Head IT Security, Governance, Risk & Controls Job at Zambia National Commercial Bank - Career Opportunity in Zambia

Vacancy title:
Head IT Security, Governance, Risk & Controls

[ Type: FULL TIME , Industry: Financial Services , Category: Computer & IT ]

Jobs at:

Zambia National Commercial Bank

Deadline of this Job:
26 July 2020  

Duty Station:
Within Zambia , Lusaka , South - Central Africa

Summary
Date Posted: Tuesday, July 21, 2020 , Base Salary: Not Disclosed


JOB DETAILS:
Zanaco PLC is inviting applications from suitably qualified and experienced individuals for the following job aimed at contributing to the Bank’s strategic vision, in the Information Technology Division under the IT Security, Governance, Risk & Controls Department at Head Office: –
HEAD IT SECURITY, GOVERNANCE, RISK & CONTROLS (X1)
JOB PURPOSE
The role is responsible for Planning, Designing, Directing and Implementing the overall functions of the Applications Security Assurance, Information Technology Continuity, Network Security and Information Technology Security Operations as well as cross-functional engagements with the Integrated Risk Management (IRM) Team to ensure security and governance for the Bank countrywide. The responsibility oversees the enhancements and enforcement of all Information Technology Security Controls and Operations Policies, Procedures and Internal Controls that will drive the entire Security environment culture across the Division and the Business as a whole to assure compliance with applicable Regulatory and Legal requirements as well as Best Practices.
The role will ensure that the Bank’s Information Technology Business Strategy is achieved through continuous improvement and focusing on innovating new Security Solutions, adherence to Budget and Performance, designing risk controls and implementing Industry Best Practice across the Organization. The role holder will work across multiple frameworks and regulatory standards including, but not limited to, NIST, ISO, PCI-DSS and will liaise with all Business groups including but not limited to Legal, Compliance and other stakeholders within and outside Zanaco to implement new solutions and processes as well as document and remediate outstanding issues. .

Under the supervision of the Chief Information Officer, the following are among the Job Key Responsibilities: –
• Creating and implementing a strategy for the deployment of information security technologies
• Performing IT security risk assessments and reporting on ways to minimize threats
• Monitoring security vulnerabilities and hacking threats in network and host systems
• Tracking latest IT security innovations and keeping abreast of latest cyber security technologies
• Communicating with key stakeholders about IT security threats
• Implementing an effective process for the reporting of security incidents
• Developing strategies to handle security incidents and trigger investigations and overseeing the investigation of reported security breaches
• Managing the IT security team, security experts and advisors
• Complying with the latest regulations and compliance requirements
• Managing the daily operation and implementation of the IT security strategy
• Conducting a continuous assessment of current IT security practices and systems and identifying areas for improvement
• Running security audits and risk assessments and ensuring compliance and governance is met
• Delivering new security technology approaches and implementing next generation solutions
• Overseeing the management of the IT security department, giving leadership to the team and developing staff
• Developing and implementing business continuity plans to ensure service is continuous when a change programme is introduced or a security breach occurs or in the event that the disaster recovery plan needs to be triggered
• Protecting the intellectual property of the organization at all times
• Devising strategies and implementing IT solutions to minimise the risk of cyber-attacks
• Information Technology Business Continuity Risk Planning, Testing, Strategy, Implementation to ensure embedding of the Business Continuity Management culture and reporting.
• Management and coordination of the Disaster Recovery Plan, updating it as and when it is needed, managing the Disaster Recovery Process as well as planning for the Disaster Recovery Functions of Information Technology
• Responsible for Developing, Implementing and Monitoring Policies, Processes and Procedures for the overall Integrity of the Information Technology Disaster Recovery System for the Bank.
• Inspection of Backup Procedures, Backup Storage, and Backup Data Integrity.
• Coordinating all Information Technology related Audit Investigations with all Stakeholders to validate non-conformities, and spearhead the Process.
• Planning and Management of Security Systems and Network across the entire Bank Topology and ensuring Network and Firewall Security and log Management.
• Leading the Development and Implementation of a strong, cost effective and coherent Network and Firewall Security Strategic for the Bank.
• Management and Maintenance of Vendor relations for off the shell Services and Service outsourcing for Information Technology Security.
• Ensure Network Security Best Practices are implemented through Auditing: Router, Switch, Firewall Configurations, Change Control and Monitoring.
• Responsible for Network Security Budgeting of Security Tools/ Training for Security Operations Analysts (SOC).
• Designing and implementing of Information Security to the Cyber Security Tools and Processes within the Bank Information Technology Security Team to ensure overarching of Data Security Strategy for the institution Threat Management and Response initiatives.
• Regularly review Threat Intelligence and thus disseminate information and countermeasures concerning Threats and Vulnerabilities.
• Provision of input to Technology Security Controls and Operations Strategy and Budget.
• Provide Technical inputs, evaluate and recommend new and emerging security Products and Technologies.
• Act as Risk Control Self-Assessment (RCSA) champion for IT Division and the entire Business.
• Evaluate risk likelihood and impact and prioritize them for analysis and response planning.
• Ensure that all risks applicable to any area is identified, assessed, reported and captured in the Risk Register.
• Ensure all emerging risks are reported and mitigating factors put in place.
• Identify, monitor and report Key Risk Indicators (KRIs) in respective unit/department.
• Ensure to operate within the given risk appetites and report any breaches promptly.
• Implement and Close all Audit recommendations, identified control weaknesses from Risk and Control Self- Assessment (RCSAs), Consultancy Reports or Customer Complaints and Risk events.
• Participate in the annual review of Procedure Manuals when requested.
• Ensure familiarization with and adherence to the Zanaco Enterprise Risk Management framework and participate in Risk Management Trainings organized by Integrated Risk Management (IRM) Unit.
• Any other responsibilities as may be assigned by management
INTERNAL/EXTERNAL CONTACT
• External: Vendors, Consultants, Industry Networks
• Internal: All Divisions


