-
Develop, implement, and maintain information security policies, procedures, and standards in line with industry best practices (e.g., ISO 27001, NIST).
-
Identify, assess, and manage information security risks across systems, applications, and infrastructure.
-
Monitor security controls and conduct regular vulnerability assessments and audits.
-
Ensure compliance with relevant regulatory and contractual requirements (e.g., NDPR, GDPR, client security requirements).
-
Lead incident response activities, including investigation, containment, remediation, and reporting of security incidents.
-
Collaborate with IT, Engineering, HR, and business teams to embed security-by-design principles.
-
Oversee user access management, data protection controls, and secure handling of sensitive information.
-
Conduct security awareness training for employees and promote a strong security culture.
-
Manage third-party and vendor security assessments.
-
Prepare security reports, risk registers, and metrics for management review.
-
Support internal and external audits related to information security.