Information Security Officer
# Information Security Officer **Virtu Thinko** · Manama · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role 1. Role Purpose To assist in implementing and maintaining the required and internationally accepted standard of information security controls across the company's IT infrastructure. To conduct the security audits and risk assessment program, and review compliance with the information security policies and associated procedures. To handle the development, implementation, operation, maintenance, and support of information security policies, standards, guidelines, and procedures that enhance the level of security over the business's information assets, and reduce the probability of loss. To handle the requirements of the Bahrain Personal Data Protection Law (PDPL). In addition, the role holder will be responsible for implementing and monitoring adherence to the company's operational risk management strategy and business objectives, and for ensuring that operational risk issues are identified and escalated to the appropriate level for consideration and approval. 2. Operational Risk Management ● Establish the required policies and procedures to manage operational risks. ● Establish and roll out the risk control self-assessment and key risk indicator framework. ● Handle the implementation of the operational risk management framework across the company in order to reduce the company's operational risk exposure. 3. Information Security Management ● Establish the required policies and procedures to manage the information security framework. ● Enforce the information security policies, procedures, controls, and standards. ● Assist in the development and implementation of information security policies and procedures. ● Lead ISO 27001 compliance, ensuring year-round task completion by respective stakeholders. ● Assist in information security training and oversight for company employees. ● Handle information security risk assessments and security audits. ● Monitor compliance with information security policies and procedures, referring problems to the appropriate department manager. ● Monitor internal control systems to ensure that appropriate access levels are maintained. 4. Advisory, Training & Awareness ● Provide expert advice on all aspects of information security and risk management to the management and staff of the company. ● Educate employees on information security and risk management matters, including the criticality of compliance with information security program requirements. ● Maintain awareness of changes in security risks, security measures, and computer systems. ● Conduct periodic operational risk and information security training for new and existing staff (at least annually). ● Perform quarterly Operational Risk training for new joiners. ● Assume responsibility as project leader for special projects and provide valuable insights to the management. ● Assist and participate in special projects concerning information security, including testing and implementation of security software enhancements. ● Maintain a broad knowledge of state-of-the-art technology, equipment, and/or systems. 5. Regulatory & Compliance ● Handle the requirements of the Bahrain Personal Data Protection Law (PDPL) and coordinate with other heads of department to ensure full compliance. ● Assist in annual audit reviews by payment associations such as PCI DSS, PCI PIN, PCI 3DS, ISO 27001, client-related audits, and other regulatory bodies. ● Evaluate the effectiveness of controls and measure whether they are meeting the standards and processes laid down by financial, regulatory, and other bodies. ● Assist in reviewing the potential risk exposure before the launch of new products/services. ● Assist in reviewing third-party contracts as and when requested. 6. Incident Response & Technical Security Operations ● Assist in monitoring the disaster recovery plan and contingency planning. ● Assist in the coordination of the handling and resolution of security breach incidents, including system intrusions and abuse; act as the primary point of contact for external law enforcement entities. ● Investigate and identify solutions to viral infestation and damage, administer antiviral programs, and work with platform experts to coordinate the support of virus protection software for common platforms in use across the company. ● Review, update, and enforce data security practices within the central computing centre shared-system environments; test for exposures to ensure adherence to guidelines and procedures, and work with platform experts to implement remedial measures as appropriate. ● Maintain inventory of the company's Hardware Security Module (HSM) system keys in accordance with regulatory requirements. ● Administer the access control procedures for designated IT applications, systems, and network infrastructure. ● Configure log sources such as systems and databases. Monitor to ensure that audit logs record user activities, exceptions, and information security events, and are kept for an agreed period of time. Monitor to ensure that the proper security settings regarding the capture and storage of events are in compliance with incident reporting procedures. ● Assist the department head in conducting regular internal and external network and system vulnerability assessments, and provide System Administrators with reports. ● Assist the department head in the security scan activities and coordinate with vendors and internal stakeholders to reach a compliance status. ● Assist the department head in the development of system configuration baselines. Monitor changes to the IT baselines and provide reporting on unauthorized changes. ● Monitor the network for intrusion and hacking activities. Work with antivirus and intrusion prevention software to analyze logs for issues and perform investigation. ● Assist in performing quarterly reviews of access control and ensure re-certification is conducted for all units. ● Handle the security architecture for the company's current and future projects (e.g. network architecture, server OS architecture, application architecture, cloud architecture, etc.). 7. Risk Management ● Ensure that the cyber-risk framework is implemented. ● Act as Business Unit Operational Risk Supervisor (BU ORS) and liaise with external parties on all matters related to risk management. ● Assist in identifying and evaluating operational and IT risks for the company. ● Assist in identifying risks and calculating likely impact and probability. ● Assist in developing and overseeing the implementation of risk mitigation strategies. ● Participate in the Business Continuity (BC) committee, including BCP testing. ● Review Risk Management Self-Assessment plans and provide commentary on operational risk issues to the assigned units. Pay: BD500.000 - BD800.000 per month Work Location: In person
Наблюдалась 2026-09-20, впервые 2026-09-20, источник — Indeed.