Description
We are seeking a highly experienced InfoSec Officer to lead our information security initiatives, particularly focusing on the unique challenges of large-scale events. This role is pivotal in ensuring robust compliance with information security policies both during and outside of event periods. The successful candidate will be responsible for developing, implementing, and managing our Information Security Management System (ISMS), including all related policies and procedures. You will conduct comprehensive risk assessments, manage security incidents from detection to resolution, and oversee our disaster recovery planning. This position requires a proactive leader to monitor for vulnerabilities, implement effective safeguards, and cultivate a security-conscious culture through staff education and awareness programs. Your expertise will directly contribute to maintaining a secure and resilient information environment for the entire organization.
Requirements
1. 8+ years of combined experience in systems, network, and IT security.
2. 5+ years of dedicated experience in Information Security.
3. Bachelor’s Engineering Degree in Computer Science, Electronics & Communication, or a related field.
4. Professional certification in Information Security from a recognized body such as ISACA (e.g., CISM, CISA) or ISC2 (e.g., CISSP).
5. Demonstrated experience in developing, implementing, and enforcing Information Security policies and procedures.
6. Proven expertise in conducting formal risk assessments and managing risk treatment plans.
7. Hands-on experience in managing the full lifecycle of security incidents, from reporting to root cause analysis.
8. Experience with developing and maintaining Disaster Recovery (DR) and Business Continuity Plans (BCP).
Desirable
1. Experience managing information security for large-scale public events.
2. Strong project management skills.
3. Experience in coordinating and leading an Information Security Management System (ISMS) committee.
4. Advanced knowledge of network security management and malicious code prevention.
5. Excellent communication and leadership skills for promoting security awareness.