RISK MANAGEMENT DEPARTMENT
8. INFORMATION AND CYBERSECURITY OFFICER * 1
Job Purpose
To support the organization in safeguarding its information assets by monitoring security systems, identifying and mitigating cyber risks, and ensuring compliance with IT policies and standards. The role is critical in maintaining a secure technology environment, investigating incidents, and promoting security awareness across the organization.
Under the supervision of the Chief Information Security Officer (CISO), the following are among the key responsibilities:
Key Responsibilities
Security Monitoring & Incident Management
■ Continuously monitor security systems and networks for anomalies or breaches.
■ Investigate security incidents, perform root cause analysis, and recommend corrective actions.
Policy & Compliance
■ Review and ensure adherence to IT policies, standards, and procedures.
■ Maintain and update documentation related to security protocols.
Risk Reporting
■ Prepare and submit monthly Information Security and Cyber Risk reports to Management.
Vulnerability Management
■ Assist in tracking and closing vulnerabilities identified through assessments and penetration tests.
Awareness & Training
■ Support security awareness programmes to strengthen organizational resilience.
Continuous Improvement
■ Stay informed on emerging trends and developments in information and cybersecurity and recommend improvements.
Other Duties
■ Undertake assignments as directed by the Chief Risk Officer.
Required Skills and Attributes
■ Data analytical skills.
■ Decision-making ability.
■ Strategic planning and implementation abilities.
■ Understanding of information security principles.
■ Good interpersonal, communication, and negotiation skills.
Qualifications and Experience
■ Degree in Computer Science or a technology-related field.
■ A Master’s degree in any of the above fields will be an added advantage.
■ Professional security management certifications such as CISM, Security+, CISSP, or other relevant certifications.
■ Minimum of 5 years’ experience in a combination of Risk Management, Information Security, and IT roles.
■ Knowledge of common information security management frameworks.

