Information Security & Operational Risk Officer

Virtuthinko

Manama

On-site

BHD 12,000 - 24,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Virtuthinko, Manama, Bahrain, seeks an information security and risk management professional to implement and maintain security controls across the IT infrastructure. Responsibilities include risk management, PDPL compliance, and incident response coordination.

The role focuses on developing security policies, conducting audits, and ensuring regulatory compliance with PDPL while aligning with the company’s risk management strategy.

Responsibilities

  • Establish policies and procedures to manage operational risks.
  • Roll out risk control self-assessment and key risk indicators.
  • Implement risk management framework to reduce risk exposure.
  • Establish and enforce information security framework policies and controls.
  • Lead ISO 27001 compliance and monitor year-round task completion.
  • Provide information security training and oversight for staff.
  • Monitor compliance with security policies and procedures.

Job description

To assist in implementing and maintaining the required and internationally accepted standard of information security controls across the company's IT infrastructure. To conduct the security audits and risk assessment program, and review compliance with the information security policies and associated procedures. To handle the development, implementation, operation, maintenance, and support of information security policies, standards, guidelines, and procedures that enhance the level of security over the business's information assets, and reduce the probability of loss. To handle the requirements of the Bahrain Personal Data Protection Law (PDPL). In addition, the role holder will be responsible for implementing and monitoring adherence to the company's operational risk management strategy and business objectives, and for ensuring that operational risk issues are identified and escalated to the appropriate level for consideration and approval.

Responsibilities
1. Operational Risk Management
  • Establish the required policies and procedures to manage operational risks.
  • Establish and roll out the risk control self-assessment and key risk indicator framework.
  • Handle the implementation of the operational risk management framework across the company in order to reduce the company's operational risk exposure.
2. Information Security Management
  • Establish the required policies and procedures to manage the information security framework.
  • Enforce the information security policies, procedures, controls, and standards.
  • Assist in the development and implementation of information security policies and procedures.
  • Lead ISO 27001 compliance, ensuring year-round task completion by respective stakeholders.
  • Assist in information security training and oversight for company employees.
  • Handle information security risk assessments and security audits.
  • Monitor compliance with information security policies and procedures, referring problems to the appropriate department manager.
  • Monitor internal control systems to ensure that appropriate access levels are maintained.
3. Advisory, Training & Awareness
  • Provide expert advice on all aspects of information security and risk management to the management and staff of the company.
  • Educate employees on information security and risk management matters, including the criticality of compliance with information security program requirements.
  • Maintain awareness of changes in security risks, security measures, and computer systems.
  • Conduct periodic operational risk and information security training for new and existing staff (at least annually).
  • Perform quarterly Operational Risk training for new joiners.
  • Assume responsibility as project leader for special projects and provide valuable insights to the management.
  • Assist and participate in special projects concerning information security, including testing and implementation of security software enhancements.
  • Maintain a broad knowledge of state-of-the-art technology, equipment, and/or systems.
4. Regulatory & Compliance
  • Handle the requirements of the Bahrain Personal Data Protection Law (PDPL) and coordinate with other heads of department to ensure full compliance.
  • Assist in annual audit reviews by payment associations such as PCI DSS, PCI PIN, PCI 3DS, ISO 27001, client-related audits, and other regulatory bodies.
  • Evaluate the effectiveness of controls and measure whether they are meeting the standards and processes laid down by financial, regulatory, and other bodies.
  • Assist in reviewing the potential risk exposure before the launch of new products/services.
  • Assist in reviewing third-party contracts as and when requested.
5. Incident Response & Technical Security Operations
  • Assist in monitoring the disaster recovery plan and contingency planning.
  • Assist in the coordination of the handling and resolution of security breach incidents, including system intrusions and abuse; act as the primary point of contact for external law enforcement entities.
  • Investigate and identify solutions to viral infestation and damage, administer antiviral programs, and work with platform experts to coordinate the support of virus protection software for common platforms in use across the company.
  • Review, update, and enforce data security practices within the central computing centre shared-system environments; test for exposures to ensure adherence to guidelines and procedures, and work with platform experts to implement remedial measures as appropriate.
  • Maintain inventory of the company's Hardware Security Module (HSM) system keys in accordance with regulatory requirements.
  • Administer the access control procedures for designated IT applications, systems, and network infrastructure.
  • Configure log sources such as systems and databases. Monitor to ensure that audit logs record user activities, exceptions, and information security events, and are kept for an agreed period of time. Monitor to ensure that the proper security settings regarding the capture and storage of events are in compliance with incident reporting procedures.
  • Assist the department head in conducting regular internal and external network and system vulnerability assessments, and provide System Administrators with reports.
  • Assist the department head in the security scan activities and coordinate with vendors and internal stakeholders to reach a compliance status.
  • Assist the department head in the development of system configuration baselines. Monitor changes to the IT baselines and provide reporting on unauthorized changes.
  • Monitor the network for intrusion and hacking activities. Work with antivirus and intrusion prevention software to analyze logs for issues and perform investigation.
  • Assist in performing quarterly reviews of access control and ensure re-certification is conducted for all units.
  • Handle the security architecture for the company's current and future projects (e.g. network architecture, server OS architecture, application architecture, cloud architecture, etc.).
6. Risk Management
  • Ensure that the cyber-risk framework is implemented.
  • Act as Business Unit Operational Risk Supervisor (BU ORS) and liaise with external parties on all matters related to risk management.
  • Assist in identifying and evaluating operational and IT risks for the company.
  • Assist in identifying risks and calculating likely impact and probability.
  • Assist in developing and overseeing the implementation of risk mitigation strategies.
  • Participate in the Business Continuity (BC) committee, including BCP testing.
  • Review Risk Management Self-Assessment plans and provide commentary on operational risk issues to the assigned units.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Officer at Virtu Thinko
Information Security Officer at Virtu Thinko

Virtu Thinko • Manama

Hybrid
BHD 5,600 - 8,900
Senior Security Officer
Senior Security Officer

Tanqeeb • Manama

On-site
BHD 18,000 - 28,000
Information Security & Operational Risk Leader
Information Security & Operational Risk Leader

Virtuthinko • Manama

On-site
BHD 12,000 - 24,000
Network Security Specialist
Network Security Specialist

Batelco by Beyon • Northern Governorate

On-site
BHD 24,000 - 36,000
InfoSec Lead: ISO 27001 & PDPL Compliance
InfoSec Lead: ISO 27001 & PDPL Compliance

Virtu Thinko • Manama

Hybrid
BHD 5,600 - 8,900
Auditor - Treasury & Financial Markets and Risk Management
Auditor - Treasury & Financial Markets and Risk Management

International Association of Insurance Professionals (IAIP) • Manama

On-site
BHD 12,000 - 18,000
Auditor - Treasury & Financial Markets and Risk Management
Auditor - Treasury & Financial Markets and Risk Management

NACBA • Manama

On-site
BHD 90,000 - 120,000
HR Business Partner
HR Business Partner

Havelock One • Askar

On-site
BHD 23,000 - 34,000
IT System Administrator and Cyber Security Consultant
IT System Administrator and Cyber Security Consultant

Ansi Recruitment & Outsourcing • Manama

Hybrid
BHD 18,000 - 30,000
IT COMPLIANCE & RISK
IT COMPLIANCE & RISK

Minds United • Manama

On-site
BHD 50,000 - 80,000