Information Security Officer at Virtu Thinko

Virtu Thinko

Manama

Hybrid

BHD 5,600 - 8,900

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Virtu Thinko is seeking an information security and risk management professional to implement and maintain security controls across the IT infrastructure in Bahrain. The role includes conducting security audits, risk assessments, and ensuring compliance with PDPL and related standards.

The candidate will drive ISO 27001 alignment, staff training, and incident response coordination. Responsibilities cover advisory, training, and regulatory interactions, with a focus on reducing operational risk

Qualifications

  • Experience implementing information security controls across IT infrastructure.
  • Familiar with risk assessment programs and audits.
  • Knowledge of Bahrain PDPL and data protection requirements.

Responsibilities

  • Assist in implementing and maintaining information security controls across IT infrastructure.
  • Conduct security audits and risk assessments.
  • Lead ISO 27001 compliance initiatives and regulatory reviews.
  • Provide expert risk management guidance to management and staff.
  • Coordinate with regulators and internal stakeholders on security and compliance.

Skills

Information security
Risk assessment
Regulatory compliance
Security auditing
Incident response
Data privacy

Tools

HSM
Vulnerability scanning
Security monitoring

Job description

This Full time on site position offers great opportunities for career growth.

1. Role Purpose

To assist in implementing and maintaining the required and internationally accepted standard of information security controls across the company's IT infrastructure. To conduct the security audits and risk assessment program, and review compliance with the information security policies and associated procedures. To handle the development, implementation, operation, maintenance, and support of information security policies, standards, guidelines, and procedures that enhance the level of security over the business's information assets, and reduce the probability of loss. To handle the requirements of the Bahrain Personal Data Protection Law (PDPL). In addition, the role holder will be responsible for implementing and monitoring adherence to the company's operational risk management strategy and business objectives, and for ensuring that operational risk issues are identified and escalated to the appropriate level for consideration and approval.

