4 Threat Intelligence jobs in Bahrain
Information Security Specialist
Posted 15 days ago
Job Viewed
Job Description
The Information Security Specialist supports the Head of Information Security and Business Continuity in safeguarding the bank’s critical information assets and ensuring the resilience of its operations. This role is responsible for implementing and maintaining comprehensive information security measures, business continuity plans, and disaster recovery strategies that protect the bank’s systems, data, and services from cybersecurity threats and operational disruptions.
The Specialist will contribute to the bank's proactive risk management approach by identifying vulnerabilities, responding to incidents, ensuring regulatory compliance, and leading initiatives to enhance business continuity. In addition, this role involves coordinating BCP and DR activities, conducting regular testing, and ensuring the organization’s preparedness for crises or emergencies.
Reporting directly to the Head of Information Security and Business Continuity, the Specialist will collaborate closely with IT and other departments and business units to integrate security and business continuity frameworks into the bank’s operational processes, supporting a secure and resilient environment that enables the bank to achieve its strategic objectives.
Responsibilities of the role:
Information Security:
- Develop, implement, and maintain information security policies, procedures, and standards in alignment with PCI-DSS and regulatory requirements.
- Monitor, analyze, and respond to security incidents, vulnerabilities, and threats across the bank’s IT systems and networks
- Conduct periodic risk assessments and gap analyses to identify security weaknesses and develop mitigation strategies
- Coordinate internal and external audits related to information security; ensure timely closure of audit findings
- Provide security awareness training to staff and promote a culture of information security
- Support secure configuration and change management processes across IT assets and infrastructure
- Work with IT and other departments to ensure security is embedded into system design and operational processes
- Stay up to date with current cyber threats and trends, and recommend appropriate risk mitigation measures
Business Continuity:
- Develop and maintain the bank’s business continuity management frameworks in line with the bank’s and regulatory guidelines
- Conduct business impact analyses (BIAs) and risk assessments across business units to identify critical functions and recovery priorities
- Lead the development, testing, and continuous improvement of BCP and DR plans to ensure organizational resilience.
- Coordinate with IT, facilities, and business teams to ensure recovery strategies are effective and practical.
- Conduct regular BCP/DR drills and exercises, and report findings with actionable recommendations.
- Liaise with regulatory bodies, auditors, and stakeholders to ensure compliance and readiness.
- Maintain documentation and evidence of BCM program activities and test results.
Areas of Knowledge, Qualification and Experience
- Atleast 5 years of experience working within a Banking Environment
- Bachelors Degree in Computer Science / Cyber Security background.
- Relevant certifications from ISC2, ISACA, SANS are highly preferred
- In-depth understanding of global information security standards (e.g., ISO 27001, NIST Cybersecurity Framework, CIS Controls) and regulatory requirements (e.g., CBB, PCI-DSS). Ability to implement and manage these frameworks within a banking context.
INFORMATION SECURITY OFFICER
Posted 18 days ago
Job Viewed
Job Description
This role will be responsible for handling the implementation and maintenance of GFG and subsidiaries Information Security Management System in accordance with local laws, regulations and best practices.
KEY ACCOUNTABILITIES- Support Head Information Security in defining and implementation of information security governance documentation including policies, manual, SOPs and guidelines.
- Support Head Information Security in conducting Risk-based Assessment of Information Security policies and operating procedures owned by other departments within the group against industry-recognized security standards and best practices, ensuring adequate preventive, detective and corrective controls to provide data integrity, confidentiality and availability.
- Support Head Information Security in conducting analysis of security requirements and controls to identify gaps and provides recommendations of industry best practices, trends, and technology products.
- Support Head Information Security in conducting on annual basis and continuous basis Information Security Risk Assessment, identify business and technology risks, internal controls which mitigate risks, and related opportunities for internal control improvement.
- Develop and maintain information register and ensure that the information is classified by data owners and protected in accordance with the information classification framework.
- Conducting awareness sessions to the new and existing employees on information security policies and global trends as per the awareness program.
- Support in defining information security requirements in information systems, projects and third parties in cooperation with the delivery departments i.e. ICT, and FM.
- Support in conducting incident investigation for information security incidents and ensuring that the necessary actions and disciplinary actions are taken.
- Support in defining information security requirements to be included in ICT Disaster recovery plans to ensure continuity of information security controls during disasters.
- Support in conducting internal and external audits to ensure that BAC Information Security Management system complies with best practices and local regulations.
- Improve the maturity of the information security management system through suggesting and supporting in the implementation of technologies such as DLP solutions, GRC solutions etc.
Bachelor’s degree in information technology.
Certified Information Security Auditor (CISA) (Preferred)
MINIMUM EXPERIENCE3+ years of Information Security experience
JOB SPECIFIC SKILLS- Proven ability to establish and manage “dotted-line” business relationships to deliver agreed outcomes/deliverables.
