US

Vacancy: Chief Information Security Officer (CISO)

Date 18 Nov 2021
Location Accra
Job Type Permanent
Industry Financial Services/Non-Banking
Description


Company Profile



Advans is a leading microfinance group established in 2005. Advans mission is to respond to the need for financial services of small businesses and other populations who have ill-adapted, limited or no access to formal financial services. The Advans Group currently spans nine countries: Cambodia, Cameroon, Ghana, the Democratic Republic of Congo, Côte d’Ivoire, Pakistan, Nigeria, Tunisia and Myanmar. As at end of December 2020, the group served more than 1,000,000 clients and employed more than 7,500 staff. The group’s shareholders are EIB, KfW, FMO, CDC Group plc, FISEA (AFD Group) and IFC. In Ghana, Advans operates since 2008 and serves around 70,000 clients through 20 branches and various channels and around 650 employees.





Job Description


Are you looking for a new challenge in a dynamic and multicultural environment? Do you have proven experience in this field? Do you want to contribute to a committed group, seeking to have a positive and sustainable impact? Advans Ghana, a leading MFI, has the position you are looking for.



What will your role be?



Under the supervision of the Deputy Chief Executive Officer, you shall:




  • Advise the Senior Management and Board on Cyber and Information Security Management.   

  • Formulate an institutional methodology for managing cyber and information security risks.

  • Develop the institution’s Cyber and Information Security policy and submit it to the Senior Management and Board for approval.

  • Develop and update specific and general work procedures for realizing the institution’s cyber and information security policy.

  • Maintain an ongoing process  of cyber and information security risk assessment with the relevant institutional units, in order to analyze and assess:

    • the risk levels integral to the institution's technological and business activities;   

    • The controls required to ensure systems integrity.

    • The level of residual risk and exposure to cyber and information security threats the institution is willing to accept in implementing these activities.



  • Integrate and coordinate all institutional cyber and information security efforts, including oversight and control of all institutional units participating in these efforts.

  • Create a framework for receiving ongoing and ad-hoc reports from various institutional units.    

  • Initiate and conduct cyber and information security readiness exercises as follows:

    • at least quarterly, an exercise shall be staged to assess the ability of one or more institutional entities to deal with a cyber-attack; and

    • once a year, an exercise shall be undertaken to assess the preparedness of the entire institution to withstand cyber-attacks.



  • Coordinate cyber and information security activities, including joint exercises with business partners and service providers.

  • Promote cyber and information security awareness and train employees, suppliers, business partners, and customers.

  • Continuously learn and monitor cyber and information security issues by identifying trends, methods, and advanced developments in the field while gathering information about emerging attack techniques and ways of dealing with them.

  • Form a Cyber-Incident Response Team.

  • Analyse cyber and information security incidents that have occurred in Ghana and worldwide, and assess their potential impact on the institution, as well as implement the relevant measures proposed.

  • Develop metrics and indicators to assess the effectiveness of cyber and information security systems and procedures.

  • Assess regular and ad-hoc institutional cyber and information security controls.

  • Draw up annual and multiannual work plans, including budgeting, prioritization, and timetables for implementing the assessment processes.

  • Prepare and submit annual reports to the Senior Management and Board, detailing the institutionally and information security defense level, weaknesses and vulnerabilities, available countermeasures, and the activities and budgets required to enhance its defenses.

  • Be responsible for collaborating with relevant institutions involved in cyber and information security issues.

  • Ensure preparation of reports on major cyber and information security incidents to the Bank of Ghana.




Required Skills or Experience


What kind of profile are we looking for?

You have a bachelor's or a master’s degree in computer science and are interested in the microfinance sector and Advans' missions. You have:



  • A minimum of 4 years experience in a similar position, preferably in the Financial sector

  • Knowledge and experience in IT Security/Governance

  • Professional certificates (CISA, CISM, CISSP, CCSP) are an added advantage.

  • Excellent organisational, prioritisation, and decision-making skills.

  • The ability to work independently and to work as part of a team






Note



Please note, employers receive numerous applications per posting and will only shortlist the most qualified candidates. Also
Jobsinghana.com is not involved in any decision made by an employer/recruiter and therefore does not guarantee that applications sent
will result in a candidate being shortlisted/selected for that position.
How to Apply Click Here


Scroll to Top