This senior-level Information Security professional will play a critical role in protecting IBEX Global’s infrastructure against emerging threats while supporting the organization’s business objectives. The role requires a strong background in Network and Cyber Security functions and involves coordinating and implementing the IT Security Roadmap and security processes to safeguard IBEX Global’s assets. The position demands hands-on involvement in risk management, vendor assessments, AI risk evaluation, team leadership, and stakeholder engagement.
Key Responsibilities
Information Security Risk Management & Assessments:
Lead and conduct comprehensive IT risk assessments covering infrastructure (on-premises, cloud, hybrid), applications, systems, data security, privacy, identity and access management, and change/configuration management. Develop and maintain risk registers, heatmaps, and executive-level reports. Support internal and external audits by providing necessary risk documentation and remediation evidence.
Supply Chain & Third-Party Risk Management:
Perform IT risk assessments for vendors, partners, and service providers, evaluating risks related to information security, data protection, business continuity, and resilience. Review vendor security questionnaires and audit reports such as SOC2, ISO 27001, PCI DSS, and ISO 42001 for AI service providers. Collaborate with Procurement, Legal, and Compliance teams to establish risk-based onboarding criteria, support contract security clauses, and monitor vendor risk remediation.
AI Risk Assessments & AI System Impact Assessments:
Lead AI risk assessments addressing model risks, data quality and bias, security threats, privacy concerns, and ethical considerations. Conduct AI System Impact Assessments to evaluate effects on individuals, regulatory compliance, and business reputation. Align AI risk activities with frameworks such as ISO/IEC 42001, NIST AI Risk Management Framework, and applicable data protection regulations. Work closely with AI, Data Science, Legal, and Product teams to integrate risk controls throughout AI system lifecycles.
Team Leadership & Management:
Manage, mentor, and coach team members while reviewing and approving risk assessment deliverables to ensure quality and consistency. Allocate tasks, set priorities, and track progress against deadlines. Provide performance feedback, skill development guidance, and technical direction. Promote standardization of risk assessment methodologies, templates, and reporting practices.
Stakeholder Engagement & Reporting:
Serve as a trusted risk advisor to technology, business, and senior leadership stakeholders. Present risk findings and recommendations to IT leadership, risk committees, and senior management. Support the development and enforcement of risk policies, standards, and procedures. Foster a culture of risk awareness and accountability across the organization.
Required Qualifications
- Bachelor’s or Master’s degree in Information Technology, Computer Science, Software Engineering, or Telecommunications.
- 8 to 12 years of relevant experience.
- Minimum 5 years of hands-on experience in IT/Information Security Risk Management.
- Strong understanding of IT risk management concepts, methodologies, controls, and architectures, including cloud environments.
- Proven experience conducting Third-Party and Supply Chain Risk Assessments.
- Familiarity with risk frameworks such as ISO 27005 and NIST Cybersecurity Framework.
- Excellent presentation and communication skills.
- Willingness to work reporting hours from 5 PM to 2 AM (PKST).
This role offers the opportunity to lead critical security initiatives within a global organization, working closely with cross-functional teams to enhance IBEX Global’s security posture and resilience.