وظيفة نائب رئيس - أمن المعلومات واستمرارية الأعمال وخصوصية البيانات شاغرة لدى First Abu Dhabi Bank في الرياض
تفاصيل الوظيفة
نبحث عن نائب رئيس لأمن المعلومات وإدارة استمرارية الأعمال وخصوصية البيانات في الرياض للانضمام إلى First Abu Dhabi Bank (FAB).
نبذة عن الوظيفة
سيتولى المرشح قيادة وظائف الأمن السيبراني وإدارة استمرارية الأعمال (BCM) وخصوصية البيانات في فرع البنك بالمملكة العربية السعودية، بصفته كبير مسؤولي أمن المعلومات (CISO) للفرع. سيعمل على إنشاء وتشغيل برنامج حوكمة أمن سيبراني متين يفي بمتطلبات إطار الأمن السيبراني للبنك المركزي السعودي (SAMA CSF) وضمان الامتثال للوائح ذات الصلة مثل إطار SAMA CSF وPDPL وضوابط الهيئة الوطنية للأمن السيبراني (NCA)، ودعم العمليات المصرفية الآمنة والمرنة. سيتعاون مع وحدات إدارة المخاطر الجماعية لوضع منهجيات وسياسات وإجراءات المجموعة في الفرع، وتنفيذ أطر الرقابة وتحسين مستويات النضج عبر مجالات الحوكمة وإدارة المخاطر والعمليات وأمن الطرف الثالث.
المهام والمسؤوليات
- قيادة وإدارة الأمن السيبراني: تحديد وتوصيل وصيانة إستراتيجية وسياسات الأمن السيبراني للفرع بما يتوافق مع مجالات SAMA CSF، وإنشاء هيكل حوكمة معتمد من الإدارة العليا، وإدارة إطار أمن المعلومات واستمرارية الأعمال للجنة المخاطر والامتثال في الفرع والمجموعة.
- تطوير الاستراتيجية والتنفيذ: دعم كبير مسؤولي المخاطر في الفرع في صياغة وتنفيذ استراتيجيات المخاطر والأمن السيبراني واستمرارية الأعمال بما يتماشى مع رؤية المجموعة؛ والحفاظ على إستراتيجية إدارة المخاطر وأطرها وتحسينها باستمرار لضمان العمل ضمن حدود الرغبة في المخاطرة المحددة.
- إعداد الميزانية والأداء المالي: إدارة إعداد ميزانية القسم ومراقبة الأداء المالي والامتثال للميزانية مع ضمان تنفيذ الأنشطة وفقًا للإرشادات المعتمدة.
- السياسات والأنظمة والإجراءات: المساعدة في تطوير وتنفيذ سياسات المخاطر (أمن المعلومات، استمرارية الأعمال، خصوصية البيانات) والإجراءات والضوابط لتلبية المتطلبات التنظيمية؛ والمساهمة في بناء ثقافة المخاطر داخل الفرع لتعزيز الوعي بممارسات إدارة المخاطر السليمة.
- إطار إدارة المخاطر: تطوير آلية مراجعة شاملة لسياسات أمن المعلومات لضمان الاتساق والملاءمة؛ وتطوير منهجيات تقييم أمني للتغييرات في البنية التحتية لتقنية المعلومات بما يتوافق مع سياسة أمن المعلومات ومعايير PCI DSS والمتطلبات التنظيمية الأخرى.
- تقييم وإدارة مخاطر المعلومات: إدارة تصنيف البيانات وتصنيف مخاطر أصول المعلومات، وإجراء تقييمات المخاطر ومراقبة نتائج اختبار الاختراق لتحديد الثغرات الأمنية والعمل مع الفرق المعنية لوضع خطط العمل التصحيحية؛ وتحديد القضايا القانونية والتنظيمية المتعلقة بأمن المعلومات وتقديم التوصيات.
- الامتثال للأمن السيبراني: ضمان الامتثال التنظيمي لـ SAMA CSF وNCA واللوائح الأخرى، والحفاظ على مستودعات الأدلة وتقارير النضج الذاتي؛ والتخطيط والتنسيق للمراجعات الدورية للأمن السيبراني وعمليات التدقيق المستقلة ومتابعة إغلاق النتائج.
- المراقبة والضمان للأمن السيبراني: التنسيق مع مكتب الأمن الجماعي لضمان المراقبة المستمرة والتسجيل، والحفاظ على قدرات مركز عمليات الأمن (SOC) لكشف الأحداث والاستجابة لها؛ وإدارة مراقبة انتهاكات أمن المعلومات واختبار البنية الأمنية لتقييم نقاط القوة والتهديدات المحتملة.
