Information Security Management Expert
STRASBOURG, 67
il y a 11 heures
- Perform ISMS control audits
- Supports the Agency's Information Security Officers in the management of information security and business continuity across organizational business processes and information systems
- Develop security controls in the context of the agency's information security framework.
- Expected also to perform the following tasks:
- Perform risk assessments
- Develop Information Security Management System (ISMS) procedures
- Develop conceptual, logical and physical security models as appropriate.
- Draft security policies, standards, procedures and guidelines in accordance with ISO27001
- Development of security plans and documentation (e.g. risk treatment plans, security test plans)
- Development of business continuity and disaster recovery plans.
- Perform security assessments and audits
- Perform ISMS control audits
- Perform ISMS gap assessments
- Design security controls in accordance with agency information security policies and standards
- Provide assistance in formal accreditation process for information systems handling EU sensitive and classified information.
- Minimum 4 years of relevant education (master or equivalent) after the secondary school
- Minimum 6 years of general IT professional experience, of which
- Minimum 3 years of relevant professional experience in Information Security Management
- Good knowledge of/in:
- ISO27001 implementation and management.
- Relevant standards and good practice in information security management
- Information risk management (in particular E-BIOS)
- Governance, Risk & Compliance (GRC) practices and controls
- ISO27001 security control audits and assessments
- Developing security policies, standards and guidelines in accordance with ISO27001 and EU security policies and standards
- Design, implementation and assessments of good practice security control frameworks such as SANS Top 20 Critical Controls, OWASP Application Security Verification Standard,
- Secure development processes (Security and Privacy design)
- Implementation of EU data protection principles in information system design and processes.
- This profile is expected to possess one or more of the following qualifications:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- ITIL/ITIL V3
- BSI ISO27001 Lead Auditor Qualification
Entreprise
Spektrum
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
FRANCE
il y a 24 jours
STRASBOURG, 67
il y a 24 jours
STRASBOURG, 67
il y a 9 heures
STRASBOURG, 67
il y a 1 jour