Job Title: Analyst Enterprise Risk Management
Reporting to: Senior Specialist Enterprise Risk Management
Division – Risk & Compliance
No. of Vacancies: 1
Mission/ Core purpose of the Job
MTN Uganda is operating in a complex risk environment and increasingly has to address multiple risks arising from many directions. Yet this does not mean all risk is detrimental to MTN’s future success. In a rapidly evolving industry, a pragmatic approach is expected to anticipate and respond to changing needs for MTN to retain competitive advantage whilst managing risk within acceptable levels.
The Analyst ERM primarily supports the Senior Specialist ERM in oversight on technology risks identified or/and owned by business. Working with Business Unit Senior Managers and, along with other risk professionals in BRM, the Technology Risk Analyst will ensure that the information risks to the business are identified, assessed, mitigated, monitored and reported.
Main Job Functions:
- Supporting the implementation of the MTN group risk management strategy and framework as it relates to technology/information risk
- Support the execution of technology risk assurance plans
- Support the execution of formal technology risk analyses, reviews, tests, audits and/or self-assessments.
- Design appropriate remedial actions for identified risks, drive remediation of findings and management of risks and exemptions.
- Provide technical advice on products and technology controls.
- Ensure that risks envisaged in planned new systems, products & services, projects and data migrations are flagged early, escalated as appropriate and resolved quickly.
- Evaluate and/or test solutions/systems and ensure appropriate information security requirements and controls have been considered and incorporated into these, where necessary support the remediation of findings.
- Report technology risks in an appropriate way for different audiences; Production of reports/dashboards such as the risk profile reports (including reports submitted to the Executive, Board and Committees)
- Manage information security investigations and incident management.
- Supporting the provision of regular review and challenge to first line risk management, escalating any major risks and concerns in a timely manner.
- Maintaining industry awareness, best practice insight and regulatory knowledge with regards to technology risk management.
- Coordinate/Support to internal and external Audit on technology controls
- Represent the division in various meetings/committees as may be assigned for risk oversight e.g. procurement; product development; etc
Job Requirements (Education, Experience and Competencies)
Education:
- Bachelor’s degree in information technology/ systems, computer science, computer/ electronic engineering or related field with at least five years’ information technology experience, with at least two years in information security governance, risk and compliance;
- Professional risk qualification with preferably two years post-qualification experience in a complex technology and/or financial services organization e.g. CISM, CISA, CISSP
Membership/Affiliation with Risk Management bodies e.g. ISACA
Experience:
Experience in interpreting and understanding an organization’s technical and business environment;
• Experience in developing the appropriate information security governance and compliance measures;
• Experience in information security risk and incident management, business continuity, disaster recovery, information security incident management, auditing and conducting assessments;
• Experience in assessments against international information security standards and/or best practice such as the ISO 27000 series, NIST 800 series, COBIT;
• Able to analyze large volumes of data using data analytical tools e.g. ACL or SQL
• Strong written and verbal communication skills.
Other Skills and Attributes
• Corporate Governance
• Information and/or Security Risk
• Regulatory Compliance
• Information Security Risk;
• Ability to gauge and manage risk.
• Project Management abilities, including escalation of issues, analytical thinking and lateral creativity
• Good Interpersonal skills
• Able to present and report on complex information in an innovative and informative way.
• Working under pressure to meet reporting deadlines
• Independent attitude and team spirit.
• Consistent demonstration of excellent written and verbal communication
• Collaborative
• Conflict handling & Resolution
• Inquisitive skewed to research
• Integrity
• Persuasiveness
Click Here to Apply
More Information
- Salary Offer 0-ush50000000 USD 0-ush50000000 Month
- Address Kampala, Kampala, Uganda