- إطار واستمرارية الأعمال والتخطيط والحوكمة: وضع خطط استمرارية الأعمال تتناسب مع طبيعة العمليات وتعقيدها، وضمان اختبارها وتنفيذها عبر الإدارات؛ وتصميم وتطوير نموذج حوكمة استمرارية الأعمال، وتنفيذ برامج التدريب والتوعية للموظفين.
- إدارة الحوادث والكوارث: امتلاك خطة الاستجابة لحوادث الأمن السيبراني وقيادة التنسيق والتحقيقات والاسترداد؛ وتحديد سير العمل للتواصل والإبلاغ التنظيمي؛ وضمان قدرات التعافي لتلبية متطلبات الأعمال من خلال الاختبار المنتظم وتحليل الاحتياجات المستقبلية.
عرض النص الأصلي للإعلان
JOB PURPOSE:
The selected candidate will assist the Country CRO and will Lead FAB KSA’s Cybersecurity, Business Continuity Management (BCM), and Data Privacy functions, acting as the Chief Information Security Officer (CISO) for the KSA franchise.
The candidate is responsible to establish and operate a robust cybersecurity governance program that meets the Saudi Central Bank (SAMA) Cybersecurity Framework (CSF) requirements, ensures compliance with all applicable laws and regulations such as SAMA CSF and BCM Frameworks, PDPL, NCA’s controls, and supports secure, resilient banking operations.
In doing this, he/she will work closely with the Group Risk Management units to ensure the Group methodologies, policies, procedures are established in KSA. Additionally, implement control frameworks, and continuously improve maturity levels across governance, risk management, operations, and third‑party security.
KEY ACCOUNTABILITIES:
Cybersecurity Leadership & Governance
- Define, communicate, and maintain the KSA Cybersecurity Strategy and Policy framework, mapped to SAMA CSF domains and sub‑domains.
- Establish and maintain a cybersecurity governance structure endorsed by senior management, with clear charters, roles, and decision rights.
- In conjunction with, and as required by the Country Chief Risk Officer, manage the Information Security & Business Continuity framework for Country and Group Risk & Compliance Committee.
Strategy Development and Implementation
- Assist the Country Chief Risk Officer in formulation, implementation and delivery of the FAB Franchise in KSA’s Risk, Cybersecurity and BCM strategies in line with the vision, mission, values and priorities.
- Maintain, execute and continuously improve FAB Franchise in KSA’s risk management strategy, frameworks and tolerances to assess and mitigate the risk and to ensure the region operates within its pre-defined risk appetite, aligned to the group’s risk & business strategy.
Budgeting and Financial Performance
- Manage the preparation of the department budget and monitor financial & risk performance versus the budget while ensuring all departmental activities are conducted in line with the approved guidelines.
Policies, Systems, Processes & Procedures
- Assist in development and effective implementation of risk policies (Information Security, Business Continuity, and Data Privacy), procedures and controls covering all areas of assigned FAB Franchise in KSA so that all relevant procedural/legislative requirements fulfilled while delivering a quality, cost-effective service.
- Contribute in development of a risk culture within the assigned FAB Franchise in KSA to drive heightened awareness and understanding of prudent risk management practices; work with other risk teams on technical aspects so that key stakeholders are equipped with the necessary knowledge and capability to take risk-based decisions on behalf of the Group.
Risk Management Framework
- Develop a comprehensive Risk Review mechanism for information security policies & procedures to assure consistency, comprehensiveness, and adequacy to enable an effective information security risk management process, and the same are adjusted as appropriate to reflect changes in the risk profile and market dynamics.
- Develop & maintain security assessment methodologies for IT infrastructure changes in line with the bank’s information security policy, PCI DSS requirements, industry standards and other regulatory requirements.
Information Risk Assessment and Management
- Manage the data classification and risk categorization of information assets in coordination with respective business/information owners, in order to enable the identification, analysis and mitigation of risk in information technology and business systems.
- Conduct risk assessments and oversee the penetration tests results to identify current and future security vulnerabilities and flaws in information systems, determine the management-approved level of risk, and work closely with relevant teams to prepare and maintain action plans to mitigate issues/IS risks.
- Identify current potential legal and regulatory issues affecting information security and monitor the assessment of their impact on the organization, in order to recommend suitable action plans and enable informed decision making.
