Principal Duties and Responsibilities:
- Assist the systems risk unit manager in the development and implementation of the IT Risk Management Framework.
- Ensuring technology controls are sufficiently protecting business risk, through the application of the Technology Risk & Control framework.
- Assess the various information technology risks that the business faces in its operations and implement action plans, policy and procedural changes for risk avoidance and mitigation.
- Identifying risk associated with the use, ownership, operation, involvement, influence and adoption of IT in the organization.
- Conduct in-depth information technology risk assessments including identifying and documenting controls, creating detailed process flows, identifying potential gaps and/or inconsistencies and making sound recommendations for improvement and/or mitigation.
- Track action steps and ensure that findings are mitigated appropriately and in a timely manner.
- Conduct readiness reviews over large information technology development projects ensuring appropriate systems development lifecycle methodologies are being applied and followed.
- Participating and providing IT risk related feedback and inputs during the selection of new technologies, products and vendors.
- Review third party technology vendors and contracts to ensure appropriate controls are in place and functioning effectively.
- Conduct risk assessment for IT projects and application selection.
Minimum Requirements:
- Hands on experience in application of the Technology Risk & Control framework.
- Overall experience of 5 years at least in the related areas. Specifically experience in:
- Performing risk assessments, control testing/analysis of financial and e-commerce systems for at least 2 years.
- Performing risk assessments of new system or technology acquisition and various types of SDLC projects for at least 2 years.
- Analysis of incidents and system changes from risk perspective and related recommendations & reporting.
- Identifying key motivators for Risk Assessment needs.
- IT Asset classification, characterization and prioritization.
- Handling scheduled and unscheduled assignments.
- Preparation of IT Risk Management policies, procedures in compliance with regulatory needs and international best practices.
- Continuous risk monitoring of IT assets and reporting to System Risk manager.
- Communicating with various business and IT teams in order to discuss identified risks, finalize assessment reports and control recommendations.
- Good understanding of banking industry.
- Knowledge and understanding of technologies and systems used in the financial sector / banks.
- Knowledge of core banking systems, such as T24 and others.
- Understanding of Information Security frameworks will be added advantage.
- Significant analytical and critical thinking skills.
- An IT/Business graduate, related certifications CRISC, CISM, CISSP, CISA etc. will be a plus.
- Understanding of the COSO internal controls framework, ISO and ISACA’s IT Risk Management frameworks.
About The Company:
Saudi Networkers Services Founded in late 2001, SNS was initially established as a joint venture between Networkers International (Networkers MSB) a UK based company and Saudi Networkers Services a Saudi based company.
- SNS has more than 1,600 employees across the MENA region.
- SNS is an ISO 9001 certified company.
- SNS reaches 380 Contractors till the moment in KSA Only.
- Extensive database 70,000+ Active professional candidates.
- Experienced in our field with more than 8 years of doing such a business.