Position : Senior Lead Specialist- Technology Risk and Business Resilience
Job Description:
- Plan, develop, implement and enhance Business Continuity Management (BCM) capabilities to ensure robust preparedness, safeguard critical business operations and meet regulatory requirements. Key activities include Business Impact Analysis, risk assessments, BCP testing, simulation exercises, call tree tests, crisis management exercises and post-exercise improvement tracking.
- Develop and maintain BCM and technology risk-related frameworks, policies, manuals, procedures, SOPs, templates and supporting documentation.
- Work closely with Technology to ensure disaster recovery strategies, recovery time objectives, recovery point objectives and technology recovery arrangements are aligned with recovery plan.
- Review the adequacy of outsourced service providers resiliency arrangements including BC Plan and BCM Exercises.
- Support incident response, crisis management and business continuity activation activities, including escalation, reporting, documentation and lessons learnt follow-up.
- Support assessments of the organization's technology landscape to identify potential risks, including cybersecurity threats, data breaches, system failures and compliance issues.
- Support BAU risk management activities, including RCSA, risk assessments, control testing, incident reporting and regulatory submissions where required.
- Prepare and support reporting on BCM, business resilience, technology risk and related matters to relevant management and risk committees.
- Promote a strong culture of risk awareness and appreciation to ensure that the Company adopts best practices in business resilience, cybersecurity and technology risk management.
Requirements:
- Bachelor's Degree in fields of Accounting/Economics/Business/Law/Risk Management/Information Technology domain knowledge
- Minimum 8 years of experience in managing and handling end-to-end business continuity activities, IT Risk Management and Information Security Risk.
- Experience in performing assessments aligned information technology-related standards such as RMIT, NIST, COBIT, ISO2700 and PCI-DSS.
- Professional certification in BCM or certified BCP practitioner is an added advantage
- Industry certification in IT security and governance (e.g., CISSP, CRISC, CISA, CISM) is preferred.
- Professional qualification in Insurance such as CMII, AMII or CII will be an added advantage