- Design and ensure implementation of governance structure for information security to manage conformity and compliancy to security KSA-wide.
- Bring pressing information security vulnerabilities/risks to top management's attention so that immediate remedial action can be taken.
Cybersecurity Compliance
- Ensure regulatory compliance with SAMA CSF, NCA and other applicable regulations; maintain evidence repositories and self‑assessment maturity reporting.
- Plan and coordinate periodic cybersecurity reviews and independent audits; track and remediate findings to closure.
Cybersecurity Monitoring and Assurance
- Coordinate with Group Security Office and ensure continuous monitoring and logging; maintain SOC capabilities for event detection, triage, and escalation.
- Manage the monitoring of information security violations, review and provide recommendations on corrective action in order to ensure that adequate information security in compliance with the necessary standards guidelines and policies.
- Manage the testing of security architecture to evaluate the security strengths and detect possible threats to IT systems.
Business Continuity Framework, Planning & Governance
- Establish business continuity plans commensurate with the nature, size and complexity of operations, taking into consideration different types of likely or plausible risks/scenarios to which the group may be vulnerable in order to provide resilience against such risks/scenarios.
- Ensure that BCM plans are defined, rigorously tested, and implemented across all departments (including call tree testing, Crisis Management plan simulation, planning of premises consolidated and/or integrated exercises), in response to threats and hazards identified through risk management processes.
- Conduct training and awareness programs and facilitate their implementation to ensure that staff can effectively execute BCM plans.
- Design, develop and implement the BC corporate governance model to develop effective guidelines for conducting the business continuity process.
Incident/Disaster Management
- Own the Cybersecurity Incident Response Plan; lead incident coordination, forensics, eradication, and recovery; conduct post‑incident reviews and lessons learned.
- Define communication and regulatory reporting workflows; ensure timely internal/external notifications per regulatory expectations.
- Ensure that the recovery capabilities meet the business requirements through conducting regular testing in coordination with IT and analyzing the future business needs, so that the decisions related to the design and procurement of the new recovery infrastructure are facilitated by key inputs and facts.
- Ensure maintaining a log of incidents and review reports before presenting to the top management to ensure they are comprehensive and accurate in their key findings and provide value added recommendations for improvements of the business continuity plans.
Data Privacy
- Develop data privacy strategies.
- Act as the primary point of contact within FAB KSA for members of staff, regulators, and any relevant public bodies on issues related to data protection -when needed.
- Ensure the FAB’s policies and procedures are in accordance with Personal Data Privacy Law (PDPL) and codes of practice.
- Evaluate the existing data privacy controls and identify areas of none or partial compliance and rectify any issues in consultation with key stakeholders.
- Inform and advise the Data Controller or Data Processor on all matters related to data privacy.
- Promote a culture of data privacy compliance across all units of the organization.
- Provide education to employees on important data compliance requirements.
- Devise training plans and provide data protection advice and support for members of staff.
- Hold training with staff members across different business units who are involved in data handling or processing.
- Proactively conduct audits to ensure compliance and address potential issues.
- Maintain records of all data processing activities carried out by FAB KSA.
- Monitoring changes to local privacy laws and making recommendations when appropriate.
- Reporting incidents to regulator and/or customers (depending on the incident).
- Review and edit existing documents or compose new documentation to ensure including all the law’s requirements in the bank literature.
- Lead and involve in data privacy related projects and initiatives.
- Coordinate with HO and other stakeholders for better alignment and efficiency.
Change Management
- Integrate cybersecurity into project and change governance; perform security assessments for new initiatives and technology changes.
- Participate in management of change through continuous improvement of functional systems, processes and practices considering global standards and changes in the business environment which demand proactive action plans
Security Awareness & Training
• Coordinate with Group Security awareness team ad develop role‑based awareness and training programs; measure effectiveness and drive culture change.
QUALIFICATIONS & EXPERIENCE:
Minimum Qualification
- Bachelor’s degree in IT or related discipline.
- Master’s degree in business administration, or a related discipline is preferred.
- Professional certifications preferred: CISSP, CISM, CRISC, ISO/IEC 27001 Lead Implementer/Lead Auditor, CBCP/CMCE, CCSP, SANS (e.g., GCIH, GCIA).
Minimum Experience
+10 years’ relevant experience in the banking sector with at least 4 years in similar positions of progressively increasing managerial responsibilities in the Information Security & Business Continuity management function.
رقم الإعلان لدى المصدر: 4462205196