Information Security Senior Professional in Giz
1 dia atrás
**Descrição:**:About the project
To enable the worldwide protection of all critical information processed by the GIZ, the establishment of an Information Security Management System (ISMS) and therefore Information Security Senior Professionals in the field structure are indispensable. Through the company-wide international standard ISO/IEC 27001 certification of information security management (ISO27001), the GIZ targets a wide variety of permanent restructuringprocesses, all of them requiring experts to coordinate and maintain these changes. While the company-wide coordination lies with the Chief Information Security Officer (CISO) and his/her Information Security Management Team (ISMT) located at the headquarters, the extensive local establishment and continuous operation of information security needs the support of a new local role, which works closely together with already existing local roles such as IT-Professionals and Digital Partners (DIPAs).
Area of responsibility
The goal of Information Security Senior Professional is to be a central single point of contact (SPoC) for organizational overview and control as well as professional knowledge concerning information security in the country office. As information technology (IT) has a big role in information security, IT-specific knowledge and/or close cooperation with technical roles is also an expected area of expertise. For the implementation of information security and the ISO27001-certification, the professional is expected to work within the existing management organization of local offices while initiating and controlling relevant processes.
Contents and Tasks
- Initial tasks
In the initial phase of implementation, the establishment of a local information security management is focused. To successfully do this, the Information Security Senior Professional establishes and later manages the security incident process, supports/accompanies the Audit Management process (including the local coordination of “penetration testing”) and ensures that a functioning vulnerability management is in place. As the local representation of the information security organization and thus the Information Security Management System (ISMS), the Information Security Officer acts as Single Point of Contact (SPoC) for information security. He also is the SPoC for projects of the portfolio and contact for all topics concerning information security. The professional ensures through a structural analysis (asset recording) an up-to-date and complete asset inventory (in cooperation with asset owners). Towards Headquarters, specifically towards the CISO, he/she provides structured reporting to the CISO. He/she is also responsible for recording the current status of information security, which includes the mentioned assets. The Information Security Officer establishes the local InfoSec Risk Management (IRM) and accompanying risk register which is implemented through identification of risks with asset owners, risk assessment with risk owner involvement, risk treatment management and further connected tasks.
- Continuous Operation and Updates
After the initial establishment, the Information Security Senior Professional is responsible for elaborating, reviewing, and updating the local security concept, the coordination and implementation of measures, guidelines/concepts as well as the adaptation of guidelines/concepts to local conditions. Concerning the information security awareness among employees, the Information Security Officer coordinates existing awareness measures and is to a limited extend personally responsible for the awareness/training efforts. He/She is further responsible for the control of the effectiveness of security measures, for revisions and audits and for ensuring the investigation of security-related incidents & coordination of their reporting (reporting system). As representative of the Information Security Management System Team (ISMS Team) the Information Security Officer (ISO) also has the permanent task of reporting to the CISO and supply necessary information for the management report of the CISO. For the local offices, the professional provides continuous consulting on information security topics and the constant operation of risk management and level estimation of information protection requirements.
Requisitos desejados: The Information Security Senior Professional is responsible for all information security issues in the country office. To carry out this work the following competencies and capabilities are expected or should be acquired within a reasonable period of time:
- 5 years work experience in an international organization, familiar with organizational structures and processes. Desirable experience in organizations with a minimum of 1000 employees;
- Experienced in conducting audits;
- Knowledge and experience in information security;
- Knowledge and experience in ISO/IEC 27001;
- Basic knowledge of actual Microsoft Software and Se
-
Analista de Recursos Humanos Sênior para o Setor
1 semana atrás
Brasilia, Brasil GIZ Brazil Tempo inteiro**Descrição**: Sobre a GIZ A Deutsche Gesellschaft für Internationale Zusammenarbeit (GIZ) GmbH é uma empresa do governo alemão atuante no âmbito da cooperação internacional para o desenvolvimento sustentável. A GIZ tem mais de 50 anos de experiência em uma ampla variedade de áreas, como o desenvolvimento e emprego, a energia, meio ambiente,...
