
Information Security Risk Officer by Standard Chartered Bank
- Accra
- Permanent
- Full-time
- Do the right thing and are assertive, challenge one another, and live with integrity, while putting the client at the heart of what we do
- Never settle, continuously striving to improve and innovate, keeping things simple and learning from doing well, and not so well
- Be better together, we can be ourselves, be inclusive, see more good in others, and work collectively to build for the long term
- In line with our Fair Pay Charter, we offer a competitive salary and benefits to support your mental, physical, financial and social wellbeing.
- Core bank funding for retirement savings, medical and life insurance, with flexible and voluntary benefits available in some locations
- Time-off including annual, parental/maternity (20 weeks), sabbatical (12 weeks maximum) and volunteering leave (3 days), along with with minimum global standards for annual and public holiday, which is combined to 30 days minimum
- Flexible working options based around home and office locations, with flexible working patterns
- Proactive wellbeing support through Unmind, a market-leading digital wellbeing platform, development courses for resilience and other human skills, global Employee Assistance Programme, sick leave, mental health first-aiders and all sorts of self-help toolkits
- A continuous learning culture to support your growth, with opportunities to reskill and upskill and access to physical, virtual and digital learning
- Being part of an inclusive and values driven organisation, one that embraces and celebrates our unique diversity, across our teams, business functions and geographies - everyone feels respected and can realise their full potential.
- Recruitment assessments - some of our roles use assessments to help us understand how suitable you are for the role you've applied to. If you are invited to take an assessment, this is great news. It means your application has progressed to an important stage of our recruitment process.
- Review and alignment of country Information security program with the Group security strategy
- Effectively and collaboratively identify, escalate, mitigate and resolve risks associated with the bank's information assets.
- Periodically inform the Board on latest developments in the cyber security universe
- Assure that process owners are escalating risks and control gaps when decommissioning of systems and data sanitization activities.
- Assure measurement of effective management of cyber threat intelligence by 1st Line ICS team.
- Assure process owners are creating awareness among staff on cyber threats and their controls.
- Assure that business process owners are managing data centers as per standards.
- Assure that the process owners are escalating compliance matters to mitigate security aspects of networking devices (servers, routers, firewalls, etc.) under applicable policies, standards, and procedures.
- Delegation of Authority from the Group CISRO for ICS risk management engagement with country
- Overseeing and challenging 1st line ICS risk proposals and risk-taking activities;
- Intervening in 1st line activities if they are not in line with existing or adjusted Risk Appetite;
- Monitoring of ICS risks and associated remediation plans across the country using the Group CISRO Governance Risk Type Framework;
- Assuring the 1st line implements controls to comply with applicable laws and regulations as defined by the Group CISRO Policy team and escalate significant regulatory non-compliance matters and developments to the Group CISRO;
- Conduct periodic information security assurance on the ICS risk profiles (including infrastructure) submitted by 1st line and suggest improvements.
- Promoting a healthy ICS risk culture and good conduct within the country.
- Lead through example and operate with the appropriate culture and values.
- Uphold and reinforce the independence of the second line ICS Risk function.
- Deliver the defined aspects of the ISRO role to support the Group's ICS risk management approach and objectives.
- Ensure that the Country role is managed in accordance with the defined Group CISRO Governance Risk Type Framework and associated Policy and Standards; and those issues are identified, escalated, and addressed as appropriate.
- Establish strong ties into the relevant country leadership, governance, risk, and control committees to ensure adequate monitoring, tracking and governance of ICS risk.
- Drive integration of ICS Risk Type Framework into the country and utilize for the ongoing governance of country risk.
- Display exemplary conduct and live by the Group's Values and Code of Conduct.
- Take personal responsibility for embedding the highest standards of ethics, including regulatory and business conduct, across the countries. This includes understanding and ensuring compliance with, in letter and spirit, all applicable laws, regulations, guidelines and the Group Code of Conduct.
- Effectively and collaboratively identify, escalate, mitigate and resolve risk, conduct and compliance matters.
- Exercise authorities delegated by the Board of Directors and act in accordance with Articles of Association.
- ISROs
- Country CROs
- Country HICSs
- Country CIOs
- Country Compliance Officers
- Country CEOs
- Banking Regulators
- Global Head, Security Technology Services
- Head of ICS Governance
- Head of ICS Policy
- Group Internal Audit
- Head of ICS Assurance and Testing
- Head of ICS Training, Awareness & Exercises
- Establish strong relationships with identified stakeholders across the country and understand their strategic goals, to ensure ICS alignment.
- Articulate the value of ICS controls and their bottom-line impact to Country's security and resiliency.
- Prepare, present and challenge in a 2nd line capacity at relevant risk committees, steering groups and cross-business opportunities.
- Perform Delegation of Authority (DoA) responsibilities for Group CISRO as defined for the countries.
- Measure efficient and effective management of ICS risk for the countries.
- Validate the accuracy of KRI's and KCI's and other risk ratings, as well as process designs, to meet policy requirements.
- Ensure that Process Owners are escalating risk, control, and process deficiencies appropriately in accordance with the relevant risk frameworks.
- Build trusted working relationships with other security functional heads, risk and compliance counterparts, and country stakeholders.
- Utilize appropriate risk management tool(s) to manage, track and monitor ICS risks across the countries.
- Maintain sufficient and appropriate evidence of work performed for review by Group Internal Audit and others.
- Monitor, assess and advise countries on acceptable risk tolerances based on policy and control environment and the evolving regulatory and threat landscape. (Knowledge of Pakistan regulatory environment will be an added advantage)
- Master's in Information Technology / Cybersecurity
- Information Security certifications and courses
- Trainings & Courses attended on security audits
- Familiar with and hands on experience of working on Security best practices and frameworks.
- Minimum 5 years of experience, having worked on similar roles.
JobDirecta