Job Description
Job Identification: 617
Duties & Responsibilities
- Managing relationships with third parties (vendors, suppliers, contractors, partners, etc.).
- Managing relationships with external stakeholders.
- Managing the employment lifecycle and performance of personnel in accordance with security policies and requirements (background checks, succession planning, disciplinary action, termination, etc.).
- Managing the knowledge, skills, capabilities, and availability of the information security team.
- Implementing an enterprise-wide, role-based information security awareness and training program.
- Defining, implementing, and enforcing the acceptable use policy.
- Prepare to convert strategic vision into actionable tasks and drive those tasks to completion.
- Information security policy and procedure development and maintenance.
- Oversight of annual security awareness training and role-based security training processes.
- Oversight with an eye on compliance and risk management for mission/business processes.
- Building a Security Governance Structure.
- Internal security and privacy control testing or operational auditing.
- Overall Information Security Governance.
- Quality assurance reviews.
- Review compliance and risk management for mission/business processes within the department.
- Hotline/helpline oversight on security events.
- Develop and maintain system security plans.
- Prepare to convert strategic vision into actionable tasks and drive those tasks to completion.
- Communicate and maintain leadership directives to the Information Security Operations Department.
- Provide key insight to overall security strategies and evaluate organizational progress towards agreed upon goals and find solution to complex issues in order to maintain timelines and achieve project success.
Job Requirements
Education:
- Minimum Education: First Degree in Computer Science / Engineering
Experience
- Minimum experience - 10 years working knowledge in Information Technology/Information Security. Higher Degrees/Professional Certificates.
- Working knowledge of PCI DSS.
- Working knowledge of ISO 27001.
- Information Security Standards, security architecture and practices.
- Good knowledge of network security and encryption models.