Implementing and maintaining information security management systems;
Preparing and compiling, updating, training, and documenting information security policy/procedures/instructions based on international standards and upstream requirements.
Defining and maintaining strategies, frameworks, and methods for assessing, responding, and monitoring security risks in consultation and cooperation with organizational units.
Defining and maintaining strategies, frameworks, and methods for evaluating, responding to, and monitoring risks related to privacy.
Identifying, analyzing, and evaluating the perspective of current and future threats to the organization and creating and maintaining an overview of the risks and threats of the organization's technological environment (creating and maintaining the security risk profile of the organization).
Identifying, valuing, and maintaining assets and services and evaluating technical risks.
Communicating and interacting with organizational units to follow up on technical measures and solutions.
Requirements
Mastering information and network security concepts.
Mastering information security management system standards (including ISO/IEC 27001:2022 and ISO/IEC 27002:2022).
Mastering the risk management process (technical and systemic) and related standards (including ISO/IEC 27005:2022).
Familiarity with business continuity management and cyber resilience (BCP/DRP) and relevant standards (including ISO 22301:2019).
Familiarity with payment information security standards and standards (including PCI-DSS).
Familiarity with the local information security requirements (including Shaparak, AFTA, and Passive defense).
Information security management system (ISMS) implementation and audit experience.
Familiarity with common threats and vulnerabilities in the field of information technology and the payment industry.
Mastering of writing techniques and skills in compiling technical and management documents and reports.
Teamwork spirit, responsibility, follow-up spirit, and individual improvement skills.