Enable job alerts via email!

IS Governance Analyst

Sadara Chemical Company

Saudi Arabia

On-site

SAR 200,000 - 300,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled Information Security professional to enhance their IT department's governance and risk management strategies. This role involves developing comprehensive Information Security policies, conducting risk assessments, and ensuring compliance with industry standards. The ideal candidate will have a Bachelor's degree in a relevant field and a minimum of three years of experience in Information Security. Join a forward-thinking company where you can make a significant impact on the organization's security culture and practices.

Qualifications

  • Bachelor's degree in a relevant field is essential.
  • 3 years of experience in Information Security roles.

Responsibilities

  • Develop IT/OT governance framework and Information Security policies.
  • Conduct Business Impact Analysis and manage risk assessments.
  • Ensure compliance with Information Security regulations.

Skills

Information Security Governance
Risk Management
Compliance
Information Security Policies
Business Impact Analysis

Education

Bachelor degree in Computer Science
Bachelor degree in Computer Engineering
Bachelor degree in Information Management Systems

Job description

Duties:

Job Purpose:

Provide technical and professional expertise to the IT department and other Sadara Business Functions for Information Security Governance, Strategy planning for Information Security (IS) enterprise wide, Information Security Risk Management and Compliance with Rules, Regulations and business requirements with associated enforcement and Information Security Awareness to assure defined secure level of Information Security behaviors in Sadara culture is achieved.

Functional Duties:

  1. Develop Information Technology (IT)/ Operation Technology (OT) governance framework from Information Security Management System perspective.
  2. Develop Information Security Policies, Guidelines and Standards.
  3. Develop Information Security Processes, Standard Operation Procedures (SOPs) and Minimum Security Baselines (MSBs).
  4. Alignment with policies and requirements from IT and the business, industry standards and best practices for both IT and OT.
  5. Develop, Implement and monitor Risk Management Methodology.
  6. Conduct Business Impact Analysis (BIA) and build Risk Register.
  7. Identify, analyze and provide recommendations on risk landscape, risk posture and mitigation plans.
  8. Evaluate and review business solutions/services from Information Security perspective.
  9. Participate in Change Management Advisory Board (CAB) meetings to review and reflect on Information Security Compliance for all changes (Normal and Urgent).
  10. Provide Information Security requirements and assure related rules and regulations compliance for systems/services acquisitions, development and maintained.
  11. Develop, Implement and verify effectiveness of Information Security Awareness programs and campaigns.
  12. Managements of Information Security Projects.
  13. Perform job related activities requested by line supervisors/manager.

Managerial Duties:

N/A

Education:

Essential: Bachelor degree in Computer Science, Computer Engineering or Information Management Systems.

Certification:

Years of Experience: 3

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.