Our client is a government agency which supports ICT delivery services. This is a leadership role that requires technical proficiency demonstrated in multiple cybersecurity domains.
Responsibilities:
- Lead the agency-level cybersecurity function in supporting agency digital transformation initiatives whilst ensuring digital resilience of agency systems.
- Formulate and implement agency cybersecurity strategies, policies and work plans, ensuring continuous alignment with agency's business strategic goals
- Review and enhance risk management through threat-based risk assessments, risk mitigations, risk monitoring and reporting.
- Provide consultation and endorse risk management and mitigation plans from agency’s project teams.
- Govern and enhance the agency's security posture by maintaining visibility and oversight of ICT assets, security architectures, and cybersecurity operations code of practices.
- Develop and maintain incident response plan and playbooks. This involves planning, designing and conduct of security incident response workshops and exercises (table-top exercises, simulation and drills) as well as lead the investigation and management of ICT security incidents.
- Provide advisory and recommendations on appropriate cybersecurity technologies to be deployed that meets agency’s business requirements and aligned with WOG-wide advisories and practices.
- Ensure secure by design ICT product development, and that security controls implementations comply with the defined security policies, standards and guidelines.
- Develop and maintain effective cybersecurity awareness and training programmes
Requirements:
- Degree in Computer Science, Information Systems, Engineering or related Technology field
- At least 8-10 years of management experience related to information security and solid grasp of ICT operations, security policies, business processes and the relationship between them.
- Ability to work with multi-functional, multi-disciplined teams to formulate, institute real time awareness of security posture and baseline among end users.
- Good interpersonal and partner/executive leadership skills.
- Demonstrate knowledge and experience in security by design implementations, review of system architecture, devsecops practices, Infrastructure as Code (IaC) tools and securing CI/CD pipelines
- Demonstrate understanding of cloud service models (IaaS, PaaS, SaaS), coupled with a strong understanding of core cloud services and modern cloud-native architectures (serverless, containers, microservices)
- Identify on-premises and cloud-specific cybersecurity risks and threats, demonstrating skills to thoroughly assess their impact and likelihood. This assessment encompasses, but is not limited to, secure configurations, insider threats, vendor risks, data leakage, malwares including ransomware, account hijacking, and compliance risks.
- Evaluate the effectiveness of existing controls and recommending appropriate mitigation strategies for on-premises and cloud-related cybersecurity and data security issues.
- Display understanding of emerging threats and technologies, and the ability to translate risk into business impact
- Strong understanding of compliance requirements and the ability to identify potential violations in on-premises or cloud environments.
- Able to communicate cyber security topics effectively to senior stakeholders.
- Minimally possess CISSP certification, preferably with other related certifications, e.g. CISM, CCSP, GCIH that demonstrates continuous learning and knowledge of industry best practices.
- We believe in being Agile, Bold and Collaborative, and are looking for people who identify with these values.