Head of Information and Cyber Security

؜ - ؜Cairo ؜ -

Job details

Job : Operations
Primary Location : Africa & Middle East-Egypt-Cairo
Schedule : Full-time
Employee Status : Permanent
Posting Date : ‎26/May/‎2022, ‎8:53:‎54 PM
Unposting Date : Ongoing


About Standard Chartered
We're an international bank, nimble enough to act, big enough for impact. For
more than ‎160 years, we've worked to make a positive difference for our
clients, communities, and each other. We question the status quo, love a
challenge and enjoy finding new opportunities to grow and do better than
before. If you're looking for a career with purpose and you want to work for a
bank making a difference, we want to hear from you. You can count on us to
celebrate your unique talents. And we can't wait to see the talents you can
bring us.


Our purpose, to drive commerce and prosperity through our unique diversity,
together with our brand promise, to be here for good are achieved by how we
each live our valued behaviours. When you work with us, you'll see how we
value difference and advocate inclusion. Together we:
* Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
* Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
* Be better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
* In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
* Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations
* Time-off including annual, parental/maternity (‎20 weeks), sabbatical (‎12 weeks maximum) and volunteering leave (‎3 days), along with with minimum global standards for annual and public holiday, which is combined to ‎30 days minimum
* Flexible working options based around home and office locations, with flexible working patterns
* Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
* A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning
* Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.
* Recruitment assessments - some of our roles use assessments to help us understand how suitable you are for the role you've applied to. If you are invited to take an assessment, this is great news. It means your application has progressed to an important stage of our recruitment process.
Role Responsibilities
JOB SUMMARY
Define key responsibilities to reflect the duties and responsibilities
of this role.

We are establishing a capability to successfully implement and embed the new
Information and Cyber Security (ICS) Risk Type Framework (RTF) into Africa and
Middle East (AME) countries to bring consistency in the identification and
mitigation of ICS Risks. The Head of ICS (Egypt Branch) will drive the
adoption and implementation of the framework across the delegated countries.
This role will require hands on approach to understand, embed, and guide Egypt
on the ICS RTF to maximize risk reduction and capability improvement, while
meeting compliance and legal obligations, and minimising client impact. The
role will require to have end-to-end view of all ICS activities with regular
risk assessment, tracking, follow up and reporting at the relevant forums.
The Head of Information and Cyber Security (Egypt Branch) will provide
exceptional leadership, maintain highly constructive relationships with key
stakeholder, and possess strong security risk framework knowledge to mobilize
effort and commitment.
* He/she will execute a robust and efficient plan to rollout ICS RTF by working with key stakeholders including COOs/CIOs direct teams, ICS RTF Implementation Programme teams, Office of the CISO and Security technology teams. The plan will incorporate digital footprint discovery, risk assessment, definition and implementation of controls as guided by the ICS RTF and tailored to the relevant areas.
* CISO authority for countries in scope (Egypt).
* Supporting Africa and Middle East in the implementation of the ICS Risk framework including working with stakeholders to identify, assess and rate the information assets, build out the risk profile per the framework, initiate risk assessments and put together treatment plans.
* Use qualitative and quantitative data sources to validate Key Control Domains (KCD) and associated controls, accelerate risk assessment process, validate business risk profile, and develop action plans to remediate to bring ICS risk back into appetite.
* Deploy and implement Threat Scenario risk assessment in country.
* Follow up on identified thematic cyber issues, develop processes to address issues from re-occurrence and ensure cyber hygiene across the whole portfolio.
* Provide regular status updates including progress, top risks and issues to the respective country and regional forums for the relevant domains. Track RAG status, key milestones, risks, dependencies, and issues.
* Interface into Technology forums to ensure security technologies are operating with input from countries and be actively involved in the roadmap of these technologies.
* Development of risk treatment plans for the assigned areas in conjunction with the business and technology teams. Interface with other areas to ensure dependencies are known and prioritised. Negotiate timelines to ensure proper remediation by maintaining support and organizational alignment.
* Adapt to emerging and horizon risks and address issues to maximize outcomes. Urgent and timely action for risks and issues which adversely impact cyber risk profiles.
* Re-planning and prioritising as required to maximise risk reduction.
* Coordinate and plan for cyber crisis management exercises, build response and recovery capabilities, workarounds, ensure up to date playbooks etc. Assist with other cyber activities underway
RESPONSIBILITIES
Strategy
* Ensure effective prioritisation and application of industry best practice into the ICS RTF and ICS country risk.
* Identify changes to plan required in terms of additional components, reprioritisation to anticipate and respond to changes.
* Learn from the recent regional and global cyber events and build into strategy to address current and emerging risks
Business
* Maintain strong stakeholder engagement with other COO ICS teams, Chief Risk Officer, Chief Information Security Office teams, ICS RTF Implementation Programme teams and Security Technology teams.
* Establish and maintain working groups across domains to progress the framework roll out.
* Escalate appropriately to ensure necessary decisions are made in a timely manner.
People & Talent
* Lead through example and build the appropriate culture and values
* Set appropriate tone and expectations from team and work in collaboration with risk and control partners
* Ensure the provision of ongoing ICS training and development of people, and ensure that holders of all critical functions are suitably skilled and qualified for their roles
Risk Management
* Manage the rollout of the ICS RTF professionally and efficiently, closely tracking timeline commitments for provision of information and action plans, and for validation of actions taken.
* Ensure adoption of security tooling and capability to address ICS risk tactically and strategically.
* Address and adopt response and recover capabilities and assist with cyber crisis management exercises, playbooks etc.
Governance
* Support the Africa and Middle East Head of Information Security on running periodic working groups and ensuring proper rollout of the ICS RTF.
* Assist with pulling together Risk papers going to various Risk committees within the region.
* Manage actions coming out of various risk and compliance forums.
Regulatory & Business Conduct
* Lead the [Egypt Information and Cyber Security] to achieve the outcomes set out in the Bank's Conduct Principles: [Fair Outcomes for Clients; Effective Financial Markets; Financial Crime Compliance; The Right Environment.]
* Display exemplary conduct and live by the Group's Values, Valued Behaviours, and Code of Conduct.
* Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across the Bank.
* Effectively and collaboratively identify, escalate, mitigate, and resolve risk, conduct and compliance matters.
Key stakeholders
* COO, Egypt
* Group CISO
* Head of Global ICS Operations
* Head of ICS Regions
* Regional CISO and Regional ICS team
* CIO, Egypt
* CEO, Egypt
* Banking Regulators
* Head of ICS Governance
* Head of ICS Policy
* Head of ICS Assurance and Testing
* Head of ICS Training, Awareness & Exercises
QUALIFICATIONS
TRAINING, LICENSES, MEMBERSHIPS AND CERTIFICATIONS
* Minimum of ‎8 - ‎12 years' experience with at least ‎5 years in Information and Cybersecurity capacity in financial industry
* Minimum of ‎5 years in banking industry
* Degree in Engineering, Computer Science/Information Technology, or its formally recognised equivalent.
* One or more of the following certifications will be preferred:
* Certified Information Systems Security Professional (CISSP)
* Certified Information Security Manager (CISM)
* Certified Chief Information Security Officer (CCISO)
* SANS Global Information Assurance Certifications (GIAC)
* Certified in Risk & Information Systems Control (CRISC)
* Payment Card Industry - Quality Security Assessor (PCI-QSA), etc.
* ISO ‎27001/‎22301 Lead Implementor or Lead Auditor
* Strong integrity, independence, and resilience
* Willing and capable of travel across the countries in the portfolio if required
* A Master's degree is desirable
Visit our careers website www.sc.com/careers

