Старший специалист по ИТ- и информационной безопасности

в PASHA Financial Holding

О роли

Purpose of the Role
The Senior IT & IS Risk Specialist supports the Group's Information Security and IT risk management across the Corporate Center and Strategic Assets. This role plays a key part in establishing and enhancing risk strategies, frameworks, and baselines, monitors IT/IS risks and key metrics, and provides expert analysis on emerging cyber threats.
Strategic Context
Within the Corporate Center, the Senior Specialist oversees information security policies and standards, data security and identity controls, incident response, and third-party risk mitigation. The role collaborates with stakeholders across the Group to promote consistent risk practices, strengthen cyber resilience, protect critical assets, and ensure operational continuity.
The Senior Specialist works closely with the IT and IS Risk Manager and partners with Strategic Asset risk and information security teams to align cyber and technology risk priorities across the Group.
Key Responsibilities
Group-wide IT & Information Security Risk Management — Governance & Strategy
  • Contribute to shaping the direction of Information Security and Technology Risk management across the Corporate Center and Strategic Assets
  • Drive implementation and tracking of strategic targets related to cyber resilience and technology risk across the Group
  • Facilitate the integration of IT and cyber risk considerations into enterprise risk management processes
  • Provide expert analysis on emerging cyber threats and technology risk exposures to relevant stakeholders
  • Coordinate cyber capability maturity assessments and track improvement initiatives across Strategic Assets
  • Follow up on the execution of IT and Information Security roadmaps across Strategic Assets and highlight gaps against strategic objectives
Frameworks, Baselines & Methodologies
  • Maintain and enhance the Group-wide IT and Information Security Risk Management framework
  • Establish and maintain the Group-wide methodology for Critical Services and Systems Availability
  • Maintain and communicate Business Continuity baseline requirements across the Group
  • Maintain the Third-Party Cyber Risk Management baseline and monitor its application
  • Coordinate Group-wide Penetration Testing requirements and practices
  • Ensure frameworks and methodologies remain aligned with recognized standards such as ISO 27001 and the NIST Cybersecurity Framework
  • Participate in defining the Group-wide Artificial Intelligence (AI) security management framework, including governance principles, risk assessment methodologies, and control requirements for the secure use of AI solutions
Risk Monitoring & Reporting
  • Maintain standards for IT and Information Security risk reporting across the Group
  • Establish and track Key Risk Indicators (KRIs) for cyber and technology risks
  • Review quarterly IT and Information Security risk reports from Strategic Assets and consolidate key insights
  • Contribute to updates of the Risk Appetite Statement related to IT and cyber risk
  • Maintain Risk Health Index metrics for technology and cyber risk domains
  • Escalate material cyber and technology risks with recommended mitigation options to the IT and IS Risk Manager and Risk Director
Stakeholder Engagement & Communication
  • Act as a key point of contact on cyber and technology risk topics for Strategic Assets
  • Participate in Strategic Asset Risk Management Committees and provide subject matter expertise
  • Promote alignment on cyber and technology risk priorities across the Corporate Center and Strategic Assets
  • Maintain and contribute to the Group-wide Information Security community
Industry & Regulatory Alignment
  • Benchmark cyber risk management practices against industry standards and peers
  • Monitor regulatory and industry developments related to IT security and cyber risk
  • Promote adoption of relevant regulatory expectations and leading practices across Strategic Assets
Information Security of the Corporate Center — Security Policy and Standards
  • Develop, implement, and maintain information security policies, standards, and procedures aligned with industry best practices and regulatory requirements
  • Promote effective communication and understanding of policies among relevant personnel
  • Regularly review and update policies to address evolving threats and technologies
  • Monitor adherence to security policies and standards across the organization
  • Provide guidance and support to employees in understanding and complying with security requirements
Data Security Monitoring and Control
  • Monitor and analyze data protection alerts to identify potential data leakage, unauthorized data transfers, or misuse of sensitive information
  • Investigate suspicious activities, validate incidents, and coordinate with relevant stakeholders to ensure timely remediation
  • Continuously fine-tune monitoring rules and detection scenarios to improve accuracy and reduce false positives
  • Monitor user access activities and changes to critical systems to detect unauthorized or inappropriate access to sensitive data
  • Review access control reports and privilege assignments to monitor alignment with internal policies and segregation of duties principles
  • Support regular access reviews and contribute to strengthening data access controls across the organization
Identity Infrastructure Monitoring and Control
  • Monitor core identity and authentication systems to detect unauthorized account changes, privilege escalations, and abnormal access activities
  • Track the creation, modification, and deletion of user accounts, roles, and group memberships to ensure compliance with access governance standards
  • Investigate high-risk or suspicious identity-related events and coordinate timely remediation with relevant teams
