Enable job alerts via email!

Senior System Risk Officer

Saudi Networkers Services (SNS Group)

Riyadh

On-site

SAR 200,000 - 300,000

Full time

Today
Be an early applicant

Job summary

A leading IT services company in Riyadh is looking for a qualified IT Risk Manager to assist in developing and implementing an IT Risk Management Framework. The ideal candidate will have over 5 years of experience in risk assessments, particularly in the financial sector, and possess strong analytical skills. Knowledge of IT security frameworks and relevant certifications will be advantageous.

Qualifications

  • 5+ years in IT risk management, specifically in risk assessments and control testing.
  • Experience in financial systems and technology evaluations.
  • Knowledge of ISO and ISACA’s IT Risk Management frameworks.

Responsibilities

  • Assist in developing and implementing the IT Risk Management Framework.
  • Conduct risk assessments for IT projects and systems.
  • Review and assess third-party technology vendors.

Skills

Risk assessment
Analytical skills
Communication
IT Risk Management Framework

Education

IT/Business graduate
Certifications (CRISC, CISM, CISSP, CISA)
Job description
Responsibilities
  • Assist the systems risk unit manager in the development and implementation of the IT Risk Management Framework.
  • Ensure technology controls are sufficiently protecting business risk, through the application of the Technology Risk & Control framework.
  • Assess the various information technology risks that the business faces in its operations and implement action plans, policy and procedural changes for risk avoidance and mitigation.
  • Identify risk associated with the use, ownership, operation, involvement, influence and adoption of IT in the organization.
  • Conduct in-depth information technology risk assessments including identifying and documenting controls, creating detailed process flows, identifying potential gaps and/or inconsistencies and making sound recommendations for improvement and/or mitigation.
  • Track action steps and ensure that findings are mitigated appropriately and in a timely manner.
  • Conduct readiness reviews over large information technology development projects ensuring appropriate systems development lifecycle methodologies are being applied and followed.
  • Participate and provide IT risk related feedback and inputs during the selection of new technologies, products and vendors.
  • Review third party technology vendors and contracts to ensure appropriate controls are in place and functioning effectively.
  • Conduct risk assessment for IT projects and application selection.
Qualifications
  • Hands on experience in application of the Technology Risk & Control framework.
  • Overall experience of 5 years at least in the related areas. Specifically experience in
    a. Performing risk assessments, control testing/analysis of financial and e-commerce systems for at least 2 years
    b. Performing risk assessments of new system or technology acquisition and various types of SDLC projects for at least 2 years
    c. Analysis of incidents and system changes from risk perspective and related recommendations & reporting
    d. Identifying key motivators for Risk Assessment needs
    e. IT Asset classification, characterization and prioritization
    f. Handling scheduled and unscheduled assignments
    g. Preparation of IT Risk Management policies, procedures in compliance with regulatory needs and international best practices
    h. Continuous risk monitoring of IT assets and reporting to System Risk manager
    i. Communicating with various business and IT teams in order to discuss identified risks, finalize assessment reports and control recommendations
  • Understanding of banking industry
  • Knowledge and understanding of technologies and systems used in the financial sector / banks
  • Knowledge of core banking systems, such as T24 and others.
  • Understanding of Information Security frameworks will be added advantage
  • Significant analytical and critical thinking skills.
  • An IT/Business graduate, related certifications CRISC, CISM, CISSP, CISA etc. will be a plus
  • Understanding of the COSO internal controls framework, ISO and ISACA’s IT Risk Management frameworks
About The Company

Saudi Networkers Services founded in late 2001, SNS was initially established as a joint venture between Networkers International (Networkers MSB) a UK based company and Saudi Networkers Services a Saudi based company.

  • SNS has more than 1,600 employees across the MENA region.
  • SNS is an ISO 9001 certified company.
  • SNS reaches 380 Contractors till the moment in KSA Only.
  • Extensive database 70,000+ Active professional candidates.
  • Experienced in our field with more than 8 years of doing such a business.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.