بوبا العربية تعلن عن وظيفة مدير تنفيذي أول - Cybersecurity GRC & Data Protection في جدة
تفاصيل الوظيفة
شركة بوبا العربية في جدة، السعودية، تبحث عن Senior Executive Manager - Cybersecurity GRC & Data Protection لإدارة العمليات اليومية لوحدة حوكمة وإدارة المخاطر والامتثال لأمن المعلومات.
المهام والمسؤوليات
- إدارة وتطوير برنامج حوكمة أمن المعلومات: توثيق العمليات، وضع مؤشرات الأداء، تحسين العمليات بشكل مستمر وتحديد المسؤوليات.
- تصميم وتنفيذ عملية إدارة مخاطر أمن المعلومات: تحليل المخاطر الحالية والمحتملة، إعداد تقارير مخاطر مخصصة للجهات المعنية، وتصميم نموذج تشغيل مخاطر الطرف الثالث مع مراقبة المؤشرات.
- مراقبة الامتثال للمتطلبات القانونية والتنظيمية: تقييم فعالية أنظمة الرقابة، مراجعة الإجراءات، والتنسيق مع الإدارات لضمان الالتزام بسياسات أمن المعلومات.
- إدارة حماية البيانات بصفة مسؤول خصوصية: تحديد نطاق البيانات الشخصية، تحليل مخاطر الخصوصية، وضع خطط التخفيف، ومراقبة الامتثال للوائح حماية البيانات السعودية (PDPL).
الشروط والمتطلبات
- خبرة لا تقل عن 10-12 سنة في مجال أمن المعلومات.
- درجة البكالوريوس في تقنية المعلومات أو علوم الحاسب (BE-IT / B Tech / Comps).
- شهادة مهنية معتمدة في أمن المعلومات مثل CISM، CRISC، CISA، أو CIPP/GDPR/CDPSE.
المهارات المطلوبة
- مهارات تواصل ممتازة.
- نهج قائم على المخاطر.
- قدرة على التعلم السريع وتطبيق المعرفة.
- الالتزام بسرية البيانات.
- مهارات تعدد المهام.
- فهم منهجيات تقييم وإدارة المخاطر.
- خبرة في تطوير وتنفيذ استراتيجية وحلول الحوكمة والمخاطر والامتثال (GRC) على مستوى المؤسسة.
- خبرة في إدارة البيانات وحمايتها.
- خبرة في أمن المعلومات بشكل عام.
- معرفة بأطر الأمن السيبراني والحوسبة السحابية (Frameworks, Architecture, Design, Operations, Controls).
عرض النص الأصلي للإعلان
To manage daily operations of Cyber Security Governance, Risk & Compliance unit.
1 - Governance Documentation & Implementation:
· Develop and maintain a cybersecurity governance program
· Develop and document quality governance processes for Cyber initiatives, BAU, policies/standards, contracts, etc.
· Ensure the processes are aligned to clear objectives and have oversight/review frequencies.
· Review/document RASCI for processes
· Ensure that there is a continuous improvement cycle for process.
· Establish value for the Governance structure/process
2 - Risk Management & Enhancement:
· Design and implement a Cyber Security risk management process.
· Analysing current risks and identifying potential risks that are affecting BUPA Arabia
· Evaluating the BUPA Arabia’s previous handling of risks and comparing potential risks with criteria set out by the company such as costs and legal requirements.
· Risk reporting tailored to the relevant audience. (Educating the board of directors about the most significant risks to the business; ensuring business heads understand the risks that might affect their departments; ensuring individuals understand their own accountability for individual risks)
· Explaining the external risk posed by BUPA Arabia to stakeholder.
· Design and implement third-party risk operating model to identify, evaluate and provide solutions to complex business and technology risks.
· Identify and address key third party related risks and areas of concerns associated with new and existing third-party relationships
· Monitor Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for appropriate escalation to stakeholders
· Develop a TPRM dashboard to highlight key TPRM program metrics and statistics (e.g., third-party portfolio risk, cyber security incidents, program efficiencies/value add)
3 - Compliance Monitoring & Management:
· Maintain the list of all legal / regulatory compliance requirements.
· Ensure periodic assessment of the efficiency of Cyber Security control systems and recommend effective improvements.
· Ensure the review and evaluation of Cyber Security procedures to identify hidden risks or common issues.
· Coordinate with different department to review their respective compliance with Cyber Security Polices.
· Ensure implementation of program to perform periodic review on company procedures and processes.
4 - Data Protection Management:
· Data Privacy Officer (DPO) ensuring that the Bupa Arabia processes the personal data of its staff, beneficiaries, providers or any other individuals in compliance with the applicable KSA data privacy regulations.
· Identify personal data schemes and the applicable privacy laws and regulations.
· Identifies and analyzes privacy risks that are applicable to the privacy ecosystem.
· Develops a data privacy mitigation plan to mitigate identified privacy risks.
· Monitors the proper implementation of the mitigation plan with other business units.
· Monitors compliance with the KSA PDPL and other data protection laws.
· Advise the Data Controller or Data Processor and its employees about their obligations to comply with the KSA PDPL and other data protection laws.
· 10 - 12 years
· Communication skills
· Risk based approach
· Fast learning and application
· Adherence to confidentiality of data
· Multitasking
· Understand Risk assessment and management methodology.
· Experience in developing and implementing enterprise governance, risk, and compliance strategy and solutions.
· Experience in data management and protection solutions
· Experience in information security experience
· Experience in an enterprise governance, risk and compliance
· Knowledge of Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration.
· BE-IT / B Tech /Comps
· Additionally, one more certification in information security domain.
· CISM
· CRISC
· CISA
· CIPP / GDPR / CDPSE
Information Technology, Cybersecurity