The Head of Cyber Security leads the cyber defence operation covering Cyber Strategy & Resilience, Security Design & Engineering, Cyber Defense & Operations and Security Services & Remediation operations.
Overall accountable leader for cyber security within the First Line of Defence (1LOD), reporting to GM-Technology (CIO). Designated as the "Accountable Lead" for Cyber Security, responsible for the end-to-end delivery of the Bank's cyber security strategy, operations, and resilience capabilities .
Accountable for the effective design, implementation, and operation of all 1LOD cyber security controls across the enterprise, ensuring controls meet the objectives set by the Second Line of Defence (2LOD).
Provides strategic direction and leadership across all cyber security functions: Strategy & Resilience, Security Design & Engineering, Cyber Defense & Operations, Security Services & Remediation, and 1.5LOD Governance, Risk & Compliance.
Accountable for ensuring the Bank's cyber security posture meets regulatory requirements (CBO), international standards, and operates within the Board-approved cyber risk appetite.
Represents the 1LOD cyber security function at executive management and Board forums, meetings as required, providing assurance on the effectiveness of the 1LOD control environment.
Partners with the 2LOD Head of Technology and Cyber Risk (CISD) to ensure constructive alignment between independent risk oversight and operational delivery, maintaining the integrity of the Three Lines of Defence model.
Accountable for the allocation of cyber security resources, budget, and investment priorities to maximise risk reduction and strategic value.
Champions a culture of security awareness across the enterprise and ensures cyber security is embedded in business and technology decision-making.
Accountable for the Bank's cyber incident response at the executive level, acting as the senior decision-maker during major cyber incidents and crisis events.
Drives the maturation of the Bank's overall cyber security capability, establishing measurable objectives and ensuring continuous improvement across all functions.
Desired Candidate Profile
- 15+ years in cyber security, information security, or technology risk management, with a significant portion within banking or financial services
- Minimum 10 years in senior leadership roles with executive committee and board-level reporting and engagement experience
- Proven track record of building, leading, and maturing large, multi-disciplinary cyber security functions (50+ FTEs) in a regulated environment
- Experience developing and executing enterprise cyber security strategies aligned to business objectives and regulatory requirements
- Competent in leading teams operating across the full spectrum of cyber security domains: security architecture, engineering, defense operations (SOC/IR), GRC, and resilience
- Experience managing regulatory relationships and ensuring compliance with financial sector cyber regulations (e.g., CBO requirements)
- Track record of managing significant security investment portfolios (OpEx/CapEx) and demonstrating measurable risk reduction
- Executive-level crisis management and incident command experience
- Experience operating within a formal Three Lines of Defence model and partnering effectively with 2LOD and 3LOD (Internal Audit) functions
- Bachelor's degree in Computer Science, Information Systems, Cyber Security, or related field (Master's degree or MBA preferred)
- CISSP certification required
- CISM certification highly advantageous
- CISA or CRISC advantageous
- Strategic leadership or executive management qualification beneficial (e.g., Cranfield, INSEAD, or equivalent)
- Professional membership of relevant bodies (e.g., (ISC)², ISACA)
- Knowledge of CBO regulations, Basel standards, and international cyber security frameworks (NIST CSF, ISO 27001)
يقود رئيس الأمن السيبراني عملية الدفاع السيبراني التي تغطي الاستراتيجية والمرونة السيبرانية، وتصميم الهندسة الأمنية، والدفاع والعمليات السيبرانية وخدمات الأمن والتعافي من الحوادث.
القائد المسؤول كلياً عن الأمن السيبراني ضمن خط الدفاع الأول (1LOD)، وتقريراً إلى مدير عام التقنية (CIO). تم تعيينه كـ "القائد المسؤول" للأمن السيبراني، مسؤول عن التسليم الشامل لاستراتيجية الأمن السيبراني للبنك وعملياته وقدرات المرونة.
مسؤول عن التصميم الفعال والتنفيذ والتشغيل لجميع ضوابط الأمن السيبراني في 1LOD عبر المؤسسة، مع التأكد من أن الضوابط تفي بالأهداف التي حددها خط الدفاع الثاني (2LOD).
