Appel à candidature : La BAD recrute un.e Analyste en chef.fe de la cybersécurité basé à Abidjan, Cote d’Ivoire.

 

 

 

 

 

 

 

THE COMPLEX:

The Vice-Presidency, Technology and Corporate Services (TCVP) is responsible for the design, development, and delivery of efficient, people-centered, client-oriented, corporate services and information technology solutions to ensure overall institutional effectiveness in all aspects of the Bank’s corporate services. The Complex provides leadership in the formulation and implementation of the Bank’s strategies, policies, controls, and approaches on organizational information technology systems, software applications, cyber security, IT support, and infrastructure systems. The Complex is also responsible for the management of the Bank’s real estate assets, institutional procurement, language services, and business continuity.

THE HIRING DEPARTMENT/DIVISION:

Cybersecurity is a new Unit within the Bank, established to provide expertise and assistance to ensure the Bank’s infrastructure and information assets are appropriately protected. The Cybersecurity Unit is responsible for safeguarding of all bank’s Information Communication Technology (ICT) assets across all platforms, locations, and stakeholders. The Cybersecurity Unit is part of the Bank’s ICT lifecycle management that provides secure ICT solutions to the Bank. The Unit leads and provides cyber security technology solutions at the Bank, such activities include but are not limited to Cybersecurity Security Operation Center (C-SOC), Cyber Incident Response, Threat Intelligence, Zero-day Attack and Defense, Cloud Security, Mobile Security, Data Security, and Application Security. The Cybersecurity Unit also focuses on developing and driving information risk strategies, and policies/standards, ensuring the effectiveness of solutions, and ensuring appropriate risk policies and procedures such as user log-on and authentication rules, security breach, escalation procedures, and security assessment procedures. The Unit also enforces information security policies and procedures, monitors data security profiles on all platforms, and investigates risk scenarios.

THE POSITION:

The Chief Cybersecurity Analyst will be supporting the Head of Cybersecurity to protect the Bank’s IT resources and information assets by (i) Ensuring strategic alignment of information security in support of business objectives; (ii) Ensuring availability, confidentiality, integrity, audit ability of the Bank’s information systems; (iii) Ensuring the continued availability of the Bank’s information systems; (iv) Ensuring reduction of adverse impacts on the Bank’s business operations to an acceptable level; (v) ensuring conformity of applicable laws, regulations, and standards; (vi) preventing non repudiation at computer-based activities.

KEY FUNCTIONS:

Under the supervision of the Head of Unit, the Chief Cybersecurity Analyst will carry out the following functions.

Information Security Governance: Assist to establish and maintain a framework to provide assurance that information security strategies are aligned with business objectives and consistent with applicable laws and regulations. Includes assisting with the following:

  • Defining and elaborating the information security strategy in support of the Bank’s business strategy and direction.
  • Liaising with HR Operations, Recruitment, and Client Services to ensure that each job description includes information security governance activities.
  • Identifying current and potential legal and regulatory issues affecting information security and assessing their impact on the Bank.
  • Establishing and maintaining information security policies that support business goals and objectives.

 Risk Management: Identify and manage information security risks to achieve business objectives. Include assisting with the following:

  • Developing systematic, analytical, and continuous risk management processes.
  • Ensuring that risk identification, analysis, and mitigation activities are integrated into projects and process life cycles.
  • Identifying and analyzing risks through suitable and recommended methods.

Information Security Program Management: Assist to design, elaborate and manage information security programs to implement the information security governance framework.

  •  Leading in establishing and maintaining plans to implement the information security governance framework.
  •  Helping in defining the annual information security budget and obtaining Information Security Steering Committee approval.
  •  Assisting in managing the information security budget in implementing the information security program.

 Information Security Management: Oversee and supervise information security activities to execute the information security program.

  • Leading the Bank’s IT security team: plan, organize, assign, supervise, and monitor the work of team members
  • Ensuring that the rules of use for information systems and the administrative procedures for information systems comply with the Bank’s information security policies.
  • Ensuring that services provided by other enterprises, including outsourced providers are consistent with established information security policies.

Response Management: Assist to establish and manage the capability to respond to and recover from disruptive and destructive information systems events:

  • Designing, elaborating, and implementing processes for detecting, identifying, and analyzing security-related events.
  • Developing response and recovery plans including organizing, training, and equipping teams.
  • Ensuring periodic testing of the response and recovery plans where appropriate.

COMPETENCIES (skills, experience, and knowledge)

  1. Minimum of a Master’s degree in Information Security, Computer Science, Information Technology, or related discipline.
  2. Preferably seven (7) years of relevant post-qualification experience, with at least three (3) years of demonstrated IT infrastructure implementation and management.
  3. Mixed managerial, analytical, and technical skills and knowledge in all aspects of computer security in multi-IT areas: database, development, network, operating systems, IT security, specific applications security, etc.
  4. Good understanding and writing skills of computer systems security strategies, policies, principles, procedures, and standards.
  5. Good technical knowledge and experience across multiple platforms and technologies: Windows, Unix, Linux, networking, applications concepts, databases; wide area networks; computer operations, Intranet/Internet, LAN/WAN Connectivity with good knowledge of firewalls, switches, and routers (especially Cisco products).
  6. Good technical knowledge and experience in defining access and authorization controls within the Bank’s critical applications: SAP. SWIFT, SUMMIT, etc.
  7. Good technical knowledge and experience in Business Continuity Planning areas.
  8. Good knowledge of structured systems analysis techniques and practices as well as strong analytical and problem-solving skills
  9. Good Knowledge of risk assessment processes
  10. Good understanding of 1SO27001-2, and current legal and regulatory requirements relating to information security and privacy
  11. Up-to-date knowledge of information security, and industry certifications covering information security are added advantages.
  12. Demonstrable experience with networks and systems involved in keeping an organization secure.
  13. Strong management and leadership skills and the ability to influence senior management are essential.
  14. Competence in the use of standard Microsoft Office applications (Word, Excel, Access, and PowerPoint).
  15. Excellent written and verbal communication in English or French with a working knowledge of the other language.

Apply here

Closing Date : 06/04/2023