Cyber Risk Manager
The Cyber Risk Manager guides the assessment of information and cyber risks associated with technology initiatives and provides recommendations on control requirements by risk policy and standards. He/ She manages and coordinates responses to regulatory inquiries, inspections, audits and ensures cyber security standards and policies are established and implemented. He oversees the development of reports and implements policies and standards. He manages employees and is held accountable for the performance and results of a team. He provides guidance on security measures and protocols to stakeholders. He is familiar with cyber security standards, protocols and frameworks, and ensures the organization’s compliance to the Cyber Security Act 2018. He is knowledgeable in using various cyber security monitoring and analysis tools and techniques depending on the organization's needs and requirements. He also has expertise in cyber risk mitigation strategies and protocols. The Cyber Risk Manager has a sharp, analytical mind and is able to anticipate problems and risks to mitigate them ahead of time. He is an excellent communicator who works well with others and promotes a cooperative working environment and relationships within and beyond his team.
Skills and Competencies
Technical Skills & Competencies
Generic Skills & Competencies
Critical Work Functions and Key Tasks
• Manage the strategic development and improvement of risk frameworks, methodologies
and requirements
• Recommend strategies to address key risk areas in cyber security
• Assess business needs against cyber security concerns and legal and/or regulatory requirements
• Anticipate internal and external business challenges and legal or regulatory issues
• Provide strategic risk guidance to stakeholders in the implementation and execution of cyber risk
strategies across the organization
• Formulate governance procedures for documenting and updating security policy,
standards, guidelines and procedures
• Plan the implementation of information systems and cyber security policies
• Develop the organization’s Cyber Risk Maturity model
• Develop policies and frameworks for conducting cyber security risk assessments and compliance audits
• Advise the development of techniques and procedures for the conduct of cyber risk assessments
• Develop plans for cyber risk assessment activities across the organisation
• Coordinate the on-going cyber risk assessment activities across the organisation
• Provide strategic and technical recommendations following identification of vulnerabilities in
operating systems
• Incorporate emerging security and risk management trends, issues, and alerts into
risk assessment framework
• Develop cyber risk mitigation strategies and policies for the organization
• Oversee the development of documentation on methodologies and tools to mitigate cyber risks
• Establish guidelines for reporting outcome of cyber risk assessments
• Oversee the development of internal threat awareness reports
• Present threat awareness reports to technical and non-technical staff
• Develop programmers and initiatives to strengthen the capability of the organization to mitigate risks
• Oversee the planning and conduct of organizational cyber security exercises
• Act as a subject matter expert in cyber security incident and breach investigations
and post-breach remediation work
• Propose procedures to prevent future incidents and improve cyber security
• Monitor the maintenance of the cyber security operations training plans for all security staff
• Manage responses to regulatory inquiries, inspections or audits