وصف الوظيفة
Role Overview
AVP, Security Incident Management at Mashreq, UAE. This role requires UAE National status.
Role Purpose
Lead the incident response team within the Cyber Defense Center to ensure timely and effective handling of security incidents. The role involves coordinating with various stakeholders, managing incident response processes including investigation, analysis, containment, recovery, communication, and reporting, while continuously improving the organization's incident management capabilities and meeting compliance requirements.
Key Responsibilities
Strategic Oversight & Governance
- Provide strategic direction and oversight for the incident management process, ensuring alignment with organizational goals and objectives.
- Develop and refine incident management policies and procedures, ensuring they are up-to-date and effective in addressing current and emerging threats.
- Lead the development and implementation of comprehensive Security Governance strategies that address identified risks and compliance requirements, incorporating advanced technologies and methodologies to enhance security posture.
- Assess and design security posture determination processes, tools and methodologies.
Incident Response & Crisis Management
- Lead the coordination of major security incidents and crisis management, ensuring that all relevant teams and stakeholders are effectively engaged and provide appropriate technical insights to the Crisis Management Team (CMT).
- Manage incident investigation, analysis, containment, recovery, communication and reporting.
- Quickly analyze incidents to understand their root causes by gathering data, identifying patterns, and determining the impact on systems and users.
Continuous Improvement & Learning
- Conduct thorough post-incident reviews to identify lessons learned and implement improvements to prevent future incidents.
- Proactively drive initiatives that enhance incident response and resilient cyber posture.
- Continuously improve the organization's incident management capabilities.
- Commit to learning from experiences and continuously improving relevant processes and outcomes.
- Maintain up-to-date knowledge of security trends, threats, and countermeasures.
Operations & Automation
- Automate potential resilient security processes to ensure continuous compliance with security best practices.
- Continuously monitor security hygiene and performance using tools and processes.
- Review and approve use cases and playbooks for SIEM/SOAR tools.
- Operationalize SIEM/SOAR tools such as Sentinel and ArcSight.
Stakeholder Management & Communication
- Maintain clear and effective communication with stakeholders, providing updates on incident status and resolution efforts.
- Coordinate with various stakeholders throughout the incident response process.
- Collaborate with other IS teams, Operations and technical teams on enhancing security incident response resilience.
Performance & Accountability
- Define and report KPIs for Security Incident Response.
- Take full responsibility for activities and hold self and team accountable for their outcomes.
- Focus on delivering outputs that create meaningful impact such as enhanced security culture and protection posture of the bank.
Training & Mentorship
- Provide training and mentorship to other team members, ensuring the team is well-prepared to handle incidents.
Qualifications & Experience
- 12+ years of rich experience in information security domain.
- At least 6-8 years of dedicated experience in Security Incident Response.
- Hands-on experience in implementing and operationalizing SIEM/SOAR tools such as Sentinel and ArcSight.
- Experience in defining and reporting KPIs for Security Incident Response.
- Familiarity with advanced SOC monitoring technologies, risk, threat and security measures.
- Knowledge across SOC domains including governance, control frameworks, policies, compliance management, risk management and incident response.
- Comprehensive knowledge of regulatory and compliance requirements and how they influence the bank's Information Security strategy.
- Preferably worked in BFSI domain with proven experience in SOC function.
- Strong understanding of key security standards and regulations such as NIST 800-61, CERT/CC, PCI, and ISO 27035.
- Deep understanding of Security Incident Response frameworks and their application in creating robust policies.
- Knowledge of evolving advanced tech stacks and related control and risk universe from a SOC perspective.
- Knowledge and expertise in conducting risk assessment and management.
- Technical or computer science degree preferred.
Skills & Competencies
- Incident analysis and root cause determination.
- Critical thinking and ability to evaluate situations from multiple angles under pressure.
- Strong technical background to understand systems and technologies involved in diagnosing issues.
- Deep understanding of Security Incident Response frameworks.
- Technical knowledge of systems and technologies crucial for coordinating with technical teams.
- Professional certifications: GCIH, CISSP, CEH, FOR608, CISM or equivalent.
Additional Information
- UAE National status required.