  • Review and analyze changes within identity repositories and authentication policies to ensure integrity, traceability, and accountability
  • Support periodic access recertification and segregation of duties controls across critical systems
  • Identify gaps in identity and access monitoring processes and recommend enhancements to strengthen overall security posture
Incident Response and Management
  • Develop and maintain a comprehensive incident response plan, outlining procedures for identifying, containing, and resolving security incidents
  • Conduct regular tabletop exercises and drills to test the effectiveness of the incident response plan
  • Lead investigations into security incidents to determine root cause, extent of damage, and necessary corrective actions
  • Gather and analyze evidence to support investigations and legal proceedings, if required
  • Coordinate with relevant stakeholders, including law enforcement and external experts, as needed
  • Conduct post-incident analysis to identify lessons learned and improve future prevention efforts
  • Implement recommendations to strengthen security controls and prevent similar incidents from occurring
Security Awareness and Training
  • Develop and deliver security awareness training programs to educate employees about security best practices and the importance of protecting sensitive information
  • Promote a culture of security awareness through various communication channels, including newsletters, posters, and workshops
  • Provide specific training on phishing and social engineering tactics to help employees recognize and avoid potential threats
  • Conduct phishing simulations to assess employee awareness and identify areas for improvement
Vendor and Third-Party Risk Management
  • Assess the security practices of third-party vendors and suppliers to ensure they meet the organization's security standards
  • Require vendors to sign appropriate security agreements and undergo regular security audits
  • Develop and implement measures to mitigate risks associated with third-party relationships, such as data sharing agreements and access controls
  • Monitor vendor performance and address any security concerns that arise
Key Relationships
Internally, the role collaborates closely with IT Security Engineers, Network Engineers, Systems Administrators, Application Developers, and IT Project Managers on the design and integration of security controls; with Operational and Financial Risk Managers on IT-related risk; with Legal Counsel on data privacy and incident response matters; with HR Business Partners and Training and Development Specialists on security awareness programs; and with Business Unit Heads, Line Managers, and Data Owners on communicating and enforcing security requirements.
Externally, the role engages with regulators (including the Central Bank, Insurance Supervisory Authority, and Data Protection Authority), industry and cybersecurity associations, technology and cloud service vendors, external IT and financial auditors, and cybersecurity consultants such as threat intelligence analysts, penetration testers, and forensic investigators. The role also works closely with Strategic Asset risk management and information security teams on risk identification, security baselines, incident response coordination, and cyber maturity improvement initiatives.
Requirements
Required:
  • Bachelor's degree or higher in Information Security, Informatics, Computer Science, Management of Information Systems, or a related field
  • Minimum of 4+ years of professional experience in Information Security and IT, with a strong focus on risk management, compliance, and incident response
  • Strong understanding of operating systems, networking, firewalls, application security, virtualization, cloud security, and data privacy
  • Familiarity with information systems concepts, including security and control risks, logical and physical access security, change management, information security and privacy, business recovery practices, and network technology
  • Proficiency in one or more relevant certifications, such as CRISC, CISM, CISSP, ISO/IEC 27005 Risk Management, or equivalent technology industry certifications (e.g., Certified Network Engineer, Certified Security Professional)
  • Experience with information security standards and regulations such as the ISO 27k family, NIST, and PCI DSS
  • In-depth understanding of information security paradigms and risk management concepts
  • Work experience and sound knowledge of the banking or insurance industry
  • Excellent written and verbal communication skills, including the ability to present technical information to both technical and non-technical audiences
  • Strong writing and documentation skills for creating clear and concise reports, policies, and procedures
  • Proven experience working within group structures and collaborating with multiple entities, subsidiaries, or business units in a complex organizational environment
  • Demonstrated ability to identify, assess, and mitigate security risks in complex IT landscapes
  • Experience developing and implementing information security policies, standards, and procedures
Preferred:
  • Experience coordinating cyber capability maturity assessments or leading improvement initiatives across multiple business units or subsidiaries
  • Familiarity with AI security governance, risk assessment methodologies, and control requirements for the secure use of AI solutions
  • Prior experience engaging directly with regulators or industry associations on cybersecurity and data privacy matters
Purpose of the Role
The Senior IT & IS Risk Specialist supports the Group's Information Security and IT risk management across the Corporate Center and Strategic Assets. This role plays a key part in establishing and enhancing risk strategies, frameworks, and baselines, monitors IT/IS risks and key metrics, and provides expert analysis on emerging cyber threats.