Job Skills: Not Specified


QUALIFICATIONS AND EXPERIENCE
• IT related Degree
• Masters in ICT Security will be an added advantage
• At least eight (8) years’ experience working experience in IT Technology with experience in Banking
• Certifications Required: ISO 27001, COBIT 5, ITIL, CISM, CISA, CISSP
JOB CORE COMPETENCIES
• Excellent communication skills – verbal and written
• Presentation and Reporting skills
• Leadership skills
• Research/ Information gathering skills
• Networking Skills
• Stakeholder Management
• Budget Management
• Drive for results


Job Education Requirements: IT related Degree


Job Experience Requirements: Not Specified


Work Hours: 8

 

{module 312}

Job application procedure
All applications must have an application/cover letter and detailed curriculum vitae indicating the position being applied for in the subject line and should be sent by email to vacancies@zanaco.co.zm  no later than Sunday, 26th July 2020.
Kindly note that you MUST attach copies of Grade 12 and Tertiary qualifications along with the application cover letter and curriculum vitae. Applications sent without these attachments WILL NOT be considered.
ONLY SHORTLISTED APPLICANTS WILL BE COMMUNICATED TO.
Zanaco provides equal opportunity in employment for all qualified persons and prohibits discrimination in employment (women are encouraged to apply).


All Jobs

QUICK ALERT SUBSCRIPTION

{module 316}

Job Info
Job Category: Computer/ IT jobs in Zambia
Job Type: Full-time
Deadline of this Job: 26th July 2020
Duty Station: Lusaka
Posted: 21-07-2020
No of Jobs: 1
Start Publishing: 21-07-2020
Stop Publishing (Put date of 2030): 21-07-2065
Apply Now
Notification Board

Join a Focused Community on job search to uncover both advertised and non-advertised jobs that you may not be aware of. A jobs WhatsApp Group Community can ensure that you know the opportunities happening around you and a jobs Facebook Group Community provides an opportunity to discuss with employers who need to fill urgent position. Click the links to join. You can view previously sent Email Alerts here incase you missed them and Subscribe so that you never miss out.

Caution: Never Pay Money in a Recruitment Process.

Some smart scams can trick you into paying for Psychometric Tests.