وصف الوظيفة
Role Overview
Manager IT Security International (Qatarization) at QNB in Doha, Qatar. The role supports the Senior Vice President of IT Security International in providing oversight, guidance and governance to QNB Group Subsidiaries on all matters relating to QNB Group IT Security.
Company Overview
QNB Group was established in 1964 as Qatar's first Qatari-owned commercial bank and is now the largest bank in the Middle East and Africa region. The Group operates through more than 31 countries across three continents, with more than 28,000 employees serving up to 20 million customers through 1,000 locations and 4,300 ATMs. QNB maintains ratings of A from Standard & Poor's, Aa3 from Moody's, and A+ from Fitch, and is ranked as the most valuable bank brand in the Middle East and Africa according to Brand Finance Magazine.
Role Purpose
Assist the Senior Vice President of IT Security International in providing oversight, guidance and challenge on the deployment of a consistent methodology, approach and execution of Group Information Security policies, standards and practices across QNB International Units. Work closely with IT Security teams and stakeholders in Subsidiaries and International Branches to undertake risk assessments and promote efficient communication and synergies between international IT Security functions and QNB business areas, support areas, and control functions.
Key Responsibilities
Governance & Framework
- Support implementation of the QNB Group Information Security Framework including policies, procedures and standards to improve the Group's management of Information Security.
- Provide inputs to the Manager of IT Security International to prepare the Information Security Strategy.
- Assist the Senior Vice President of IT Security International in preparing the Information Security Strategy that reflects the Group's tolerance for risk and present it to the GCRO for discussion and review.
- Act within the limits of the powers delegated to the incumbent.
Oversight & Performance Management
- Create a methodology and list of KPI/KRIs to monitor the effectiveness of controls and assess the security posture of entities.
- Increase the effectiveness of management's oversight through KPI and KRI development.
- Implement KPIs and best practices for IT Security International.
- Promote a strong control culture and general awareness of risk management across the business.
- Carry out appropriate ongoing evaluation of all systems, processes and infrastructure to ensure policies, processes and standards are in place to identify, assess, measure, manage and report Information Security, including identification of Subsidiaries' systemic Information Security.
Stakeholder Management
- Build and maintain strong and effective relationships with all Support departments and units to achieve Group goals and objectives.
- Build and maintain strong and effective relationships with all relevant stakeholders in Subsidiaries and International Branches to achieve Group goals and objectives.
- Build and maintain strong and effective relationships with related departments and units to achieve Group objectives.
- Ensure proactive participation and support of QNB International Units in the preparation and updating of policies, procedures and guidelines.
- Ensure the information security framework is well embedded across the business and functions to ensure transparency of risks, issues and events.
Reporting & Communication
- Produce adequate and accurate reports pertaining to Information Security.
- Consolidate portfolio management data and other Information Security data received from other Information Security sub-functions.
- Regularly contribute presentations to governance committees ensuring the Information Security profile is clearly reported and understood.
- Provide timely and accurate information to external and internal auditors and the Compliance function as and when required.
- Provide timely and accurate data to external and internal Auditors, Compliance, Financial Control and Risk when required.
- Escalate relevant Information Security reporting and issues as requested by the VPs and Managers of IT Security International to include and comply with all internal and/or external requirements.
Customer & Service Delivery
- Assist customers in all their queries on the Bank's products and seek solutions to their requests.
- Maintain activities in accordance with Service Level Agreements (SLAs) with internal departments and units to achieve improvements in turn-around time.
Projects & Special Assignments
- Assist in the delivery of other projects as mandated by the VPs and Managers of IT Security International.
Risk & Compliance
- Comply with all applicable legal, regulatory and internal compliance requirements including but not limited to Group Compliance Policies and Procedures: AML & CTF, Sanctions Policy, Data Protection Policy, Fraud Control Policy, Whistle Blowing Policy, Conflict of Interest and Insider Dealing Policy.
- Understand and effectively perform your role under the Three Lines of Defence principle to identify, measure, monitor, manage and report risks.
- Ensure systematic good outcomes for clients in accordance with Conduct Risk policy.
- Support the framework of RCSA, KRI, Incident reporting and remediation, as appropriate, in accordance with Operational Risk Management requirements.
- Ensure high standards of data protection and confidentiality to safeguard commercially sensitive information.
- Maintain utmost confidentiality concerning customer and internal bank information obtained during the course of business and provide such information on a need to know basis only to Senior Management of QNB, Audit and Compliance.
Professional Development & Knowledge
- Stay updated with relevant best practice pronouncements pertaining to Information Security and work towards instilling the same within the Group's Information Security practices.
- Possess an understanding of business processes and controls in all related operational areas.
- Possess superior knowledge on quantitative techniques to assessing, measuring and managing Information Security.
- Maintain an understanding of all pertinent regulations as well as best practices pertaining to Information Security.
- Keep abreast of the latest technical developments in modeling Information Security.
- Proactively identify areas for professional development of self and undertake development activities.
- Seek out opportunities to remain current with all developments in the professional field.
- Maintain appropriate knowledge to ensure full qualification to undertake the role.
- Complete all mandatory training provided by the Bank, attain and maintain the required levels of competence.
- Attend mandatory internal and external seminars as instructed by the Bank.
Additional Information
- Business Unit: QNB - Qatar
- Division: Risk Management
- Location: Doha, Qatar
- Position Classification: Qatarization role
- Full details are available on the employer's original posting.