يوفر التوجيه الاستراتيجي والقيادة عبر جميع وظائف الأمن السيبراني: الاستراتيجية والمرونة، تصميم وهندسة الأمن، الدفاع والعمليات السيبرانية، خدمات الأمن والتعافي، وحوكمة ومخاطر والتوافق 1.5LOD.
مسؤول عن ضمان أن وضع الأمن السيبراني للبنك يفي بالمتطلبات التنظيمية (CBO)، والمعايير الدولية، ويعمل ضمن الشهية للمخاطر السيبرانية المعتمدة من المجلس.
يمثل وظيفة الأمن السيبراني في 1LOD أمام لجان الإدارة التنفيذية والمجلس، ويحضر الاجتماعات كما يلزم، موفراً الضمانات حول فعالية بيئة الضوابط في 1LOD.
يتعاون مع رئيس التكنولوجيا ومخاطر السيبر (CISD) في 2LOD لضمان توافق بنّاء بين الإشراف المستقل على المخاطر والتنفيذ التشغيلي، مع الحفاظ على سلامة نموذج الثلاثة خطوط للدفاع.
مسؤول عن تخصيص موارد الأمن السيبراني والميزانية وأولويات الاستثمار لتعظيم الحد من المخاطر والقيمة الاستراتيجية.
يُروّج لثقافة الوعي الأمني عبر المؤسسة ويتأكد من دمج الأمن السيبراني في اتخاذ قرارات الأعمال والتقنية.
مسؤول عن استجابة البنك للحوادث السيبرانية على مستوى التنفيذيين، acts كأعلى صانع قرار خلال الحوادث والكوارث السيبرانية الكبرى.
يدفع نضج قدرة الأمن السيبراني للبنك بشكل عام، مع وضع أهداف قابلة للقياس وضمان التحسين المستمر عبر جميع الوظائف.
الملف الوظيفي المرغوب فيه
- أكثر من 15 عامًا في الأمن السيبراني، أمن المعلومات، أو إدارة مخاطر التقنية، مع جزء كبير في الخدمات المصرفية أو الخدمات المالية
- حد أدنى 10 سنوات في أدوار قيادية عليا مع تقارير وارتباط بمستوى اللجنة التنفيذية والمجلس
- سجل حافل ببناء وقيادة وتطوير وظائف الأمن السيبراني الكبيرة والمتعددة التخصصات (أكثر من 50 وظيفة) في بيئة منظمة
- خبرة في تطوير وتنفيذ استراتيجيات الأمن السيبراني المؤسسية متوافقة مع أهداف الأعمال والمتطلبات التنظيمية
- كفاءة في قيادة فرق تعمل عبر طيف كامل من مجالات الأمن السيبراني: هندسة الأمن، الهندسة، الدفاع والعمليات (SOC/IR)، GRC، والمرونة
- خبرة إدارة العلاقات التنظيمية وضمان الامتثال للوائح قطاع المالية السيبرانية (مثلاً متطلبات CBO)
- سجل إدارة محافظ استثمارية أمنية كبيرة (OpEx/CapEx) وإثبات تقليل مخاطر قابل للقياس
- خبرة إدارة الأزمات على مستوى التنفيذيين وخبرة القيادة أثناء قيادة الحوادث
- العمل ضمن نموذج ثلاث خطوط للدفاع وتعاون فعال مع 2LOD و3LOD (الـإلتدقيق الداخلي)
- درجة البكالوريوس في علوم الحاسوب، أنظمة المعلومات، الأمن السيبراني، أو مجال ذي صلة (درجة الماجستير أو MBA مفضلة)
- شهادة CISSP مطلوبة
- شهادة CISM ميزة كبيرة
- شهادة CISA أو CRISC ميزة
- مؤهل قيادة استراتيجية أو إدارة تنفيذية مفيد (مثلاً كرانفيلد، INSEAD، أو ما يعادلها)
- عضوية مهنية في هيئات ذات صلة (مثلاً (ISC)²، ISACA)
- معرفة بأنظمة CBO، معايير Basel، وأطر الأمن السيبراني الدولية (NIST CSF, ISO 27001)