-
Professional Services Consultant
Há 3 dias
Brasilia, Brasil Fortinet Tempo inteiroProfessional Services Architect As customers security infrastructure become more complex, Fortinet Professional Services experts are positioned to help them every step of the way. We’ve accumulated many years of experience to help our customers with their security design, deployment, operation, and optimization needs. The Professional Services Architect...
-
Security Operations Analyst
Há 3 dias
Brasilia, Brasil Kyndryl Tempo inteiroWho We Are Kyndryl is a market leader that thinks and acts like a start-up. We design, build, manage, and modernize the mission-critical technology systems that the world depends on every day. So why work at Kyndryl? We are always moving forward - always pushing ourselves to go further in our efforts to build a more equitable, inclusive world for our...
-
Senior Recruiter
2 semanas atrás
Brasilia, Brasil Cielo Talent Tempo inteiroCompany Description Are you ready to accelerate your career? Join Cielo as a Senior Recruiter! A career at Cielo will give you the opportunity to work with the industry’s smartest people and to take ownership of your success! Cielo is a brand that reflects our big idea - that talent is rising - and with it our opportunity to rise above. We create careers...
-
Salesforce Developer
2 semanas atrás
Brasilia, Brasil Doit Security, Inc. Tempo inteiro**Company Description** Cloud adoption and digital transformation are becoming the standard in every business and market area. Doit Security is starting a long-term effort to assist cloud security firms with the new SASE category. **THIS POSITION IS 100% REMOTE** **Position Description** We are searching for a proactive person that can assist us in...
-
Engagement Manager, AWS Professional Services
1 semana atrás
Brasilia, Brasil Amazon AWS Services Brazil Ltd Tempo inteiroThe Amazon Web Services Professional Services (ProServe) team is seeking a highly skilled and versatile Engagement Manager (EM) to join our team and lead the delivery of complex cloud solution projects. In this role you will combine technical expertise with strong project leadership skills to drive successful implementations of AWS-based solutions for our...
-
Técnico de Suporte N2
Há 3 dias
Brasilia, Brasil Hepta Tempo inteiro**Brasília/DF**: - 08:00-20:00 ESCOLARIDADE **Superior - Cursando** - Na área de TI CONHECIMENTOS - Navegadores de internet - Sistema Operacional: Windows - Instalação, configuração e resolução de problemas de sistemas de automação de escritório MS Office - Active Directory - Instalação, montagem e configuração de Hardwares - Instalação,...
-
Senior Consultant
1 dia atrás
Brasilia, Brasil Actualize Consulting Tempo inteiroSenior Consultant - Treasury, Financial Transactions & Accounting Fully remote position offering a flexible work schedule. Location: LATAM (Brazil)You’ll work with top-tier clients across industries - multinationals, banks, and government entities. You're not just executing tasks, you’re leading workstreams, shaping recommendations, and driving change in...
-
Jr Information Security Analyst
2 semanas atrás
Brasilia, Brasil Topaz Brasil Tempo inteiroSer **Topaz** significa assumir o compromisso de contribuir dia a dia em cocriar soluções capazes de fazer da indústria financeira um lugar mais seguro, dinâmico e acessível para todos, em todas as partes. Nosso amplo ecossistema de soluções tecnológicas nos posiciona como a plataforma financeira mais completa do mercado: com soluções que vão do...
-
Information Security Analyst
Há 7 dias
Brasilia, Brasil Topaz Brasil Tempo inteiro**_Na Topaz, a tecnologia nos une e a evolução nos conecta! - ** Em nossa organização, estamos totalmente comprometidos em contribuir para soluções financeiras que tornem a indústria um lugar seguro, acessível e dinâmico. Queremos alcançar diferentes partes do mundo com nosso amplo ecossistema de soluções tecnológicas. Por isso, convidamos...