Information Security Manager
To Manage, and lead all activities to protect JCDC digital and physical information assets by Operating within the Information Security division, implementing and maintaining our data security policies and procedures, ensuring that JCDC data remains secure and in compliance with all regulatory requirements. And coordinate with various teams across the organization to identify weaknesses, manage data security incidents, and provide strategic guidance on data protection.
Key Accountabilities:
Data Security
- Manage all activities related to the implementation of JCDC data security strategy to ensure alignment with business strategy.
- Manage all activities related to development and enforce data security procedures, general instructions, and admin procedures in line with JCDC goals and compliance requirements.
- Manage and respond to data security incidents, including conducting post-incident analysis and implementing preventive measures to avoid future occurrences.
- Manage Collaboration with cross-functional teams to protect a defined data asset inventory.
- Manage Collaboration with all internal departments to ensure data security best practices are integrated throughout the organization.
- Manage all activities related to training and awareness programs execution to educate employees on data security practices and the importance of protecting classified information.
- Manage all activities related to the selection and implementation of data security tools and technologies to enhance our security posture.
- Manage all activities related to Monitor industry trends, threats, and best practices in data security to keep our policies and procedures up to date.
- Provide expert advice and guidance on data security matters to senior management and other key stakeholders.
Identity and Access Management
- Manage Collaboration with data owners to define and establish access controls for classified data resources.
- Manage all activities related to conduct and coordinate reviews of access controls and permissions for classified data resources.
- Manage all activities related to the process for granting, modifying, and revoking access to data resources, ensuring that these actions are performed in line with established policies and are authorized by the respective data owners.
- Manage all activities for approvals for identity and access Management requests for database, dataset, USB, SAP, cloud drives, e-vaults, internet URL access, Data Loss Prevention (DLP), and Rights Management Services (RMS) to prevent data breaches.
- Manage all activities related to monitor user access review activities across JCD data systems.
Data Privacy
- Manage all activities related to the development and implementation of processes for efficiently handling data subject requests, such as access, rectification, deletion, etc...
- Manage Collaboration with all departments to ensure data privacy best practices are integrated throughout the organization.
- Manage all activities related to monitoring the implementation of the provisions of the Law and its Implementing Regulations and manage requests related to Personal Data following the provisions of the Law and its Implementing Regulations in collaboration with the cyber security GRC.
- Manage all activities related to the selection and implementation of data privacy tools and technologies to enhance our security posture.
- Manage and lead the process of conducting Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new and existing projects, systems, or processes.
- Manage all activities related to the organization's data breach response and notification procedures, ensuring a timely and coordinated response to any data privacy incidents.
Strategic Contribution
- Ensure effective cascading of the divisional strategy into sectional business plans to ensure vertical alignment and horizontal integration with other interfacing strategies.
People Management
- Manage the effective achievement of assigned objectives through the leadership of the designated section by setting individual objectives, managing performance, developing and motivating staff to maximize sectional performance.
- Lead the talent development initiatives for the assigned section, collaborating with technical/discipline experts and ensuring talent availability to fit business requirements.
Budgeting and Financial Performance
- Manage the preparation, recommend the sectional budget, and monitor financial performance versus the budget while ensuring all sectional activities align with the approved guidelines.
Policies, Systems, Processes & Procedures
- Manage and ensure effective implementation of policies, procedures and controls covering all areas of assigned sectional activity so that all relevant procedural/legislative requirements are fulfilled while delivering a quality, cost-effective service.
Continuous Improvement
- Lead the identification of opportunities for continuous improvement and sustainability of systems, processes, and practices considering global standards, productivity improvement, and cost reduction.
Reporting
- Ensure that all department reports are prepared timely and accurately and meet JCDC requirements, policies, and quality standards.
Qualification, Experience, & Skills:
Minimum Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or any related field from a reputable university. (Master’s degree preferred)
- One or more of the following qualifications are highly desirable:
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
Minimum Experience:
- 8 years of experience in a similar field – 3 years in managerial role.
Job-Specific Skills (Generic / Technical):
- Solid knowledge in information security, independently executes tasks and solves routine challenges.
- Solid knowledge of Data Information Security.
- Excellent use of English (must) and Arabic language (preferred).
- Excellent verbal and written communication and presentation skills, with the ability to effectively present information.
- Proficiency in using Microsoft Office Suite (Word, Excel, PowerPoint, and Outlook)
- Ability to quickly learn and adapt to new technology tools and software used within the organization.
- Demonstrates understanding of the cultural and professional environment in KSA and the GCC region.
- Good understanding of relevant market practices and applicable laws & regulations, with the ability to interpret and apply knowledge to ensure compliance
- Proficient in essential technical skills related to the role, including knowledge of industry-specific tools, software, and methodologies, enabling effective task execution.
- Demonstrate proficiency in essential soft skills as per JCDC Competency Framework based on the role’s level of responsibility.