Job Detail
-
Job ID 146850
Job Description
Location: Kuwait
Reporting To: Technology risk Director
Job Summary:
Seeking an Information Security & Data Privacy Specialist to be deployed onsite with a leading financial institution in support of the Bank’s Non-Financial Risk function. The role delivers advisory and execution support across information security, data privacy, and data protection in alignment with CBK, CBUAE/DFSA, and international regulatory expectations.
Key Responsibilities:
Review and segregate information security and data privacy policies in line with CBK and
CBUAE/DFSA regulations, producing a policy review report highlighting jurisdictional differences and required amendments.
Perform card discovery scans to identify cardholder data across approximately 3,500
Workstations and servers.
Support information security risk assessments across 250+ information assets, per the ISMS Risk Assessment Methodology.
Assist in conducting a CBUAE NESA current-state assessment and develop the associated remediation action plan.
Support Information Security Risk Reviews aligned with ISO 27001, PCI DSS, and SWIFT CSP controls.
Perform Privacy Impact Assessments (PIAs) across approximately 180 banking applications/systems.
Perform Privacy by Design assessments as per CORF across the same application population.
Document Records of Processing Activities (RoPA) across 20 divisions and 170 sub-divisions.
Maintain and update the Bank’s Data Privacy system records.
Prepare weekly/monthly progress reports aligned with the Information Security/Data Privacy plan.
Candidate Profile:
Requirement open to all nationals
5–7 years of experience in Information Security and 3–5 years in Data Privacy.
ISO 27001 / ISO 27701 Lead Auditor or Lead Implementer certification (Information Security/Data Privacy).
CIPM / CIPP certification (Privacy).
CISM / CISA certification (Information Security).
Working knowledge of PCI DSS, SWIFT CSP, and central bank regulations (CBK / CBUAE /
DFSA) relating to information security and data privacy.
Strong knowledge of the ISO 31000 standard and GDPR / regional data privacy requirements.

