Manage internal and external security audit activities, including audit planning, coordination, tracking of audit findings, and ensuring the timely implementation and closure of remediation actions. Support compliance monitoring and continuous improvement efforts relating to ISO/IEC27000 certification and other regulatory requirements.
Manage and ensure authorised access governance in accordance with organisational and regulatory requirements, including reviewing, approving, revoking, and tracking access rights and exceptions where required.
Maintain the cybersecurity risk register, perform cybersecurity risk assessments, monitor risk mitigation plans, and follow up on remediation actions to ensure identified risks are addressed within stipulated timelines. Escalate significant risks to Management where necessary.
...