Deskripsi Pekerjaan
Join BOF, Inc. as a pivotal Risk and Information Security Officer to safeguard our digital infrastructure and drive proactive risk management initiatives. This critical role combines strategic oversight with hands-on security operations to protect sensitive data, ensure regulatory compliance, and fortify our organization against evolving cyber threats. You'll collaborate across departments to implement robust security frameworks, conduct comprehensive risk assessments, and develop mitigation strategies that align with industry standards like ISO 27001 and NIST.
As a key guardian of our information assets, you'll lead incident response planning, manage security audits, and champion continuous improvement of our security posture. This position offers the opportunity to shape enterprise-wide security policies while working in a dynamic environment that values innovation and resilience. If you're passionate about protecting critical systems and thrive in roles requiring meticulous attention to detail, we invite you to contribute to BOF, Inc.'s commitment to operational excellence and data integrity.
Tanggung Jawab
- Develop and implement enterprise-wide risk management frameworks aligned with banking regulations
- Conduct regular security assessments, penetration testing, and vulnerability scans
- Establish and maintain information security policies, procedures, and controls
- Lead incident response planning and coordinate breach mitigation activities
- Ensure compliance with BSP Circulars, PCI-DSS, and other regulatory requirements
- Manage vendor risk assessments and third-party security evaluations
- Deliver security awareness training and promote security culture across departments
- Monitor threat intelligence and emerging risks to inform security strategy
Kualifikasi
- Bachelor's degree in Information Technology, Cybersecurity, or related field
- Minimum 5 years of experience in information security or risk management
- Professional certifications (CISSP, CISA, or CISM) preferred
- Deep knowledge of banking regulations (BSP, AML/CFT)
- Experience with SIEM tools, vulnerability scanners, and security automation
- Strong analytical skills for threat modeling and risk quantification
- Excellent written and verbal communication for stakeholder reporting
- Proven ability to develop security policies and incident response plans