Sagicor Group Jamaica is looking for the ideal candidate to join our IT and Data Security team in the capacity of: IT Security Officer - Risk and Compliance
The selected candidate will be responsible for ensuring appropriate controls are in place for the security of information assets. This position plays a key role in the review and development of policies, implementation of internal IT controls and compliance improvement; therefore ensuring that our procedures and activities comply with all regulatory requirements and internal policies. Additionally, where necessary to lead or provide subject matter expertise in risk assessment exercises.
Key Duties and Responsibilities:
- Performing security reviews and risk assessments.
- Serve as project lead and/or subject matter expert on IT security projects.
- Address questions from internal and external audits and examinations.
- Develop policies, procedures and standards that meet existing and newly developed policy and regulatory requirements.
- Facilitate IT security/risk training and awareness of applicable standards, risks and industry best practices.
- Monitors performance of risk remediation tasks, changes related to risk mitigation & reports on findings.
- Maintains oversight of IT and vendors regarding the security maintenance of their systems, services and applications.
Academic Qualifications/Specialized Skills/Competencies:
- Bachelor’s degree in either Information Technology, Computer Science or a Cyber Security equivalent qualification from a recognized tertiary institution
- Qualifications desired are CISA and/or CISSP.
- Minimum of three years’ experience conducting IT compliance assessments
- Minimum of two years’ experience in administering IT security controls in an organization
- Project management skills and/or certification would be an asset.
- Effective communication skills
- Knowledge of technical infrastructure, networks, databases and systems in relation to IT and/or Data Security risks
- Ability to communicate effectively both orally and in writing
- Ability to produce reports for technical and non-technical stakeholders, i.e. Senior Management
If this role is of interest to you kindly submit an application no later than November 30, 2020. While we appreciate all applications, only shortlisted applicants will be contacted.