Job Purpose:
The role acts as the primary IT point of contact responsible for implementing and supporting cybersecurity requirements within the IT function
Key Responsibilities:
- IT Governance: Develop, maintain, and continuously improve the IT Governance Framework based on ISO 27001, ISO 22301, COBIT, and ITIL.
- Policies & Compliance: Govern IT policies, procedures, standards, and controls, ensuring alignment with cybersecurity and international standards.
- IT Process Governance: Establish and oversee ITIL processes including change, incident, problem, configuration, asset, and service management.
- Control & Performance Monitoring: Monitor compliance with governance controls, SLAs/OLAs, configuration standards, operational procedures, and performance metrics.
- Change & Incident Governance: Ensure changes and incidents are properly assessed, approved, documented, resolved, reviewed, and subject to lessons learned.
- Asset & Documentation Governance: Ensure accurate IT asset inventories and secure, version-controlled management of IT documentation, configurations, SOPs, architecture, and DR materials.
- Business Continuity & DR: Oversee ISO 22301 requirements, including BIAs, continuity requirements, DR documentation, testing, and readiness.
- Vendor Governance: Monitor third-party compliance, contractual obligations, SLAs, and business continuity requirements.
- Audit & Risk Management: Coordinate internal/external ISO audits, track findings and corrective actions, and ensure IT-related cybersecurity and risk-treatment actions are completed.
- Reporting & Leadership: Prepare governance dashboards and reports covering compliance, audit actions, SLA performance, service maturity, risks, and continuity readiness for senior leadership.
- Stakeholder Management: Collaborate with Cybersecurity, Enterprise Architecture, and IT Operations to embed governance and security requirements into projects, changes, and technology implementations.
- Awareness & Training: Deliver governance and compliance awareness programs covering ISO requirements, ITIL, change management, service management, and policies.
- Continuous Improvement: Identify process gaps, operational risks, audit recommendations, and regulatory changes, and drive ongoing improvements to the IT governance program.
Qualifications:
- Bachelor’s degree in IT, Information Systems, Computer Science, or a related field.
- 5-8 years of experience in IT governance, IT compliance, IT risk management, or IT service management.
- Strong experience implementing and maintaining ISO 27001 ISMS and ISO 22301 BCMS
- Experience in drafting policies, developing processes, and managing governance documentation.