About the Business & Position Overview
Compliance Manager
Job Profile
Key Responsibilities
Risk Management
Governance Framework Development
Compliance Management
Audit Coordination
Policy Development
Job Description
Implement security controls, risk assessment framework, and program that align to best
practices and regulatory requirements.
- Assist with implementation of ISMS across the organization entities
- Good understanding of the security technologies such as DLP, NGAV, EDR, CASB, PIM/PAM,
Firewall, Proxy, Email ATP, WAF etc.
- Well versed with well-known security frameworks such as ISO 27001:2022 / NIST CSF / PCI
DSS / ISO 22301.
- Ensure key information security risks and issues are identified, addressed and resolved in a
timely manner.
- Assess efficacy of security controls, document and report control failures and gaps to
stakeholders. Provide remediation guidance and prepare management reports to track
remediation activities.
- Ensure third party security assessments - Assist with Third Party Risk Management framework
including policy updates, procedures, due diligence questionnaires and the monitoring of third
parties- adherence to information security and data privacy obligations.
- Develop relevant metrics, analyse data, identify trends and help drive improvements to the
control environment
- Remains current on best practices and technological advancements
- Drive security awareness program across the organisation
Qualification Details
Essential Qualification: - Graduate in any discipline (Preferably in IT / Computer Science)- Excellent interpersonal skills, comfortable working at all levels within an organization and in a widevariety of situations.- Relevant industry certification such as ISO 27001 Lead Auditor/ ISO 27001 Lead Implementor / CISM etc. (at least one) is highly desirable.- Broad level of knowledge of security and risk issues and techniques across platforms.- Excellent knowledge of methodologies, processes and tools associated with supporting this functioneffectively.
Preferred Qualification: same as above
Experience Details
Essential Experience: Must have GRC experience for at least 6-8 years.Experience of leading an ISMS as part of an ISO27001 certified program.