Strategic Context
Within the Corporate Center, the Senior Specialist oversees information security policies and standards, data security and identity controls, incident response, and third-party risk mitigation. The role collaborates with stakeholders across the Group to promote consistent risk practices, strengthen cyber resilience, protect critical assets, and ensure operational continuity.
The Senior Specialist works closely with the IT and IS Risk Manager and partners with Strategic Asset risk and information security teams to align cyber and technology risk priorities across the Group.
Key Responsibilities
Group-wide IT & Information Security Risk Management — Governance & Strategy
  • Contribute to shaping the direction of Information Security and Technology Risk management across the Corporate Center and Strategic Assets
  • Drive implementation and tracking of strategic targets related to cyber resilience and technology risk across the Group
  • Facilitate the integration of IT and cyber risk considerations into enterprise risk management processes
  • Provide expert analysis on emerging cyber threats and technology risk exposures to relevant stakeholders
  • Coordinate cyber capability maturity assessments and track improvement initiatives across Strategic Assets
  • Follow up on the execution of IT and Information Security roadmaps across Strategic Assets and highlight gaps against strategic objectives
Frameworks, Baselines & Methodologies
  • Maintain and enhance the Group-wide IT and Information Security Risk Management framework
  • Establish and maintain the Group-wide methodology for Critical Services and Systems Availability
  • Maintain and communicate Business Continuity baseline requirements across the Group
  • Maintain the Third-Party Cyber Risk Management baseline and monitor its application
  • Coordinate Group-wide Penetration Testing requirements and practices
  • Ensure frameworks and methodologies remain aligned with recognized standards such as ISO 27001 and the NIST Cybersecurity Framework
  • Participate in defining the Group-wide Artificial Intelligence (AI) security management framework, including governance principles, risk assessment methodologies, and control requirements for the secure use of AI solutions
Risk Monitoring & Reporting
  • Maintain standards for IT and Information Security risk reporting across the Group
  • Establish and track Key Risk Indicators (KRIs) for cyber and technology risks
  • Review quarterly IT and Information Security risk reports from Strategic Assets and consolidate key insights
  • Contribute to updates of the Risk Appetite Statement related to IT and cyber risk
  • Maintain Risk Health Index metrics for technology and cyber risk domains
  • Escalate material cyber and technology risks with recommended mitigation options to the IT and IS Risk Manager and Risk Director
Stakeholder Engagement & Communication
  • Act as a key point of contact on cyber and technology risk topics for Strategic Assets
  • Participate in Strategic Asset Risk Management Committees and provide subject matter expertise
  • Promote alignment on cyber and technology risk priorities across the Corporate Center and Strategic Assets
  • Maintain and contribute to the Group-wide Information Security community
Industry & Regulatory Alignment
  • Benchmark cyber risk management practices against industry standards and peers
  • Monitor regulatory and industry developments related to IT security and cyber risk
  • Promote adoption of relevant regulatory expectations and leading practices across Strategic Assets
Information Security of the Corporate Center — Security Policy and Standards
  • Develop, implement, and maintain information security policies, standards, and procedures aligned with industry best practices and regulatory requirements
  • Promote effective communication and understanding of policies among relevant personnel
  • Regularly review and update policies to address evolving threats and technologies
  • Monitor adherence to security policies and standards across the organization
  • Provide guidance and support to employees in understanding and complying with security requirements
Data Security Monitoring and Control
  • Monitor and analyze data protection alerts to identify potential data leakage, unauthorized data transfers, or misuse of sensitive information
  • Investigate suspicious activities, validate incidents, and coordinate with relevant stakeholders to ensure timely remediation
  • Continuously fine-tune monitoring rules and detection scenarios to improve accuracy and reduce false positives
  • Monitor user access activities and changes to critical systems to detect unauthorized or inappropriate access to sensitive data
  • Review access control reports and privilege assignments to monitor alignment with internal policies and segregation of duties principles
  • Support regular access reviews and contribute to strengthening data access controls across the organization
Identity Infrastructure Monitoring and Control
  • Monitor core identity and authentication systems to detect unauthorized account changes, privilege escalations, and abnormal access activities
  • Track the creation, modification, and deletion of user accounts, roles, and group memberships to ensure compliance with access governance standards
  • Investigate high-risk or suspicious identity-related events and coordinate timely remediation with relevant teams
  • Review and analyze changes within identity repositories and authentication policies to ensure integrity, traceability, and accountability
  • Support periodic access recertification and segregation of duties controls across critical systems
