CISO and Manager Security, Risk, Compliance - GL E
Reporting to the CIO, the role is primarily to provide the vision and leadership for developing and supporting cyber security strategy, initiatives, and roadmap. The Chief Information Security Officer (CISO) directs the planning and implementation of enterprise IT systems, business operations, and facility defences against security breaches and vulnerability issues. This individual is also responsible for auditing existing systems, while directing the administration of security policies, activities, and standards. Oversees cybersecurity risk management within the Global Fund, and is responsible for governance, auditing, risk management and compliance of the IT systems.
This role will play a pivotal role in safeguarding our information systems and ensuring the integrity and confidentiality of sensitive data. This role will be responsible for developing and implementing robust cybersecurity strategies, policies, and procedures to protect our organization from evolving cyber threats, in alignment against best practice standards ISO 27001, 22301 and GDPR.
This role will advise senior management and governance bodies on cyber security to protect the Global Fund and the ecosystem (e.g., PR’s) from emerging cyber threats (phishing, data loss, reputational risk linked to any misuse of system / data) and plan defences against security breaches and drive a continuous improvement mindset.
Key Responsibilities
As Manager, Security, Risk, Compliance & CISO this person will:
Information Security & Risk
- Lead the definition, implementation, and management of Global Fund Information Security Strategy and roadmap.
- Ensure effective governance of Information Security, liaising with all relevant stakeholders.
- Develop and implement comprehensive cybersecurity risk management strategies, policies, and procedures in line with industry best practices (e.g., ISO 27001/2, NIST) and organizational objectives.
- Collaborate with Legal Department to define and implement strong security, privacy and data protection framework through grants and across the organisation.
- Lead, implement, maintain, and oversee enforcement of business continuity policies, procedures and plans for end-to-end resilience, following industry-standard best practices, e.g., ISO 22301.
- Identify, assess, and prioritize cybersecurity risks and vulnerabilities across our information systems and networks, ensuring proactive mitigation measures are in place.
- Collaborate with cross-functional teams to establish effective incident response plans and ensure prompt and appropriate action is taken in the event of a cyber incident or breach.
- Contribute to IT projects identifying their risk profile and security requirements and assist the implementation of adequate security controls as an integral part of the final product.
- Monitor and evaluate the performance of cybersecurity technologies, tools, and solutions, making recommendations for enhancements or replacements as necessary.
- Lead and manage a team of cybersecurity professionals, providing guidance, mentoring, and performance feedback to enhance their skills and capabilities.
- Conduct regular audits and assessments to evaluate the effectiveness of cybersecurity controls, ensuring compliance with relevant legal, regulatory, and contractual obligations.
- Stay abreast of the latest cyber threats, trends, and emerging technologies to continuously enhance our cybersecurity posture and proactively address potential risks.
- Foster a culture of cybersecurity awareness and education within the organization by developing and delivering training programs across the organisation and country ecosystem (e.g., PR’s).
- Build increased collaboration on cyber threat intelligence for prevention and protection of Global Fund and PR’s/countries.
- Collaborate with external stakeholders, including government agencies, industry partners, and cybersecurity organizations, to exchange information, share best practices, and enhance collective defence against cyber threats.
- Provide regular reports and updates to the CIO and senior management on cybersecurity risks, incidents, and the overall effectiveness of the cybersecurity program.
- Responsible for the IT risk reporting in collaboration with the Chief Risk Officer (CRO) team for an integrated enterprise risk reporting via Global Fund operational risk register (ORR) to Senior Management (MEC), the Audit and Finance Committee (AFC) and Board.
- Manage all matters relating to e-discovery investigations in collaboration with HR, Legal, Communications, Risk, Ethics and Office of Inspector General (OIG) Departments.
- Promote and oversee strategic cyber security relationships between internal resources and external entities, including government, vendors, and partner organizations.
Compliance