- Ability to work effectively with all levels of personnel across the organization.
- Proven ability to communicate clearly and appropriately based on audience with excellent facilitation and customer service skills.
- Excellent written and verbal communications, critical thinking skills, effective interpersonal skills, strong formal presentation abilities.
- Ability to be flexible and work effectively with ambiguity and change.
Senior Information Security Specialist
Posted 18 days ago
Job Viewed
Job Description
Roles & Responsibilities:
- Monitoring the system and ensuring the system is available 24/7.
- Maintain best practices and security standards.
- Design and implement security solutions that protect the organization's On-prem / cloud infrastructure, applications, and data from security threats.
- Conduct regular security assessments of the organization's On-prem / cloud environment to identify potential security vulnerabilities and recommend appropriate remediation measures.
- Configure and maintain various security tools such as firewalls, intrusion detection and prevention systems, and security information and event management (SIEM) systems to ensure optimal protection against security threats.
- Regularly monitor the syslogs and take corrective actions if any security breaches or vulnerabilities are found in the logs.
- Run VAPT tools to mitigate security vulnerabilities.
- Manage access controls for cloud resources, including user authentication and authorization, identity and access management (IAM), and network security groups (NSGs).
- Monitor the On-prem / cloud environment for security incidents and respond promptly to any security breaches or threats.
- Create and maintain security policies and procedures for the organization's On-prem / cloud environment, including disaster recovery plans, incident response plans, and security awareness training for employees.
- Keep up-to-date with the latest security trends and best practices to ensure that the organization's On-prem / cloud environment remains secure against evolving security threats.
- Review and apply the WAF policies to protect against DDoS and application-related attacks.
- Test the WAF rules and ensure they block malicious traffic.
Qualifications & Technical Skills:
- Minimum of 10 years of experience.
- B.Sc. in Computer Engineering or Equivalent.
• Security Incident Handling & Response
• Security Management Frameworks
• Firewall/IDS/IPS (Palo Alto, Fortinet, Cisco, etc.)
• Vulnerability Management (VAPT)
• SIEM Management
• Data Management Protection
• Advanced Malware Prevention
• Identity & Access Management
• AWS: IAM, KMS, VPC, Security Groups, Network ACLs, VPC endpoints, CloudWatch, VPC Flow Logs
• Logging and Monitoring, SIEM, Syslog
• CloudFront, WAF and Certificate Management
• Technical Certifications like CEH, Security+, CISSP, etc.
#J-18808-LjbffrInformation Security and Data Protection Specialist
Posted 8 days ago
Job Viewed
Job Description
Job purpose
- Overseeing information security, cybersecurity and IT risk management programs based on industry-accepted information security and risk management frameworks.
- Responsible for the organization's data privacy and protection function to ensure compliance with various regulations and best practices.
2. Primary Duties Performed
- Develop and maintain the cybersecurity Risk Management Framework of the organization for addressing the overall approach for handling cybersecurity risks and managing them in a methodological manner.
- Evaluate employees' information security awareness and provide the necessary training whenever is needed.
- Conduct frequent reviews on Vulnerability Assessment and Penetration Testing (VAPT) and manage vulnerabilities.
- Define the necessary controls to ensure all regulatory requirements related to cybersecurity are met, designed effectively with clear documentation.
- Identify the critical assets of the organization and ensure implementation of risk identification and management strategies for these critical assets.
- To assess technology projects to ensure that cybersecurity is adequately addressed.
- Responsible to identifying and managing cybersecurity risk for all third-party technology engagements and all cloud computing engagements.
- Evaluates and recommends cybersecurity technologies and solutions.
- Review cybersecurity & Risk Management manual and recommend necessary updates.
- Act as Data Protection Officer to identify and evaluate the Company's data processing activities.
- Monitor data management procedures and compliance within the Company.
- Assess Company compliance with Data Protection Private Law.
- Provide advice and arrange training to employees on Data Protection.
- Review and recommend updates on Data Protection Manual.
- Serve as the point of contact between the company and the data protection authorities.
- Performs other related duties assigned by the department head.
3. Secondary Duties Performed
- Assist in implementing risk management framework, policies and programs covering business, financial, operational, technological, and regulatory risks.
- Assist in the development and management of controls and business contingency plans.
- Maintain and update organizational risk register.
- Oversee the regular validation and testing of the Company Business Continuity Plan.
- Review Risk Management manual and recommend necessary updates.
4. Work & Business Contacts
Internal
- Management team and staff.
External
- Regulatory Bodies: Central Bank of Bahrain and Personal Data Protection Authority.
- Law Firms and Legal Advisors.
- Internal and External Auditors.
- VAPT vendors.
Division / Department: Risk Management
Incumbent Reports to: Manager – Risk & Project Management
#J-18808-LjbffrBe The First To Know
About the latest Threat intelligence Jobs in Bahrain !