About the job Chief Information Security Officer
About Our Client
Our client, a leading insurance organization in Sri Lanka, is seeking an experienced Chief Information Security Officer (CISO) to lead and strengthen its enterprise-wide cyber security, information security governance, technology risk management, and regulatory compliance framework. Reporting directly to the CEO, this role will provide independent security leadership and oversight across the organization.
Role Summary
The Chief Information Security Officer (CISO) will serve as the organization's senior information security executive, responsible for safeguarding the confidentiality, integrity, and availability of information assets. The role will lead the development and execution of the cyber security strategy, governance framework, risk management program, regulatory compliance initiatives, and security operations across the enterprise.
Key Responsibilities
Strategic Leadership & Governance
- Develop and execute the enterprise cyber security and information security strategy aligned with business objectives and regulatory requirements.
- Establish, maintain, and enforce information security policies, standards, and governance frameworks.
- Act as the primary advisor to the CEO, Board of Directors, and senior leadership on cyber security and information security matters.
- Lead and contribute to Information Security Committee meetings and governance reporting activities.
- Provide regular updates on cyber security risks, incidents, compliance status, and security maturity to executive leadership and the Board.
Risk Management & Compliance
- Lead enterprise-wide cyber security risk assessments and risk management initiatives.
- Ensure compliance with applicable regulatory requirements, industry standards, and internal policies.
- Maintain information security governance frameworks aligned with recognized standards such as ISO/IEC 27001, NIST Cybersecurity Framework, and CIS Critical Security Controls.
- Coordinate and manage internal and external security audits, assessments, and regulatory reviews.
- Partner with legal, compliance, and privacy functions to ensure data protection and privacy compliance.
Cyber Security Operations
- Oversee security monitoring, incident detection, response, containment, recovery, and post-incident reviews.
- Ensure effective security operations through technologies and processes including SIEM, SOC, endpoint protection, vulnerability management, penetration testing, and threat intelligence.
- Lead cyber incident response activities and ensure timely reporting to relevant stakeholders and regulatory bodies where required.
- Develop and test cyber resilience, business continuity, and disaster recovery capabilities.
Identity & Access Management
- Own enterprise identity and access management programs.
- Ensure implementation of least-privilege principles, multi-factor authentication (MFA), privileged access management, and periodic access reviews.
- Strengthen access governance across critical business systems and applications.
Vendor & Third-Party Security
- Establish and maintain a vendor risk management framework.
- Conduct security due diligence and ongoing monitoring of critical third-party providers.
- Ensure contractual security requirements and risk mitigation measures are implemented and maintained.
Security Awareness & Culture
- Develop and deliver enterprise-wide cyber security awareness and training programs.
- Drive a strong security culture across the organization.
- Support leadership awareness programs, including Board-level training and cyber security education.
Team Leadership
- Build, lead, mentor, and develop the Information Security team.
- Establish clear goals, performance expectations, and succession plans for key security roles.
- Promote collaboration across technology, business, compliance, and risk functions.
Key Performance Indicators (KPIs)
- Achievement of regulatory compliance requirements with no significant security-related findings.
- Effective management and resolution of security incidents within defined timelines.
- Continuous improvement of cyber security maturity and security posture.
- Successful maintenance of relevant security certifications and standards.
- Timely remediation of identified vulnerabilities and security gaps.
- Completion of security awareness training programs across the organization.
- Strong governance reporting and Board engagement on cyber security matters.
- Effective management of third-party cyber security risks.
Required Skills & Knowledge
- Strong knowledge of cyber security and information security frameworks including ISO/IEC 27001, NIST CSF, and CIS Controls.
- Expertise in security operations, incident response, vulnerability management, threat management, and security monitoring.
- Deep understanding of identity and access management (IAM), cloud security, network security, and application security.
- Knowledge of business continuity management (BCM) and disaster recovery (DR) principles.
- Experience in cyber risk management, governance, compliance, and audit management.
- Strong stakeholder engagement, communication, and executive presentation skills.
- Proven ability to influence and engage with Boards, regulators, and senior management.
- Excellent leadership, people management, and change management capabilities.
Qualifications & Experience
- Bachelor's Degree in Information Technology, Computer Science, Cyber Security, or a related discipline.
- Master's Degree in Cyber Security, Information Technology, Business Administration, or a related field is preferred.
- Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP, and ISO/IEC 27001 Lead Auditor/Lead Implementer are highly desirable.
- Minimum 10–15 years of progressive experience in Information Security, Cyber Security, or Technology Risk Management.
- At least 5 years of experience in a senior cyber security leadership role such as CISO, Head of Information Security, or equivalent.
- Proven track record of leading enterprise cyber security programs, governance frameworks, and risk management initiatives.
- Experience within financial services, insurance, banking, or other highly regulated industries is highly advantageous.
- Experience engaging with regulatory authorities and Boards on cyber security, risk, and compliance matters is preferred.
Career Progression
Potential future career paths include:
- Group Chief Information Security Officer (Group CISO)
- Chief Technology Officer (CTO)
- Chief Information Officer (CIO)
- Chief Risk Officer (CRO)
If you are interested, please do share your profile at jobs@mindplus.global