2 months ago
02 May 00:00
Malta Financial Services Authority
Unfortunately this job has now expired. However you can view all of our Live jobs here.
Head within Supervisory ICT Risk and Cybersecurity
About Supervisory ICT Risk and Cybersecurity
The Cybersecurity and ICT risk function provides specialist services and support to Authorisation and Supervision teams at the Authority across all financial sectors as part of the overall supervisory framework. It is responsible for the assessment of fit and proper Cybersecurity posture, ICT strategic alignment to Business strategy, ICT governance, and general ICT risk profile, exposures and controls of Licenced Holders and applicants seeking Authorisation based on established regulatory frameworks, technical standards and guidelines. The function therefore provides the necessary technical risk assessments and guidance as part of the Authority's holistic risk-based supervision model.
It also supports the development of policy and supervisory work related to cybersecurity and ICT risk. Furthermore, the function provides technical support and coordination in terms of cybersecurity forensics, supervisory investigations or enforcement actions as required.
The selected candidate shall manage a team of cybersecurity and ICT risk professionals responsible for ongoing supervisory Cybersecurity and ICT assessments, and regulatory compliance in this aspect.
He or she will represent MFSA at various working groups and task forces at local and international level to support the continuous updating of supervisory cybersecurity and ICT risk assessments as well as related policy according to regulatory development and market evolution, working closely with all stakeholders at strategic, supervisory and operational level across the whole organisation. To this extent, he or she will therefore drive the continuous development of cybersecurity/ICT guidance to Licence Holders and external ICT auditors.
The selected candidate shall also act as the primary contact at the Authority on cybersecurity and ICT-related incident management across the regulated financial services sectors.
We are looking for candidates with a solid foundation in Information Technology and Information Security principles, having a related degree at MQF level 7, and must have a professional background of at least eight continuous years in IT Risk Assessment or IT Audit, preferably in the Financial Services Sector. You would also ideally have had some previous working experience in Enterprise level IT operations or software development.
As a seasoned professional, the selected candidate would have certifications such as CISSP, CISM, or CRISC, and expected to have strong knowledge of cybersecurity frameworks and standards such as ISO 27000 series and NIST framework, as well as IT management and governance frameworks such as COBIT 5. You would be expected to be very conversant with applicable laws and regulations.
As a people manager the selected candidate would have had at least three years’ experience in managing a team of professionals in ICT risk and cybersecurity. We are looking for candidates with strong leadership skills, professional integrity and accountability. The selected candidate will also be an excellent communicator capable of collaborating effectively within and outside the organisation at all management levels.