Chief Information Security Officer (CISO)

0 8


Under the supervision of the Deputy Chief Executive Officer, you shall:

  • Advise the Senior Management and Board on Cyber and Information Security Management.
  • Formulate an institutional methodology for managing cyber and information security risks.
  • Develop the institution’s Cyber and Information Security policy and submit it to the Senior Management and Board for approval.
  • Develop and update specific and general work procedures for realizing the institution’s cyber and information security policy.
  • Maintain an ongoing process of cyber and information security risk assessment with the relevant institutional units, in order to analyse and assess:
  • the risk levels integral to the institution’s technological and business activities;
  • The controls are required to ensure systems integrity.
  • The level of residual risk and exposure to cyber and information security threats the institution is willing to accept in implementing these activities.
  • Integrate and coordinate all institutional cyber and information security efforts, including oversight and control of all institutional units participating in these efforts.
  • Create a framework for receiving ongoing and ad-hoc reports from various institutional units.
  • Initiate and conduct cyber and information security readiness exercises as follows:
  •  at least quarterly, an exercise shall be staged to assess the ability of one or more institutional entities to deal with a cyber-attack; and
  • once a year, an exercise shall be undertaken to assess the preparedness of the entire institution to withstand cyber-attacks.
  • Coordinate cyber and information security activities, including joint exercises with business partners and service providers.
  • Promote cyber and information security awareness and train employees, suppliers, business partners and customers.
  • Continuously learn and monitor cyber and information security issues by identifying trends, methods and advanced developments in the field while gathering information about emerging attack techniques and ways of dealing with them.
  • Form a Cyber-Incident Response Team.
  • Analyse cyber and information security incidents that have occurred in Ghana and worldwide, and assess their potential impact on the institution, as well as implement the relevant measures proposed.
  • Develop metrics and indicators to assess the effectiveness of cyber and information security systems and procedures.
  • Assess regular and ad-hoc institutional cyber and information security controls.
  • Draw up annual and multiannual work plans, including budgeting, prioritization and timetables for implementing the assessment processes.
  • Prepare and submit annual reports to the Senior Management and Board, detailing the institutionally and information security defence level, weaknesses and vulnerabilities, available countermeasures, and the activities and budgets required to enhance its defences.
  • Be responsible for collaborating with relevant institutions involved in cyber and information security issues.
  • Ensure preparation of reports on major cyber and information security incidents to the Bank of Ghana.


  • You have a bachelor or a master’s degree in computer science and are interested in the microfinance sector and Advans’ missions. You have:
  • A minimum of 4 years experience in a similar position, preferably in the Financial sector
  • Knowledge and experience in IT Security/Governance
  • Professional certificates (CISA, CISM, CISSP, CCSP) are an added advantage
  • Excellent organisational, prioritisation and decision-making skills
  • The ability to work independently and to work as part of a team



CLOSING DATE: December 4, 2021

The post Chief Information Security Officer (CISO) appeared first on NewWebGh.

Leave A Reply

Your email address will not be published.