Junior Information Security Officer

Amman , Jordan

Job Title: Junior Information Security Officer (Liaison Officer)


Job Purpose

To serve as Delta's internal, full-time operational watchdog and coordinator for information security. The role provides continuous visibility over CBJ Cyber Security Framework (CBJ CSF) related controls in the periods between Cryptika's scheduled reviews, and acts as the standing internal liaison for Cryptika (Delta's outsourced CISO / CISOaaS provider). The purpose is continuity, not duplication: Cryptika visits periodically and provides expert direction, while this role detects day-to-day events (new systems, new vendors, new access, configuration changes), follows them up, keeps evidence, and escalates, so that compliance is actively maintained daily rather than only reviewed periodically. This role does not replace Cryptika; it makes the combined control framework effective in daily operation.


Duties & Responsibilities

Technical & Operational Duties

● Act as the primary internal point of contact for Cryptika, ensuring timely and clear communication between Cryptika and Delta's internal departments.

● Relay operational triggers to Cryptika, new systems, servers, assets, vendors, or remote access requirements, as well as new data sharing agreements, datasets, or sensitive data flows and notify Cryptika, the DPO, IT, or management as required and confirm the right owner has picked it up.

● Coordinate the scheduling and logistics of Cryptika's periodic reviews and site visits, ensuring internal stakeholders and required evidence are ready in advance.

● Follow up with internal departments on action items, recommendations, and control requirements raised by Cryptika, and report progress back to Cryptika and the Risk Section until each item is closed.

● Notify Cryptika promptly of any suspected security incidents and coordinate the flow of information between Cryptika and internal teams during investigation, containment, and closure.

● Maintain a log of all communications, action items, and agreed timelines with Cryptika, to ensure nothing is dropped between review cycles.

● Escalate to Risk Management any items where Cryptika's recommendations remain unaddressed or overdue.

● Ensure that any changes to systems, controls, or processes with security implications are communicated to Cryptika in a timely manner, so their guidance stays current and relevant.

● Support Cryptika by collecting information required for cyber risk assessments and maintaining the cyber risk and Key Risk Indicators (KRIs).

● Monitor operational triggers that may require security, privacy, or compliance action, new systems, servers, assets, vendors, or remote access requirements and notify the responsible owner (Cryptika, DPO, IT or Risk Management).

● Perform any other coordination duties related to the Cryptika relationship as assigned by the direct manager.


Working Relationships

Internal Working Relationships

● Risk Management (narrative reporting line).

● IT Department (technical implementation owner).

● Data Protection Officer (DPO).

● Business departments (owners of data and processes).

● Control owners.


External Working Relationships

● Regulatory bodies (Central Bank of Jordan).

● Cryptika (outsourced CISO / CISOaaS provider).


Required Education Level

● Bachelor’s degree in information technology, Information Security, or equivalent.


Required Work Experience

● 0-2 years of experience in Information Technology or Information Security; prior experience in the insurance or financial sector is preferred.


Required Skills & Abilities

● Results-oriented

● Planning & organization

● Accountability

● Strict confidentiality, this role handles sensitive information across all departments.

● Team collaboration

● Effective communication

● Persistence & initiative

● Confidence to challenge and question control bypasses.

Required Knowledge

● Basic understanding of cybersecurity governance, including general frameworks such as ISO/IEC 27001.

● Familiarity with Central Bank of Jordan Cyber Security Framework (CBJ CSF) requirements.

● Basic understanding of Jordan's Personal Data Protection Law (PDPL) and data protection concepts.

● Basic understanding of risk management principles and the risk management cycle (identification, assessment, treatment, monitoring, and reporting).

● Ability to recognize when a cybersecurity or information security event constitutes a reportable incident.

● Ability to communicate risk and security matters clearly and concisely to non-technical stakeholders.

● Basic IT and security awareness are sufficient to recognize relevant triggers.

● Strong coordination, follow-up, and documentation discipline.


Required Languages

● Fluency in both Arabic and English.


Required Training

● Training courses on the latest developments in cybersecurity and data protection.

● Specialized training on Central Bank of Jordan Cyber Security Framework (CBJ CSF) requirements.

● Training on incident reporting and security awareness.

 

Reference Code
JP26-24
Post Date
26 days ago
Work Class
Junior Level
Work Type
Full-Time
Share This Job Post
Apply Now