General Summary or Job Objective:
The IT Security Officer will be responsible for establishing and maintaining a corporate-wide information cybersecurity management program, ensuring that all information assets are adequately protected.
Essential Functions:
- Develop and implement Cybersecurity Strategies, Policies, and IT risk management programs
- Work closely with the CTO and IT teams to assess and manage cybersecurity risks
- Evaluate the IT threat landscape to reduce risk, leading auditing, and compliance initiatives,
- Assist in implementation of the IT Cyber Security strategies, policies, and procedures
- Prepare the documentation for the IT Cyber Security reports and guidelines
- Develop and enhance an information security management framework
- Monitor, maintain and administrate the IT security devices (such as Firewalls, Core Switches, Web filtering, Spam Filtering devices etc) in coordination with IT Infrastructure and Cloud Unit to ensure no threats impacting the operations of these devices
- Understand and interact with related disciplines through committees to ensure the consistent application of policies and standards across all technology projects, systems, and services;
- Partner with business stakeholders across INDEX Holding group to raise the awareness of Cyber Security risk management concerns by conducting the required training and workshops
- Assists with the overall business technology planning, providing current knowledge and future vision of technology and systems
- Manage and maintain cyber security incident management and track accordingly
- Review the audit reports and assist to tackle the security issues raised by the auditors
- Conduct a periodic security check on all the relevant IT systems and services that are running in production
- Conduct periodic penetration testing to the relevant technologies that are running in production
- Conduct a periodic vulnerability assessment to the relevant technologies that are running in production
- Perform a periodic check of the backup restoration practice in INDEX Holding to ensure the consistency of the backup data and integration
- Assist in controlling IT related risk by advising management and functional units on all IT policies and procedures
- Ensure the confidentiality and protection of corporate data, proprietary information, and intellectual property
- Check system updates to ensure patch management with the latest patches and upgrades on a regular basis
- Assist in managing the crisis situations, involving complex technical hardware or software problems and ensure adequate provision for business continuity and disaster recovery
- Ensuring that INDEX Holding is adaptable to evolving cyber security compliance regulations
- Solicit, study, and evaluate all IT Project Plans to ensure risk low effectiveness, in addition identify and develop risk analysis and supervise risk management for the IT department
Qualifications and Experience:
- Bachelor’s Degree in Information Technology, Computer Science, or a related field, with additional technical training/certifications in System Administration
- Professional certifications such as CISSP, CEH, CISM, or CISA are an added advantage, along with hands-on experience in Risk Management, Penetration Testing, and Vulnerability Assessment
- Minimum 7 years of experience in IT Cybersecurity, IT Systems, and Network Evaluation
- Strong understanding of security standards and best practices, with the ability to apply them effectively
- Knowledge of the latest technologies and cybersecurity research is an advantage
- Strong project management skills
- Excellent English communication skills (written and verbal); Arabic language skills are an added advantage
- Strong organizational, time management, and interpersonal skills
To apply send your CV to hr@index.ae