Senior Manager: Regional Information Security
il y a 6j
source :

Détails de l'annonce

Poste proposé : Senior Manager : Regional Information Security

Key Deliverables

  • The Senior Manager Regional Information Security will be accountable to achieve the following objectives :
  • Strategy Implementation

  • Oversee the development of country specific Information Security plans for each of the OPCOs within the region in alignment with the Group Information Security priorities and plan while addressing local country needs
  • Implementation of the Information Security Policy and Standards in line with the overarching Group and local business goals and Group InfoSec priorities
  • Conduct regular reviews of the information security effectiveness in the Opcos within the region to ensure its alignment with the changing dynamics of the internal and external ecosystem, products and services being launched
  • Governance

    Strategic & Operational Meetings

  • Drive adequate risk mitigation and controls and elicit inputs from relevant parties
  • Perform evaluation baseline of Service Level Agreements (SLAs) and KPIs
  • Drive approval process on new initiatives
  • Prepare proposal on change initiatives SLA, policies and procedures
  • Manage and provide solutions to escalations that have multiple processes / functions impact on critical path of service delivery
  • Review and finalise objectives, targets and budgets for the Regional Information Security team as applicable
  • Review key risks, issues and dependencies and set mitigation actions
  • Sign-off / make decisions regarding tactical changes.
  • Performance

  • Monitor OPCO and individual performance and alignment with MTN Global Information Security Strategy
  • Ensure alignment between Regional Information Security manager, Global Expertise Functions, RVP Office, and Opco Information Security teams
  • Reporting

  • Report on a monthly basis to the GM : Group Information Security Program Management relating to progress made within the function and in accordance with the measurement metrics set by the organisation
  • Provide regular feedback to key stakeholders within the OPCOs and Group in alignment with the OPCO Plans and KPI’s
  • Budgets

  • Develop and manage project initiative budgets in line with business objectives
  • Ensure that the cost of operations is reduced, in line with a least cost operating strategy stemming from the business drivers
  • Facilitate the development of OPCO Security budgets in alignment with Group direction and local OPCO requirements
  • Operational Delivery & Execution

  • Oversee and proactively manage the ways of working between the Hub and Spoke Opcos, in line with the agreed terms and SLAs
  • Moderate and proactively address operational challenges between the Hub and Spoke Opcos
  • Establish and lead the overarching Regional Information Security strategy and governance model for the various Regions
  • Ensure the Regional Information Security support and drive continuous improvement initiatives in the regions with respect to Information Security operations, governance, and architecture.
  • Provide regional perspectives and inputs to Global InfoSec teams to enable globally relevant business / Information Security solution designs
  • Drive implementation of policies and mechanisms to control the access of data, as well as response to data breaches in the Opcos within the region
  • Define and implement processes to respond to security incidents involving the loss or compromise of sensitive data in the Opcos
  • Manage and actively drive the notification of a data or privacy breach to affected individuals, regulatory authorities, covered entities, and media
  • Define requirements and ensure implementation of monitoring and protection of data in use, data in motion, and data at rest based on classification
  • Ensure execution of segregation of duties (SoD) tests in the Opcos against access settings, and report contention
  • Ensure implementation of adequate security countermeasures in the Opcos to prevent of unauthorized access and malware infection of IT networks and systems
  • Conduct periodic reviews for network and / or system monitoring for malicious activities or policy violations
  • Ensure implementation of firewall rule requests, review, and approval process as per Group standards and processes in the Opcos
  • Ensure implementation of secure configuration / hardening standards in line with Group a approved standards, in the Opcos
  • Ensure implementation of information security controls in the Opcos to protect databases and stored data
  • Implement Group policies and minimum expectations for completing a business impact analysis (BIA) and Risk Assessment
  • Ensure Opco recovery and business continuity strategies, plans, and procedures from an Information Security perspective are reviewed and implemented in the Opcos.
  • Governance and Regional Oversight

  • Establish governance and oversight protocols with Opcos to ensure critical strategic Information Security metrics are achieved collectively
  • Establish internal team cadence (amongst Regional Information Security Managers) to discuss, understand and resolve information security related issues across all the regions
  • Cascade and drive critical Global Information Security metrics and targets within the regions
  • Review Regional Opco Information Security KPI targets and performance across all regions on a periodic basis and craft region specific interventions as required
  • Co-Develop the IPF for each of the heads of security within the OPCOs within the region and manage performance against the IPF
  • Provide visibility, decision support and effective governance of Cyber Security and Threat Management programs within the regions
  • Review, report and resolve high risk / priority cyber threat trends across the regions on a periodic basis.
  • Global Solution Development and Projects

  • Based on understanding of the Region, provide inputs to the Group Information Security teams to plan for global program and initiative release schedules
  • Monitor progress and provide insights to the respective Group Information Security Program owner
  • Independently evaluate the success and impact of the program with respect to the Opco and Region. Provide feedback to the respective Group Information Security Program owner to enable improvements and course correction
  • Profil recherché pour le poste : Senior Manager : Regional Information Security

    Education :

  • Minimum of 4-year tertiary degree / diploma (Bachelor of Science, Engineering or related field)
  • MBA or Masters (advantageous)
  • CISSP Certification
  • Other preferred certifications are : CISA, CISM, CBCP, ISO 27001 Lead Auditor or Lead Implementer
  • Prince 2 (advantageous).
  • Experience :

  • Minimum of 10 years of working experience in the Information Security domain
  • Experience in the Financial Services or telecommunication sector is advantageous
  • Minimum of 4 to 5 years of Senior Management experience
  • Experience in Information Security related Governance, Enterprise Risk Management and Compliance
  • Experience working in Africa and Middle East and have a grasp of political, social, infrastructure and integrity challenges
  • Advanced working understanding of the information technology environment of a telecom company
  • Worked across diverse cultures and geographies
  • Pan Africa multi-cultural experience is advantageous.
  • Competencies :

    Functional Knowledge :

  • Risk assessment procedures, policy formation, role-based authorization methodologies, authentication technologies and security attack pathologies
  • Cyber defence
  • Security architecture
  • Security operations
  • Data protection
  • Resiliency
  • Secure development lifecycle.
  • Signaler cette offre d'emploi

    Thank you for reporting this job!

    Your feedback will help us improve the quality of our services.

    Mon email
    En cliquant sur « Continuer », je consens au traitement de mes données et à recevoir des alertes email, tel que détaillé dans la Politique de confidentialité de neuvoo. Je peux retirer mon consentement ou me désinscrire à tout moment.
    Formulaire de candidature