Job Summary
the following vacancy has arisen within Group IT and applications are invited from suitably qualified and experienced persons to fill the vacancy. the incumbent will be responsible for designing and maintaining the architecture of the it security posture of be FMHL Group and identifies, assesses, and treats risks to the confidentiality, integrity, and availability of its information assets in accordance with FMHL’s overall risk tolerance and will translate the IT-risk requirements and constraints of the business into technical control requirements and specifications, as well as reports on ongoing performance.
Duties And Responsibilities
-
Creating a cybersecurity framework that is aligned with the goals and objectives of the Group.
• Developing, implementing and monitoring a strategic, comprehensive enterprise information security ant IT risk management program.
Planning, procuring, and rolling out security hardware and software, ensuring that It and network infrastructure is designed according to best security practices.
• Overseeing projects, budgets and resources under it Security and Risk management to ensure that the Group gets a favorable return on its investments in staff, hardware, software and service providers.
•Monitors all operations and infrastructure, including regular examination of security alerts and checking logs.
• Defining, assessing and ensuring the quality of information security governance that supports FMHL’s strategic and operational objectives, and meets legislative requirements and industry best practice.
• Providing a comprehensive capability to recover business operations with minimal operational risk, encompassing all data processing and business operational areas of the organization.
• Performing risk assessments that identify the level of vulnerability across FMHL’s assets.
• Managing the handling of the complete threat spectrum and compliance of the organization’s security policies or
standard security practices. Threats include DDoS attacks and different types of malware, such as viruses, ransomware and phishing
• Providing technical guidance or system process expertise, coaching and mentorship to the Security team.
Qualifications And Experience
Person Specification
• Degee in Information Systems, Computer Science or Software Engineering.
• 4 years in 0 Security and Risk management in progressively senior roles
• Al least 3 of the following certifications
• certified Information Systems Senility Professional (CISSP) issued by ISC2
• Certified Information Security Manager (CISM) issued by ISACA certifications
• AWS or Azure cloud security certifications.
• CCSP issued by Cisco
• MCSE – Security issued by Microsoft
• CCNA Certification
• Sophos, Kemp LoadBalancer, Cisco ISE, Kaspersky and ASA Firewall knowledge or certification
• Working knowledge in all areas of technology (infrastructure, applications, SDK, end-user platforms and SOC Operations)
• Experience deploying enterprise application security testing tools (SAST, DAST, open source, etc), solutions and in Cl/CD. Agile, and Waterfall environments
• Experience in scripting, and automation (DevSecOps)
Job Summary
More Information
- Job Application Details With you, for you. Candidates meeting the above criteria should forward their Curriculum Vitaes (CVs), copies of certificates and application letters to Group Human Resources via the following email address: [email protected] FacebookTwitterWhatsAppGmail