إرفاق
وصف الوظيفة
To manage daily operations of Cyber Security Governance, Risk & Compliance unit.
1 - Governance Documentation & Implementation:
· Develop and maintain a cybersecurity governance program
· Develop and document quality governance processes for Cyber initiatives, BAU, policies/standards, contracts, etc.
· Ensure the processes are aligned to clear objectives and have oversight/review frequencies.
· Review/document RASCI for processes
· Ensure that there is a continuous improvement cycle for process.
· Establish value for the Governance structure/process
2 - Risk Management & Enhancement:
· Design and implement a Cyber Security risk management process.
· Analysing current risks and identifying potential risks that are affecting BUPA Arabia
· Evaluating the BUPA Arabia’s previous handling of risks and comparing potential risks with criteria set out by the company such as costs and legal requirements.
· Risk reporting tailored to the relevant audience. (Educating the board of directors about the most significant risks to the business; ensuring business heads understand the risks that might affect their departments; ensuring individuals understand their own accountability for individual risks)
· Explaining the external risk posed by BUPA Arabia to stakeholder.
· Design and implement third-party risk operating model to identify, evaluate and provide solutions to complex business and technology risks.
· Identify and address key third party related risks and areas of concerns associated with new and existing third-party relationships
· Monitor Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for appropriate escalation to stakeholders
· Develop a TPRM dashboard to highlight key TPRM program metrics and statistics (e.g., third-party portfolio risk, cyber security incidents, program efficiencies/value add)
3 - Compliance Monitoring & Management:
· Maintain the list of all legal / regulatory compliance requirements.
· Ensure periodic assessment of the efficiency of Cyber Security control systems and recommend effective improvements.
· Ensure the review and evaluation of Cyber Security procedures to identify hidden risks or common issues.
· Coordinate with different department to review their respective compliance with Cyber Security Polices.
· Ensure implementation of program to perform periodic review on company procedures and processes.
4 - Data Protection Management:
· Data Privacy Officer (DPO) ensuring that the Bupa Arabia processes the personal data of its staff, beneficiaries, providers or any other individuals in compliance with the applicable KSA data privacy regulations.
· Identify personal data schemes and the applicable privacy laws and regulations.
· Identifies and analyzes privacy risks that are applicable to the privacy ecosystem.
· Develops a data privacy mitigation plan to mitigate identified privacy risks.
· Monitors the proper implementation of the mitigation plan with other business units.
· Monitors compliance with the KSA PDPL and other data protection laws.
· Advise the Data Controller or Data Processor and its employees about their obligations to comply with the KSA PDPL and other data protection laws.
المهارات
· 10 - 12 years
· Communication skills
· Risk based approach
· Fast learning and application
· Adherence to confidentiality of data
· Multitasking
· Understand Risk assessment and management methodology.
· Experience in developing and implementing enterprise governance, risk, and compliance strategy and solutions.
· Experience in data management and protection solutions
· Experience in information security experience
· Experience in an enterprise governance, risk and compliance
· Knowledge of Cyber and cloud security standard frameworks, architecture, design, operations, controls, technology, solutions, and service orchestration.
· BE-IT / B Tech /Comps
· Additionally, one more certification in information security domain.
· CISM
· CRISC
· CISA
· CIPP / GDPR / CDPSE
المؤهلات العلمية
Information Technology, Cybersecurity
تفاصيل الوظيفة
المرشح المفضل
Bupa Arabia
Bupa Arabia is a healthcare insurance company based in the Kingdom of Saudi Arabia. We are an associate business of Bupa Group, which is a global healthcare company with an international reach that extends across multiple business operations, practices, and resources.
Founded in October 1997, Bupa Arabia was initially established through a partnership between Bupa Global International and Nazer Group, with the key focus to provide health insurance services with high quality and competitive prices, while ensuring a distinctive experience for customers. Bupa Arabia has since evolved into a fully Saudi-owned and operated company. Our transformation from a joint venture into a publicly traded company on the Saudi Stock Exchange occurred in 2008, as we made 40% of our shares available to the public during our Initial Public Offering (IPO).
As a subsidiary of the global Bupa Group, we draw upon international expertise while maintaining a profound understanding of local healthcare requirements and regulations. This allows us to offer comprehensive healthcare insurance solutions tailored to the unique needs of the Saudi Arabian market.
Bupa Arabia prides itself on its commitment to the wellbeing and development of its employees, providing them with the same standard of care, support, and professionalism that it expects to be delivered to its customers.
Our core values shape every aspect of our work and culture:
Commit – Own it with accountability and urgency.
Collaborate – Win together through cross-functional synergy.
Care – Put people first, both employees and customers.