Information Security Risk Management Analyst
IDLC Finance PLC • Dhaka, Bangladesh
Role Overview
IDLC Finance PLC is seeking a qualified professional for the position of Information Security Risk Management Analyst within its Enterprise Risk Management (ERM) team. The role focuses on overseeing information security and data protection risks, ensuring regulatory compliance, and strengthening the organization’s cybersecurity governance framework.
Key Responsibilities
- Develop and maintain the Information Security Risk Management Framework aligned with ERM policies
- Maintain the Information Security Risk Register and monitor security and data protection risks
- Define and monitor Key Risk Indicators (KRIs) related to information security
- Prepare risk dashboards and reports for senior management and the Board Risk Committee
- Oversee the enterprise Data Classification Framework to protect information assets
- Provide governance oversight of the Privacy Information Management System (ISO/IEC 27701)
- Conduct information security risk assessments for third-party vendors
- Perform security risk reviews for new systems and digital initiatives
- Review major security incidents and ensure corrective actions are implemented
- Monitor compliance with Bangladesh Bank ICT Security Guidelines
- Conduct training and awareness programs on information security risks
- Perform ad hoc risk analysis assignments as required by management
Educational Requirements
- Bachelor’s or Master’s degree in Information Security, Cyber Security, Computer Science, Information Technology, EEE, or related fields
Experience
- 5-7 years of experience in information security risk management, IT audit, technology risk, or IT governance
- Experience in banks or financial institutions will be an added advantage
Professional Certifications
- CISA, CRISC, ISO 27001 Lead Auditor / Implementer, or equivalent certifications will be an advantage
Required Skills & Competencies
- Strong knowledge of information security risk management and enterprise risk frameworks
- Understanding of ISO 27001, ISO 27701, and regulatory compliance standards
- Experience in risk assessment, control evaluation, and risk reporting
- Strong analytical, communication, and reporting skills
- Ability to work independently and provide objective risk oversight











