Information Security Officer
CurrentEstablished the Information Security governance programme and coordinated the efforts (including the associated budget) directed to the protection of the information assets and compliance with the adopted standards or regulatory requirements. Responsible for the cybersecurity strategy by leveraging technical capabilities, including new technology and threat information, to meet the commitment made by VAKT to its clients and investors.Main Responsibilities:• Design, implement and… Show more Established the Information Security governance programme and coordinated the efforts (including the associated budget) directed to the protection of the information assets and compliance with the adopted standards or regulatory requirements. Responsible for the cybersecurity strategy by leveraging technical capabilities, including new technology and threat information, to meet the commitment made by VAKT to its clients and investors.Main Responsibilities:• Design, implement and review the adoption of IT governance and security standards (Cyber Essential Plus, ISO/IEC 27001:2013, ISO/IEC27017:2015, AICPA SOC II)• Coordinate or assist with security and compliance matters like the implementation of new security tools, Internal/External Auditor engagements and any Information Security legislative/regulation compliance requirement.• Provide security subject matter expertise on projects undertaken by the business and act as an advisor on all business security policy, security strategy and information risk management issues.• Coordinate data privacy assessments or third-party risk assessments, organise internal control reviews and risk assessments to monitor compliance with information security policies and standards.• Work effectively with all teams to coordinate InfoSec changes and to ensure that InfoSec requirements are embedded at an early stage of the business process.• Develop and maintain Security Incident Response Procedures and Data Breach Guidelines. Review and report on security incidents, potential incidents or other security risks and ensure that appropriate correction and preventative measures are implemented.• Work closely with the Dev Leadership to assist with risk remediation and solution design related to dependencies checks, vulnerability scanning and penetration testing of critical assets.• Brief Executive Team on security posture and risks; coordinate and maintain staff information security awareness and cyber security induction program. Show less