Cyber Risk and Compliance Manager İş İlanı

İşveren Hakkında

QUALIFICATIONS AND JOB DESCRIPTION

In line with FIBA's information security strategies, the Cyber Risk and Compliance Manager is responsible for the leadership in designing, prioritizing and applying the policies, procedures and instructions needed in compliance with the information security governance and regulations of the affiliates. In order to control all risk management and compliance activities within the Fiba Group, the candidate will work on monitoring second level security controls, following the action plans and handling the relevant risks in an integrated manner within the corporate risk management.

Responsibilities:

• Evaluating the effects of risks originating from information security and including them in corporate risk management.

• Carrying out and reporting the 2nd level monitoring studies on the 1st level controls performed by the information security personnel.

• Following the status of the action plans prepared by IT and business units regarding the issues identified in internal or external audits or examinations on information security issues.

• Providing necessary guidance or sharing expectations as an internal consultant in information security studies when necessary.

• Writing Information Security Policy / Procedure / Instruction in accordance with the compliance processes with laws, regulations and relevant legislation, monitoring and auditing the compliance of these procedures with metrics.

• Ensuring compliance with the Personal Data Protection Law within Fiba Group. Being an expert on prioritizing and addressing technical measures.

Operating the lifecycle of data inventory keeping, data classification & labeling, data masking, secure data storage and destruction along with data governance.

Qualifications:

• Excellent leadership, self-motivated, critical thinking, strong problem-solving, strong written and verbal communication skills,

• 6-8 years of work experience in the relevant field,

• Ability to manage team, process, project, program and people management experience,

• Having knowledge of information security risk management concepts,

• Having knowledge of laws, regulations, standards and frameworks related to information security,

• To be able to understand audit trails or alarm records from security systems,

• Having relevant CRISC – CISA – ISO27001 LA certificates is a plus.


*In recruitment processes, Fiba Group is commited to avoid all forms of discrimination and respect the principles of gender equality.