, my responsibility is securing the bank's information assets and systems and acting as an internal infosec consultant, providing guidance on security matters to various business units. My duties are extensive and involve:• Developing and maintaining information security policies, procedures, and guidelines that align with industry best practices and regulatory requirements.• Establishing and executing a security risk management program by identifying potential risks, threats, and vulnerabilities to the bank's information assets and systems and creating strategies to mitigate them.• Defining the controls required to secure information assets based on their asset value and classification levels. Establishing oversight of the security infrastructure, evaluate, maintain, and monitor security systems, physical controls, and other security controls to ensure they are effective and compliant with internal security policies, regulatory requirements, and industry best practices.• Executing compliance testing and security assessment programs to ensure that the bank's security controls are effective and compliant with internal security policies, regulatory requirements, and industry best practices.• Developing and executing security awareness programs to educate bank employees on security best practices and promote a security-conscious culture.• Providing support for security issues to the various business units to ensure that their security requirements are met.• Overseeing security issues in contracts and business partner relationships and ensuring that security requirements are included in contract and agreement provisions.• Coordinating for the development, management, and execution of the security incident and compliance response process to ensure that security incidents are handled promptly and effectively.• Supporting the implementation of the bank's disaster recovery plan and conducting testing to ensure that it is effective.