-
Strategy & Governance: Lead the development and execution of the organisation’s information security strategy, ensuring alignment with overall business goals. Work closely with stakeholders to define and implement security policies, standards, and procedures.
-
Information Security Roadmap: Design and implement information security roadmaps and provide high-level guidance to ensure successful execution. Regularly review and update strategies to adapt to changing security landscapes.
-
Security Risk Management: Define and implement methodologies for information risk assessments, including risk identification, evaluation, and mitigation strategies. Work with governance and risk teams to address all risk management requirements.
-
Budget & Resource Management: Collaborate with other security roles to construct and manage the security budget. Ensure that necessary resources are allocated to meet the security needs of the organisation.
-
Standards & Processes: Identify, develop, and enforce security standards and processes that support the overall IT security policy. Ensure continuous monitoring and reporting to meet compliance and regulatory requirements.
-
Security Awareness & Training: Lead IT security awareness programs and provide ongoing training and certification for IT staff to enhance security knowledge across the organisation.
-
Security Incident Management: Oversee the organisation’s incident management framework and support loss prevention initiatives to protect against data breaches and cyber-attacks.
-
Compliance & Reporting: Ensure the application of security compliance in accordance with industry regulations and best practices. Report on security trends and risk management activities regularly to business stakeholders.
-
Architecture & Design Review: Participate in architecture and design reviews to ensure security principles and standards are applied. Provide input to reference architecture and guide integrated solutions.
-
Leadership & Team Collaboration: Lead and mentor the information security team, fostering a culture of collaboration and continuous improvement. Chair operational information security steering committees and participate in strategic security steering committees.
-
Business Communication: Translate complex technical security matters into business terms for stakeholders and senior leadership. Provide periodic trend analysis with a focus on capital and financial markets security.