Compliance Specialist
CORE PROFILE
Information Security Specialist (Information Security Compliance) ensures compliance with core security framework/regulation i.e. ISO27001, BSP, PCI DSS, SOC2, and SWIFT, information security policies, corporate policies and process documents. Provide supports on strengthening information security awareness across internal and external stakeholders, different business units and external parties.
NATURE OF WORK
- Information Security Specialist (Information Security Compliance)
- Performs the following to the assigned engineering units:
- Serve as an Information Security Compliance Subject Matter Expert (SME) for relevant standards, procedures, and regulations.
- Ensure compliance with security-related regulations (e.g. BSP, DPA, ISO27001, PCI DSS, SWIFT) by working closely with different mesh teams, and OCISO SMEs to guarantee that standard practices are followed and results are documented.
- Act as the principal interface or point of contact with internal and external auditors as well as regulators when production systems are within audit scope.
- Enforce and execute tasks stipulated in information security policies and standards
- Perform security review and gap assessment against different security framework, prescribed by PayMaya.
- Ensure security and compliance standards are followed on integrations involving external partners.
DISPLAYED SKILL MASTERY
TECHNICAL SKILLS
- Knowledgeable in Information Security and Risk Management
- Audit leadership skills, security assessments or equivalent
- AWS / Cloud Computing competence
- Project Management
- ISO27001/ISMS compliance
- BSP Security compliance
- PCI DSS compliance
- SWIFT compliance
- Payment Security
SOFT SKILLS
- Strong sense of integrity and identification with the mission.
- Strong team player.
- Strong leadership and negotiation skills
- Ability to thrive on high operational tempo, and high stress environment.
- Manifest critical thinking, creativity and problem-solving
- Ability to process data nd get strategic insights
- Strong written and verbal communication
- Ability to provide on-the-job training and knowledge sharing to other analysts.
REQUIRED QUALIFICATIONS
MINIMUM EXPERIENCE
- 5 years’ experience in the field of information security/payment security.
- EDUCATIONAL BACKGROUND
- BS or equivalent degree in CS, IT, IS or equivalent fields
DESIRED CERTIFICATIONS
- CISA
- ISO/IEC 27001 Lead Auditor /Implementer
- CC
- CRISC
- Certification is just an added advantage, Person should be able to showcase the skill procured in the respective area, Qualified candidates will not have a bar of certification.