Information Governance Manager

  • Full-time

Job Description

GlobeMed Group, the largest Healthcare Benefits Management company in the MENA region is looking for an Information Governance Manager who will create, implement, and oversee the strategies and programs designed to reduce and mitigate information security risk across GlobeMed to a level tolerable to the organization. The role will establish and lead an enterprise-wide information security and assurance function, ensuring that confidentiality, integrity, and availability requirements of information systems and assets are identified and managed appropriately.

Main Duties:

  1. Provide direction on information security to the information security staff, across the central IT division, and enterprise-wide.
  2. Lead programs and processes to monitor the emergence of new threats and vulnerabilities, assessing impacts and driving responses as appropriate.
  3. Ensure that clear and timely business advice is provided to executive management on key information security and assurance issues.
  4. Establish an information security and risk management functional capability and framework across the organization.
  5. Ensure that information security and risk is adequately represented on relevant business and governance forums and is known, well-integrated, and addressed across the enterprise.
  6. Oversee and coordinate all aspects of alignment of Information Security Management System (ISMS) with ISO 27001.
  7. Create, manage, deliver to the staff, and review effective information security awareness training.
  8. Ensure that all IT and information security programs are in compliance with applicable laws, regulations, and policies.
  9. Collaborate with application owners to understand and address (as appropriate) the risk position around key business applications and processes to build the Business continuity Plan and Disaster Recovery Plan
  10. Conduct information security risk assessments across the enterprise at suitable intervals. Ensure that key risk issues are understood, communicated, and tracked on the risk register.
  11. Regularly verify that required information security and risk controls are in place, raising findings as noncompliance is found and driving improvement.
  12. Ensure that internal and external audits are supported in development of an annual strategic audit plan

Qualifications

Education:

Bachelor’s degree in communication engineering, computer science or Information systems

Experience/Knowledge:

  • 13+ years of experience in security related field
  • Security certifications such as CISSP, CISM, CRISC, CEH highly desired
  • Knowledge and expertise of security standards, concepts, principles and processes
  • Experience with common security tools such as Antivirus, Firewalls, VPNs, Intrusion Prevention/Detection Systems, Vulnerability Scanning, Application Whitelisting, Public Key Infrastructure, WAF, Security Incident Logging & Monitoring, SIEM, Event Correlation, OS hardening, and File Integrity Management

Skills/Competencies:

  • Ability to handle security incidents
  • Strong written and verbal communication skills and ability to effectively interface with both technical and business staff

By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply