IT Security and Risk Manager for an Insurance Company
Responsibilities
Create, implement and maintain policies, standards and guidelines covering IT Risk & Security Management (particularly in technology risks and information security risks);
Provide oversight on the policies such as Technology Risk Framework, Key Risk Indicators, Security Operation, and Audit Tracking & etc.;
Identify risks proactively and performs risk assessments
Responsible for the IT Disaster Recovery & IT-BCP;
Perform fire-calls for Data Invention requests;
Perform reviews of Information Classification deviations and put up recommendation for user departments
Conduct regular reviews on access control & sanctions;
Ensure all quality processes continue to operate effectively, such as CAPA (Corrective action and preventive action);
Lead all IT audit activities, which shall include the external (i.e.vendor) and internal assessments as well as all customer related, regulatory, as well as regional-governance audit activities;
Work closely and liaise with internal IT auditors or regulator, IT security compliance and reporting;
Perform IT Security Incident Management & Event Log Management;
Responsible for Penetration & Vulnerability Assessment, and performs the Vulnerablity & Threat Management reviews and supervise Penetration Testing as required;
Drive all IT Security related programmes or projects.
Initiate, facilitate, and promote on-going education activities to create IT security and incident response awareness for all staff;
Coordinate the project plans for IT Security related activities, monitor, track and escalate as required;
Work closely with information system owners and technical members to secure information and mitigate the risks;
Any other tasks as assigned by Head of Department.
Requirements
Degree/Diploma in Computer Science, Information Technology; specialization in IT Security preferred.
At least 5- 10 years of relevant experience with at least 2 years in leading a team;
Knowledge in Insurance is preferred;
Familiar and hands-on experience in effecting MAS regulatory guideline (e.g. MAS TRM Notice & Guidelines, Outsourcing guideline, etc.);
Familiar with core platform (AS/400, Wintel, storage, network, databases) and security technologies preferred;
Experience in vendor evaluation, validation and assessment advantageous;
Familiar with Data Centre operations and Disaster Recovery will be advantageous;
Highly driven and independent;
CISSP, SSCP, CISM, CISA certification will be advantageous;
Highly driven and independent;
Excellent analytical, written and communication skills required.
Proven track record on the ability to develop good working relationships.