Information Security Consultant
CurrentGRC Expert at Oman Arab BankConduct Risk Assessments: Lead comprehensive risk assessments to identify, evaluate, and prioritize risks, ensuring that effective controls are in place to mitigate critical business vulnerabilities.Develop and Implement Compliance Programs: Create and enforce compliance programs that align with regulatory standards and industry best practices, ensuring continuous adherence and minimizing compliance risks.Design Governance Frameworks: Establish governance frameworks to guide decision-making, improve accountability, and foster a culture of risk-awareness and compliance within the organization.Policy and Procedure Development: Develop, review, and update policies and procedures to ensure consistency, regulatory compliance, and alignment with organizational objectives.Internal Audits and Control Testing: Conduct audits and control testing to assess the effectiveness of internal processes and identify areas for improvement, thereby strengthening internal controls.Risk Mitigation and Incident Response Planning: Design and implement risk mitigation strategies, including incident response plans, to prepare for and minimize the impact of potential security incidents.Regulatory Change Management: Monitor and respond to regulatory changes, updating organizational policies and practices as needed to maintain compliance with evolving legal requirements.Training and Awareness Programs: Lead training and awareness programs to educate employees on risk management, compliance responsibilities, and best practices for maintaining a secure and compliant environment.Data Privacy and Protection Compliance: Ensure data protection and privacy compliance, particularly with GDPR, CCPA, or other applicable regulations.Vendor Risk Management: Evaluate and manage third-party risks by conducting vendor risk assessments, ensuring they adhere to organizational policies and regulatory requirements to protect against external threats.