Role Purpose:
The role leads and manages the Information Security function by developing and enforcing security frameworks, policies, and controls to protect the organization’s IT systems and data. It oversees security operations, manages outsourced SOC/NOC services, conducts risk assessments and audits, and drives ongoing improvements in the security posture. The role also promotes security awareness through training and ensures compliance with all internal and external security standards.
Accountabilities:
-
Manage and provide leadership for the information security function, ranging from planning and budgeting to operational activities expounding the value of information security
-
Develop and Design IT security framework and detailed risk assessments and controls plans for all the application and Infrastructure touch points.
-
Design and implement information security policies and SOPs (Standard operating procedures) to ensure IT Security is applied at all levels of IT landscape.
-
Work closely with outsourcing partners to monitor, operate, and remediate daily IT security incidents and alerts.
-
Design, implement and operate remote SOC (Security operation center) and NOC (Network Operation center) function as part of running outsource contract
-
Develop security metrics and KPIs to effectively operate and enhance.
-
Prepare training and rollout the training and guidance on information security to all MenaBev users / employees.
-
Conduct IT security audit and support 3rd party IT audit findings to close the gaps.
-
Manage periodic review process for existing IT landscape to ensure the IT security principles are applied.
Job Requirements:
-
Bachelor in IT domain preferably major in IT security
-
Certified IT security professional (CompTIA Security+, CSSP, CISA)
-
IT Security implementation and operation experience in Manufacturing industry, preferably Beverage industry.
-
3-5 years of last working experience as the leader in IT security domain.
-
Vast knowledge of current IT security trends and software.
-
Understand the regulation of SAMA, how to apply in ORG
-
ISO 27001 Experience
-
NIST