· Review and periodically update cybersecurity policies, procedures, standards, and guidelines.
· Perform cybersecurity risk assessments covering assets, systems, projects, and third parties.
· Maintain the cybersecurity risk register, develop treatment plans, track actions, and align decisions with the entity’s approved risk appetite.
· Conduct compliance gap assessments against NCA controls, ISO/IEC 27001, and other applicable national or international frameworks.
· Support internal and external audits, prepare evidence, manage non-compliance cases, and follow remediation through closure.
· Operate or support eGRC and cybersecurity risk-management tools.
· Prepare management reports, executive dashboards, KPIs, compliance status reports, and committee-level presentations.