Job Vacancy: Cyber Security Manager
Department: Financial Control & Internal Audit
Job Summary
We are seeking an experienced Cyber Security Manager to establish and lead the organization’s cyber security function within the Financial Control & Internal Audit Department. The successful candidate will be responsible for developing the cyber security strategy, assessing IT and cyber risks, strengthening security controls, conducting cyber security audits, and building a scalable security program that protects the organization’s information assets.
Key Responsibilities
* Establish and lead the organization’s cyber security function.
* Build and implement the IT & Cyber Security Audit Program.
* Develop cyber security policies, standards, procedures, and guidelines.
* Review SAP user access rights and segregation of duties (SoD).
* Review data security, backup, disaster recovery, and business continuity procedures.
* Review Zoho CRM security controls within the E-commerce Department.
* Assess cyber security risks and evaluate security controls across all business systems.
* Evaluate the effectiveness of IT General Controls (ITGCs).
* Conduct cyber security risk assessments and recommend mitigation plans.
* Review identity and access management processes.
* Coordinate vulnerability assessments and monitor remediation activities.
* Monitor compliance with internal security policies and recognized cyber security frameworks.
* Report cyber security audit findings, risk ratings, and recommendations to the Chief Audit Officer.
* Work closely with IT and business departments to improve the organization’s security posture.
* Lead cyber security awareness initiatives across the company.
* Build the Cyber Security team, including participating in the recruitment, onboarding, and development of future Cyber Security Specialists.
Qualifications
* Bachelor’s degree in Cyber Security, Information Technology, Computer Science, Information Systems, or a related field.
* Master’s degree is an advantage.
Experience
* Minimum 6–8 years of experience in cyber security, information security, IT audit, or cyber risk management.
* At least 2 years in a leadership, senior, or project lead role.
* Experience implementing or managing enterprise cyber security programs is highly preferred.
* Experience with SAP security and ERP environments is an advantage.
Technical Skills
* Strong knowledge of cyber security frameworks (NIST CSF, ISO/IEC 27001, CIS Controls).
* Experience with SAP authorization concepts and segregation of duties.
* Knowledge of network, endpoint, server, cloud, and application security.
* Familiarity with backup, disaster recovery, and business continuity practices.
* Experience reviewing ERP and CRM platforms, including SAP and Zoho CRM.
How to Apply:
Interested candidates are invited to send their CV to (hr@taawon.iq) with the subject line: Cyber Security Manager