2. Operational Risk Management
  • Establish the required policies and procedures to manage operational risks.
  • Establish and roll out the risk control self-assessment and key risk indicator framework.
  • Handle the implementation of the operational risk management framework across the company in order to reduce the company's operational risk exposure.
3. Information Security Management
  • Establish the required policies and procedures to manage the information security framework.
  • Enforce the information security policies, procedures, controls, and standards.
  • Assist in the development and implementation of information security policies and procedures.
  • Lead ISO 27001 compliance, ensuring year-round task completion by respective stakeholders.
  • Assist in information security training and oversight for company employees.
  • Handle information security risk assessments and security audits.
  • Monitor compliance with information security policies and procedures, referring problems to the appropriate department manager.
  • Monitor internal control systems to ensure that appropriate access levels are maintained.
4. Advisory, Training & Awareness
  • Provide expert advice on all aspects of information security and risk management to the management and staff of the company.
  • Educate employees on information security and risk management matters, including the criticality of compliance with information security program requirements.
  • Maintain awareness of changes in security risks, security measures, and computer systems.
  • Conduct periodic operational risk and information security training for new and existing staff (at least annually).
  • Perform quarterly Operational Risk training for new joiners.
  • Assume responsibility as project leader for special projects and provide valuable insights to the management.
  • Assist and participate in special projects concerning information security, including testing and implementation of security software enhancements.
  • Maintain a broad knowledge of state-of-the-art technology, equipment, and/or systems.
5. Regulatory & Compliance
  • Handle the requirements of the Bahrain Personal Data Protection Law (PDPL) and coordinate with other heads of department to ensure full compliance.
  • Assist in annual audit reviews by payment associations such as PCI DSS, PCI PIN, PCI 3DS, ISO 27001, client-related audits, and other regulatory bodies.
  • Evaluate the effectiveness of controls and measure whether they are meeting the standards and processes laid down by financial, regulatory, and other bodies.
  • Assist in reviewing the potential risk exposure before the launch of new products/services.
  • Assist in reviewing third-party contracts as and when requested.
6. Incident Response & Technical Security Operations
  • Assist in monitoring the disaster recovery plan and contingency planning.
  • Assist in the coordination of the handling and resolution of security breach incidents, including system intrusions and abuse; act as the primary point of contact for external law enforcement entities.
  • Investigate and identify solutions to viral infestation and damage, administer antiviral programs, and work with platform experts to coordinate the support of virus protection software for common platforms in use across the company.
  • Review, update, and enforce data security practices within the central computing centre shared-system environments; test for exposures to ensure adherence to guidelines and procedures, and work with platform experts to implement remedial measures as appropriate.
  • Maintain inventory of the company's Hardware Security Module (HSM) system keys in accordance with regulatory requirements.
  • Administer the access control procedures for designated IT applications, systems, and network infrastructure.
  • Configure log sources such as systems and databases. Monitor to ensure that audit logs record user activities, exceptions, and information security events, and are kept for an agreed period of time. Monitor to ensure that the proper security settings regarding the capture and storage of events are in compliance with incident reporting procedures.
  • Assist the department head in conducting regular internal and external network and system vulnerability assessments, and provide System Administrators with reports.
  • Assist the department head in the security scan activities and coordinate with vendors and internal stakeholders to reach a compliance status.
  • Assist the department head in the development of system configuration baselines. Monitor changes to the IT baselines and provide reporting on unauthorized changes.
  • Monitor the network for intrusion and hacking activities. Work with antivirus and intrusion prevention software to analyze logs for issues and perform investigation.
  • Assist in performing quarterly reviews of access control and ensure re-certification is conducted for all units.
  • Handle the security architecture for the company's current and future projects (e.g. network architecture, server OS architecture, application architecture, cloud architecture, etc.).
7. Risk Management
  • Ensure that the cyber-risk framework is implemented.
  • Act as Business Unit Operational Risk Supervisor (BU ORS) and liaise with external parties on all matters related to risk management.
  • Assist in identifying and evaluating operational and IT risks for the company.
  • Assist in identifying risks and calculating likely impact and probability.
  • Assist in developing and overseeing the implementation of risk mitigation strategies.
  • Participate in the Business Continuity (BC) committee, including BCP testing.
  • Review Risk Management Self-Assessment plans and provide commentary on operational risk issues to the assigned units.

Pay: BD500.000 - BD800.000 per month

Work Location: In person

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security & Operational Risk Officer
Information Security & Operational Risk Officer

Virtuthinko • Manama

On-site
BHD 12,000 - 24,000
InfoSec Lead: ISO 27001 & PDPL Compliance
InfoSec Lead: ISO 27001 & PDPL Compliance

Virtu Thinko • Manama

Hybrid
BHD 5,600 - 8,900
Information Security & Operational Risk Leader
Information Security & Operational Risk Leader

Virtuthinko • Manama

On-site
BHD 12,000 - 24,000
Network Security Specialist
Network Security Specialist

Batelco by Beyon • Northern Governorate

On-site
BHD 24,000 - 36,000
Data Privacy and Cyber Security Specialist at FinDigit
Data Privacy and Cyber Security Specialist at FinDigit

FinDigit • Manama

On-site
BHD 3,900 - 7,800
Senior Security Officer
Senior Security Officer

Tanqeeb • Manama

On-site
BHD 18,000 - 28,000
IT System Administrator and Cyber Security Consultant
IT System Administrator and Cyber Security Consultant

Ansi Recruitment & Outsourcing • Manama

Hybrid
BHD 18,000 - 30,000
IT Security Specialist - Network & Incident Response
IT Security Specialist - Network & Incident Response

Vinirma Consulting Pvt Ltd. • Awali

On-site
BHD 1,500 - 2,500
IT Security Professional
IT Security Professional

Vinirma Consulting Pvt Ltd. • Awali

On-site
BHD 1,500 - 2,500
Financial Analyst at Virtu Thinko
Financial Analyst at Virtu Thinko

Virtu Thinko • Manama

On-site
BHD 8,900 - 13,000