
المهارات المطلوبة
تفاصيل الوظيفة
وصف الوظيفة
The role will lead and oversee cybersecurity risk assessments, security control reviews, assurance and compliance activities, technology and cyber risk monitoring, vulnerability remediation, and emerging threat assessments. The position will also support the continuous enhancement of the Group’s cybersecurity governance, regulatory compliance, and overall cyber resilience.
The successful candidate will combine strong cybersecurity risk management, assurance, and technical security expertise with the ability to assess complex technology environments and engage effectively with business stakeholders, technology teams, third parties, auditors, and regulators.
Key Responsibilities
Security Architecture & Technology Risk
Conduct security reviews of infrastructure, applications, networks, databases, cloud environments, and security solutions.
Review technology architectures to ensure security requirements are incorporated by design.
Perform threat modelling and cybersecurity risk assessments for new technologies and business initiatives.
Define and assess security baselines and configuration standards.
Provide security recommendations for architecture and technology transformation initiatives.
Cloud, AI & Emerging Technology Security
Assess security controls across Microsoft Azure, Google Cloud Platform, and Oracle Cloud Infrastructure.
Conduct cloud security assessments covering identity, networks, workloads, containers, data protection, logging, and monitoring.
Assess AI, Generative AI, Machine Learning, and emerging technology solutions for cybersecurity risks.
Evaluate security and compliance requirements for AI applications and third-party AI providers.
Establish appropriate security controls for cloud-native, AI-enabled, and emerging technologies.
Application Security & DevSecOps
Lead application security assessments throughout the software development lifecycle.
Establish and enhance secure SDLC and DevSecOps practices.
Integrate security testing into CI/CD pipelines.
Oversee SAST, DAST, SCA, penetration testing, and application security reviews.
Work with development teams to identify and remediate vulnerabilities.
Promote security-by-design principles across technology projects.
Vulnerability & Security Testing
Oversee enterprise vulnerability management and risk-based remediation.
Manage penetration testing for applications, infrastructure, and external-facing systems.
Coordinate testing engagements and track remediation activities.
Establish vulnerability KPIs, KRIs, remediation timelines, and risk acceptance processes.
Identify recurring vulnerabilities and drive improvements to the Group’s security posture.
Security Operations & Incident Management
Provide governance and oversight of security monitoring and incident response.
Work with SOC and security teams to improve detection, response, investigation, and remediation.
Review SIEM use cases, monitoring requirements, and incident management processes.
Support major cybersecurity investigations and post-incident reviews.
Ensure lessons learned are incorporated into security controls and risk management.
Cybersecurity Governance, Risk & Compliance
Act as deputy to the Information Security Officer when required.
Support cybersecurity governance forums, risk committees, and management reviews.
Support internal, external, and regulatory audits, including evidence collection, findings management, and remediation tracking.
Prepare cybersecurity dashboards, KPIs, KRIs, risk reports, and management reporting.
Conduct cybersecurity assurance and control effectiveness reviews to assess cybersecurity maturity.
Qualifications:
Bachelor’s or Master’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
More than 10 years of experience in cybersecurity, technology risk assessment, assurance, or related disciplines.
Experience with ISO 27001, NIST, NIA, QCSF, PCI DSS, GDPR, PDPL, or similar frameworks and regulations.
Hands-on experience in cybersecurity risk assessments, control reviews, security assurance, and remediation.
Preferred Certifications
CISSP, CISM, OSCP, CEH, or CHFI.
Technical Skills
Enterprise Security Architecture; Cybersecurity Risk Assessment & Assurance; Cloud & AI Security; Application Security; DevSecOps; Vulnerability Management; Penetration Testing; Threat Modelling; Security Operations & Incident Response; SIEM & Security Monitoring; Governance, Risk & Compliance; Executive Reporting and Stakeholder Management.
Key Competencies
Strong analytical and risk-based decision-making skills.
Ability to translate technical cybersecurity issues into business risks and actionable recommendations.
Strong understanding of cybersecurity regulations, standards, and compliance requirements.
Ability to lead initiatives across multiple business and technology functions.
Excellent stakeholder, executive communication, and influencing skills.
Ability to balance security and governance requirements with practical business needs.
Lesha Bank LLC (Public)
Lesha Bank LLC (Public)
Lesha Bank LLC (Public)