Role Purpose
The purpose of the role is to manage the Technology Security Governance, Risk, Compliance and Assurance needs across Vodafone Ghana. To further provide security assurance, guidance and support to high profile projects according to company defined policies and requirements, best practice and local/international standards (PCI, SOX, ISO27001, GDPR, POPIA and Cyber Crime Bill of 2015) relevant to the technology security area. This role requires the individual to have credible experience in Information Security and Cyber Security Governance, Risk and Assurance based on proven frameworks such as COBIT 5, ISO27001/2, and the NIST Cybersecurity Framework. As a key member of the Vodafone Ghana Cyber Security team, the candidate should be comfortable with driving information security governance and assurance ideas and communicating clearly with technical as well as non-technical audiences.
Job Responsibility
- The incumbent will direct, develop, implement, monitor, and maintain a comprehensive Vodafone Ghana information security governance, risk, and compliance strategy
- Ensure security is embedded in IT Systems and Network Infrastructure (Mobile, IS and Enterprise) across the Vodafone Ghana network
- Defining, implementing, and efficiently maintaining technology security controls and requirements
- Ensure compliance with Legal and Regulatory requirements
- Provide SME input to Technology Security Policy requirements and procedures
- Manage, plan, implement and monitor Vodafone Ghana information security awareness and training program.
- Provide accurate and timely reporting of technology security risks identified during project engagement and propose remediation and mitigation options
- Ensure alignment of information security governance with Vodafone Ghana’s business objectives, the information security strategy, plans and controls
- Ensure compliance with the applicable legislative and regulatory interpretation and corporate risk appetite;
- Lead, develop, manage, and maintain the network-wide information security governance deliverables lifecycle including compliance measurement, deviations, and exemptions.
- Engage with the stakeholders on compliance to control effectiveness and deficiencies in the design and operating effectiveness of information security controls, design and recommend opportunities for continuous improvement.
- Develop, manage, and implement the Vodafone Ghana information security audit and assurance plans and schedules, including any specific business needs and requirements (including PCI, ISO27001, GDPR, POPIA, Cyber Crime Bill)
- Participate in IT general controls and compliance testing activities and/or audits;
Professional / Technical Competencies
- Bachelor’s Degree in Computer Science, Information Security, Engineering or Technology or other related fields.
- Minimum of 5+ years of experience in a Tech Security role.
- Knowledge of technology management/compliance frameworks such as ISO/IEC 27001, SOC 2, SOX, ITIL, COBIT, and NIST.
- Knowledge of legal, regulatory and privacy requirements, such as Personally Identifiable Information (PII) Protection and Payment Card Industry (PCI)/Data Security Standard.
- A diverse security background with knowledge in several areas including layered security architecture; internet protocols; firewalls; VPN technologies, IDS/IPS, network access control and network segmentation, anti-malware and spam technologies; risk and vulnerability assessments, and compliance.
- Security concepts related to DNS, routing, authentication, VPN, proxy services and DDOS mitigation technologies
- Windows, UNIX and Linux operating systems.
- Network security architecture development and definition.
- Web Security & Encryption
How To Apply For The Job | Cyber Security Compliance Specialist at Vodafone Ghana
To submit your application, click on the link below and complete all relevant fields on the online application form.
Application closes on 15 December 2022