- Project Manager for several projects in the department including planning, organizing and implementing several projects, preparing requests for proposals (RFPs), attending workshops for vendors, performing technical evaluation for proposals, combining scores with financial evaluations and selecting winning vendors.
- Follow up the implementation and projects plans and managing projects with vendors and other Arab Bank departments to achieve completion within the deadline time and planned budget.
- Contribute in the event monitoring and incident handling at the bank through different security solutions such as MMS, DDOS, SIEM, FIM, Anti-Phishing, by approving the scope, communicating with the vendors, follow up the implementation, assigning tasks to resources, reviewing the reports, and follow up and the remediation plans.
- Manage bridging gaps and closing the findings reported by audit, penetration testing, vulnerability management solutions, and MSS in coordination with the IT department.
- Define and review the security requirements for information systems, and follow up on the code reviews, penetrations tests, and vulnerability assessments.
- Participate in the Information Security monthly dashboards presented to Information Security Committee, and participate in developing the Information Security Policies and frameworks such as the Incident Management framework and procedures, and coordinate the efforts with all stakeholders to roll out and implement the security framework across the organization.
- Manage the regulatory compliance for Arab Bank PLC, by assessing the compliance level of AB PLC with all the InfoSec & BC related regulations issued by the central banks in the countries where AB reside. Then creating action plans and following up till full compliance is achieved.
- Contribute in applying the security measures required to support compliance with the Payment Card Industry Data Security Standards (PCI DSS) on all system components that are included in or connected to the cardholder data environment.
- Perform risk assessments throughout the bank's network in all regions to classify all information assets and find solutions and controls for vulnerabilities. Follow up implementing the proposed controls to minimize the risks imposed. Assess security issues and risks in order to give suggestions on whether such risks should be accepted or remediated, and review and approve policy exceptions.
- Manage the Information Security Department expenses, estimating budget and man-days on yearly bases, and monitor the Information Security projects variables (cost, effort, scope, etc.) against the project management plan and the project performance baseline.
- Produce monthly, quarterly and annual budget and expenditure status reports and prepare projects budget revisions for Arab Bank EPMO & sponsor in coordination with Financial Control department.
- Liaise with the Information Technology Department to implement the required technical controls, RFP preparations, vendor selection and follow up projects implementation and progress, and provide security consultancy where needed.
- Participate in the Information Security Incident Response Team, which is responsible for tracking any unusual or suspicious network behaviors and attacks.
- Participate in developing, maintaining, and promoting the Information Security Awareness program.
- Company industry:
- Banking
- Job role:
-
Information Technology