IT & Information Security Risk Manager
- Location
- Not specified
- Employment
- Full-time
- Category
- Security
- Posted
Description
Develop and maintain IT Risk Management frameworks, policies, and procedures across SOCAR and SOCAR Group entities
Integrate IT, Information Security, Operational Technology (OT), and digital risks into SOCAR’s Enterprise Risk Management (ERM) framework
Support risk assessments for IT infrastructure, applications, cloud services, operational technology, third-party providers and emerging technologies
Monitor IT and information security risk registers, mitigation actions and remediation activities
Support Risk and Control Self-Assessment (RCSA) processes
Monitor compliance with internal policies and industry standards, including COBIT, NIST, ISO 27001, ISO 31000 and ITIL
Assess IT General Controls, monitor IT incidents and support root cause analysis
Prepare risk reports, dashboards, KRIs and analytical summaries for senior management
Apply at the source
This role was published by SOCAR and listed via Careera. Applications are handled there, not on this site.
Original posting: https://careera.az/job/it-information-security-risk-manager