Manager âÃÂàIT Security at HF Group
HF Group
About the Role
The Manager - IT Security supports the Head of ICT Security / CISO in strengthening the Group's information security posture by coordinating IT security governance, cyber risk management, SOC operations oversight, security assurance, audit remediation, regulatory compliance and proactive cyber resilience across the Group. The role ensures that security policies, standards, controls, monitoring processes and assurance activities are embedded into technology operations, digital channels, projects, third-party engagements, and business processes. The role holder provides security support to the substantive Data Protection Officer by ensuring that technical and organisational security controls for personal data are defined, implemented, tested, monitored, and evidenced. This role supports privacy governance through technology control implementation, security assurance, access control, monitoring, incident coordination, third-party reviews, and remediation tracking.
Key Accountabilities
Data Protection and Privacy Security Support - Support the substantive Data Protection Officer by providing information security input into privacy governance, DPIAs, data classification, access controls, encryption, logging and monitoring, data loss prevention, third-party risk reviews, breach investigation, audit evidence and remediation tracking.
IT Security Governance and Strategy Execution - Support the CISO in implementing the Group information security strategy, governance framework, policies, standards, procedures, operating model and control assurance programme.
Regulatory Compliance and Security Reporting - Coordinate compliance reviews, evidence packs, management attestations, regulatory responses, control self-assessments and reporting to ICT, Risk, Compliance, Audit and management governance forums.
Cyber Risk, Audit and Remediation Management - Coordinate identification, assessment, monitoring, reporting and remediation of ICT and cyber risks across the Group, including audit and regulatory findings to closure.
SOC Operations Oversight and Incident Coordination - Provide management oversight of security monitoring, incident triage, escalation, response coordination, threat intelligence, SOC use cases, alert handling, incident reporting and post-incident remediation.
ICT Resilience, Disaster Recovery and Cyber Recovery Support - Coordinate security input into ICT business continuity, disaster recovery, cyber recovery planning, backup assurance, recovery testing and remediation of resilience gaps.
Identity and Access Governance - Maintain access governance covering privileged access, periodic user access reviews, role-based access control, joiner-mover-leaver controls, access certification, segregation of duties, exceptions, remediation tracking and evidence management.
Security Assurance for Projects, Platforms and Third Parties - Provide security assurance over systems, infrastructure, digital channels, cloud services, APIs, integrations, third parties and technology changes.
Qualifications
Bachelor's degree in information security, Computer Science, Information Systems, Information Technology, Cybersecurity, Risk Management, or related fields.
Relevant certifications such as CISM, CISSP, CRISC, CISA, ISO 27001 Lead Implementer/Lead Auditor, CompTIA Security+, CBCP or equivalent will be an added advantage.
At least 5 years' experience in information security, IT governance, cyber risk, security operations, security assurance, or technology risk management.
Understanding of implementation of technical security controls, identity and access management and designing security solutions in a dynamic environment
At least 2 years in a supervisory or managerial role within a highly regulated or digitized environment.
Demonstrable experience in security governance, SOC oversight, audit remediation, regulatory compliance, access governance, third-party assurance, project security assurance, incident coordination, cyber resilience and executive reporting.
Understanding of IT Audit processes, technical security testing (Red Team, Blue Team, Penetration Testing) and Cyber Incident Response including data protection guidelines.