Job Summary

  • Advertiser: Standard Chartered
  • Announcement date: 27/05/2022
  • Type of employment: -
  • Experience level: -
  • Educational level: -
  • Job location: Cairo
  • Salary: -
  • Phone number: -

More jobs like this

Cairo
30/04/2022

Purpose: A cybersecurity consultant contributes and participates in cybersecurity consultation engagements with customers; conducting first-grade assessments and producing technical analysis, and recommendations' research. They have in-depth technical knowledge in one or more cybersecurity domains.…

Cairo
11/04/2023

### **Description** At PwC, we measure success by our ability to create the value that our clients and our people are looking for. Our reputation lies in building lasting relationships with our clients and a focus on delivering value in all we do. We 're a network of firms in 158 countries with mor…

Cairo
12/04/2023

**Line of Service** **Industry/Sector** **Specialism** **Management Level** Associate **Job Description & Summary ** A career within Cybersecurity and Privacy services, will provide you with the opportunity to help our clients implement an effective cybersecurity programme that protects against …

Cairo, مدينتي
22/01/2023

4 days in month Review diagnostics and assess the functionality and efficiency of systems Implement security measures Monitor security certificates and company compliance of requirements Offer technical support to company staff and troubleshoot computer problems Install and update company software…

Cairo
28/02/2023

### **Description** At PwC, we measure success by our ability to create the value that our clients and our people are looking for. Our reputation lies in building lasting relationships with our clients and a focus on delivering value in all we do. We 're a network of firms in 158 countries with mor…

Cairo
30/05/2022

##### **ص احب المشروع** ##### **Ahmed A.** **** * مهندس برمجيات #### **ت فاصيل المشروع** التعريف بوجه عام علي هذا التخصص أذكر حجم العمل التي يمكن تنفيذه مقابل قيمة عرضك #### **ا لمهارات المطلوبة** * التعليم والتدريس الخصوصي * التدريب * تعلم البرمجة #### **أ ضف عرضك الآن**

Cairo
10/05/2023

**Role Purpose:**  Responsible for Cyber security assurance activities across Vodafone Environment (i.e: Penetration testing - Vulnerabilities analysis - Hardening configurations)  Responsible for acceptance of new nodes and ensure compliance with Vodafone cyber security policies and standard…

Cairo
03/10/2022

Job Description: * keep up to date with the latest security and technology developments. * The ability to work in a team, moderately complex projects/assignments. * May assist other technical staff with tasks and assignments. * Problem Solving capability. * Programming or scripting ab…

Cairo
14/03/2023

**Apply now** **Return to job search** ### **Description** At PwC, we measure success by our ability to create the value that our clients and our people are looking for. Our reputation lies in building lasting relationships with our clients and a focus on delivering value in all we do. We 're a net…

Cairo
22/06/2022

* Installation, configuration and maintenance for network Security equipment (Web Security, Mail Security, End point Security, Data Security, etc….) for IT Vikings customers. * Provides remote and on-site support to our customers. * Performing troubleshooting and root cause analysis on security…

اللغة: العربيّة