Specialist/Information & Cybersecurity Risk at MTN Ghana
MTN Ghana View all jobs
- Accra
- Permanent
- Full-time
- To support the effective management of information security risks across the organization by identifying, assessing, and monitoring cybersecurity threats in alignment with the enterprise risk management framework.
- The role ensures that security risks are appropriately governed as part of the second line of defense, enabling informed decision-making and regulatory compliance across all regions of the business.
- Conduct and support periodic assessments of information and cybersecurity risks across business units and technology domains.
- Maintain and update the Information Security Risk Register and Dashboard to reflect current risk posture and mitigation status.
- Execute the Information Security Control Monitoring (ISCM) plan in alignment with the enterprise risk management framework and combined assurance model.
- Support the implementation of cybersecurity risk methodologies, ensuring alignment with MTN Group standards and regulatory expectations.
- Prepare and contribute to governance committee packs and reports, ensuring timely and accurate communication of cybersecurity risk issues to executive stakeholders.
- Assist in documenting and presenting information security risk reports to internal stakeholders and board-level subcommittees.
- Coordinate with business and technical stakeholders to track and support remediation of identified cybersecurity risks.
- Apply the Group Risk Escalation and Acceptance Policy to manage, escalate, and resolve critical risk issues.
- Facilitate periodic Business Impact Analyses (BIA) and support the development and review of disaster recovery and incident response plans.
- Maintain oversight of information security playbooks and ensure alignment with business continuity strategies.
- Conduct information security maturity assessments using MTN Group's model and identify areas for improvement.
- Perform gap analyses on critical business areas and recommend risk treatment actions.
- Collaborate with internal teams (e.g., IT, Legal, Compliance) to provide risk advisory on projects, third-party engagements, and new technologies.
- Support the definition and review of the OpCo's risk appetite, tolerance, and capacity in collaboration with Group Risk.
- Contribute to the development and delivery of cybersecurity awareness and training programs across the organization.
- Contribute to testing and simulation exercises to strengthen organizational readiness and response capabilities.
- Contribute to the development and execution of the annual integrated risk plan and risk-based audit planning.
- Support enterprise-wide risk workshops and the assessment of principal residual risks.
- Dynamic and highly competitive telecommunication & ICT industry
- Multi regulated environment
- Environmental, social and governance prioritized
- Localization a key objective for business and government
- Multinational environment - Risk & Compliance Group best practices
- Performance driven environment
- Diverse cultural environment
- Partnerships
- Bachelor's degree in information security, Computer Science, Risk Management, Business Information Systems, or a related field is required.
- Professional Certifications in Information Security Risk Management are highly desirable. Preferred certifications include:
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- ISO/IEC 27001 Lead Implementer or Auditor
- CompTIA Security+ or equivalent foundational certifications
- At least 3 years' experience in a related field.
- Information Security Frameworks and Standards: In-depth training on globally recognized frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, COBIT, and ITIL.
- Cybersecurity Risk Management: Practical training in identifying, assessing, mitigating, and reporting information security risks within enterprise environments.
- Regulatory and Compliance Awareness: Training on relevant data protection and cybersecurity regulations, including the Ghana Data Protection Act, GDPR, and telecom-specific compliance requirements.
- Governance, Risk, and Compliance (GRC) Tools: Hands-on training in the use of GRC
- Business Continuity and Incident Response: Training in business impact analysis, disaster recovery planning, and incident response coordination.
- Leadership and Stakeholder Engagement: Development in communication, influence, and collaboration skills to effectively engage cross-functional teams and support governance processes.
- Emerging Technologies and Threats: Ongoing learning on evolving cyber threats, cloud security, third-party risk, and digital transformation trends impacting telecom environments.
- Information Security Frameworks & Standards: In-depth knowledge of ISO/IEC 27001, NIST Cybersecurity Framework (CSF), COBIT 2019, and related information security governance models.
- Information Security Risk Management (ISRM): Working knowledge of ISRM methodologies, including risk identification, assessment, treatment, and monitoring practices.
- Threat Modeling & Risk Analysis: Familiarity with threat modeling techniques such as STRIDE, DREAD, OCTAVE, and their application in identifying and mitigating cyber risks.
- Incident & Crisis Management: Understanding of incident response processes, emergency preparedness, recovery strategies, and business continuity planning.
- Telecommunications Infrastructure & Business Processes: Awareness of mobile network architecture, telecom operations, and sector-specific risk exposures.
- IT Infrastructure & Architecture: Foundational understanding of IT systems, networks, cloud environments, and their associated security controls.
- Risk Intelligence & Trending: Ability to analyze and interpret risk trends, threat intelligence, and emerging vulnerabilities relevant to the telecom sector.
- Project & Change Management: Basic knowledge of project management principles and their integration with risk assessment in technology and business initiatives.
- Productivity & Reporting Tools: Proficient in Microsoft Excel, PowerPoint, and Word for risk reporting, analysis, and stakeholder communication.
- Ability to manage self and be a team player, good conflict management, ability to take and manage accountability
- Energy & Drive - Innovative, Takes initiative, result oriented and develops self consistently
- Interpersonal Skills – Leadership, customer centricity, collaborative and coaches & develops direct reports
- Personal Skills – Trustworthy, integrity and ethical in dealings
- Operating Skills – Ability to focus on priorities and plans, shares knowledge effectively
- Organizational Positioning Skills – Good written and verbal communication, presentation skills, commitment to the organization
- Global thinker, Analytical thinking and Problem-solving abilities.
- Lead with Care, Collaborate with Agility, Serve with Respect, Can Do with Integrity, Act with Inclusion
- Complete Candor, Complete Accountability, Active Collaboration & Get it done.
- Anywhere/Anytime work/ Ability to manage self/Personal accountability.
JobDirecta