  • Identify gaps in identity and access monitoring processes and recommend enhancements to strengthen overall security posture
Incident Response and Management
  • Develop and maintain a comprehensive incident response plan, outlining procedures for identifying, containing, and resolving security incidents
  • Conduct regular tabletop exercises and drills to test the effectiveness of the incident response plan
  • Lead investigations into security incidents to determine root cause, extent of damage, and necessary corrective actions
  • Gather and analyze evidence to support investigations and legal proceedings, if required
  • Coordinate with relevant stakeholders, including law enforcement and external experts, as needed
  • Conduct post-incident analysis to identify lessons learned and improve future prevention efforts
  • Implement recommendations to strengthen security controls and prevent similar incidents from occurring
Security Awareness and Training
  • Develop and deliver security awareness training programs to educate employees about security best practices and the importance of protecting sensitive information
  • Promote a culture of security awareness through various communication channels, including newsletters, posters, and workshops
  • Provide specific training on phishing and social engineering tactics to help employees recognize and avoid potential threats
  • Conduct phishing simulations to assess employee awareness and identify areas for improvement
Vendor and Third-Party Risk Management
  • Assess the security practices of third-party vendors and suppliers to ensure they meet the organization's security standards
  • Require vendors to sign appropriate security agreements and undergo regular security audits
  • Develop and implement measures to mitigate risks associated with third-party relationships, such as data sharing agreements and access controls
  • Monitor vendor performance and address any security concerns that arise
Key Relationships
Internally, the role collaborates closely with IT Security Engineers, Network Engineers, Systems Administrators, Application Developers, and IT Project Managers on the design and integration of security controls; with Operational and Financial Risk Managers on IT-related risk; with Legal Counsel on data privacy and incident response matters; with HR Business Partners and Training and Development Specialists on security awareness programs; and with Business Unit Heads, Line Managers, and Data Owners on communicating and enforcing security requirements.
Externally, the role engages with regulators (including the Central Bank, Insurance Supervisory Authority, and Data Protection Authority), industry and cybersecurity associations, technology and cloud service vendors, external IT and financial auditors, and cybersecurity consultants such as threat intelligence analysts, penetration testers, and forensic investigators. The role also works closely with Strategic Asset risk management and information security teams on risk identification, security baselines, incident response coordination, and cyber maturity improvement initiatives.
Requirements
Required:
  • Bachelor's degree or higher in Information Security, Informatics, Computer Science, Management of Information Systems, or a related field
  • Minimum of 4+ years of professional experience in Information Security and IT, with a strong focus on risk management, compliance, and incident response
  • Strong understanding of operating systems, networking, firewalls, application security, virtualization, cloud security, and data privacy
  • Familiarity with information systems concepts, including security and control risks, logical and physical access security, change management, information security and privacy, business recovery practices, and network technology
  • Proficiency in one or more relevant certifications, such as CRISC, CISM, CISSP, ISO/IEC 27005 Risk Management, or equivalent technology industry certifications (e.g., Certified Network Engineer, Certified Security Professional)
  • Experience with information security standards and regulations such as the ISO 27k family, NIST, and PCI DSS
  • In-depth understanding of information security paradigms and risk management concepts
  • Work experience and sound knowledge of the banking or insurance industry
  • Excellent written and verbal communication skills, including the ability to present technical information to both technical and non-technical audiences
  • Strong writing and documentation skills for creating clear and concise reports, policies, and procedures
  • Proven experience working within group structures and collaborating with multiple entities, subsidiaries, or business units in a complex organizational environment
  • Demonstrated ability to identify, assess, and mitigate security risks in complex IT landscapes
  • Experience developing and implementing information security policies, standards, and procedures
Preferred:
  • Experience coordinating cyber capability maturity assessments or leading improvement initiatives across multiple business units or subsidiaries
  • Familiarity with AI security governance, risk assessment methodologies, and control requirements for the secure use of AI solutions
  • Prior experience engaging directly with regulators or industry associations on cybersecurity and data privacy matters
Локация
Bakı
Опыт
Senior
Занятость
Полная занятость
Зарплата
Не указана
Опубликовано
14 сентября 2026

О компании

PASHA Financial Holding
Investment Management · 51-200 · Bakı
Все вакансии PASHA Financial Holding

Ваш отклик

Этот работодатель принимает отклики у себя на сайте. Перейдите на страницу вакансии и заполните форму там.

Перейти на страницу работодателя

Похожие по навыкам

Все похожие вакансии

Вакансии, где совпадает больше всего навыков из этой позиции.

Все похожие вакансии
Не указана
Старший специалист по ИТ- и информационной безопасности
Откликнуться