About the job Director of Information Security
How You'll Contribute:
- Responsible for enterprise-wide security in the Business Unit, as such you will effectively be the Chief Information Security Officer for the BU, interfacing with our Client's key stakeholders in the African region and other international locations, as well as the Global Information Security group.
- Operate in a matrix organization with functional alignment into Global Information Security and dotted reporting into the regional Technology organization.
- Work directly with business unit leaders to facilitate risk assessment and risk management processes.
- In close collaboration with local IT, PMO, and Global Information Security, drive execution of Information Security projects, including technology deployments, ongoing security assessments and other risk management activities as per our Client's Information Security strategy and plan.
- Maintain and enhance an information security management system in accordance with ISO 27001 standards.
- Support and develop the information security strategy, risk management initiatives, and become a trusted advisor and thought leader to meet business, client and regulatory demands.
- Understand and interact with related disciplines through regulatory forums, committees, and business engagements to ensure the consistent application of policies and standards across all technology projects, systems and services.
- Provide leadership, oversight and performance management to the organizations geographically distributed information security department, including coaching and motivation for high performance.
- Maintain accountability for the Information Security budget in the region.
- Facilitate certifications, as necessary and determined by the business or Global Information Security, for SSAE 18, PCI DSS and ISO 27001.
- Partner with business stakeholders across the company to raise awareness of risk management concerns and to drive and influence their resolution.
- Work within the project and resource prioritization process to ensure security projects and efforts a represented, prioritized and executed.
- On regular basis, report status of security posture and progress against objectives to senior management in Global Information Security and regional IT.
- Maintain a thorough understanding of current security deviations, open assessment and audit findings, and vulnerabilities in our Client's security posture.
- Mobilize and support regional responses to threats and incident investigations in an effective and timely manner.
- In conjunction and coordination with Global Information Security, maintain and test incident response process and ensure its continued integration with regional and global escalation protocols.
- Oversee the completion of security audits by customers and data providers.
- Prepare and contribute in periodic communication and presentations to local business and functional leaders regarding regional security posture and direction.
- Complete annual planning process through ownership and accountability for BU plans for Information Security that align with global strategy but reflect nuances of local needs, where appropriate.
- Assist with the overall business technology planning, providing a current knowledge and future vision of technology and systems
What You'll Bring:
- 12 years+ of extensive experience in risk management, information security and IT
- 10 years Information Security Management
- Degree in Business Administration or a technology-related field required
- Professional security management certification in Information Security / Cyber Security or industry qualifications (CISSP, CISM, CISA, CCSP)
- Strong leadership, project management skills, time management, and problem-solving skills
- Ability to work in a virtual, global matrix organization
- Innovative thinking and leadership with an ability to lead and motivate cross-functional, interdisciplinary teams
- Experience with working with local and regional regulators and authorities such as the National Credit Regulator & the Information Regulator to ensure compliance with local regulations.
- Experience with contract and vendor negotiations and management including managed services
- Experience with designing, developing and implementing security processes, controls and technologies
- Working experience with information security solutions in areas such as Identity Management,
- Vulnerability Management, Content Filtering, DLP, IDS/IPS, FIM and Incident Response
- Working knowledge of industry frameworks and standards such as SSAE 18, PCI DSS, and ISO 27001
- Knowledge of information security in Windows and Linux operating systems as well as TCP/IP networks
- Understanding of web application and product security controls
- Experience with performing system audits and security assessments, and in interfacing with external auditors
- Experience with reporting security metrics (dashboards, KPIs, KRIs)
- Ability to operate as an information security business partner and advisor to senior executives and, where necessary, a hands-on contributor on technology deployments and other projects
What we offer:
We aim high and are reaching for new heights every day. This is a terrific time to join our team as we build on our commitment to integrity, service, reliability and innovation. These values stand behind the decisions we make every day, as well as our relationships at work and with the clients we serve. We believe in the power to achieve and are taking it in bold new directions.
Who we are:
Our Client is a global leader in credit information and information management services, our Client gives businesses, consumers and the global community the power to achieve their goals. Businesses count on us to better manage risk and customer relationships. Consumers are able to better manage credit to achieve their financial goals. In communities around the world, we help build strong economies and give people the power to achieve their dreams. Exceptional opportunities are coming as we build on this strong foundation. Our ambitious growth strategy includes substantial new investment worldwide, a wide range of new solutions to help our clients
succeed like never before, and new ideas for expanding our reach in every part of our dynamic and fast-moving industry. Were on an exciting journey and you can be a part of it. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.