Develop and maintain IT Risk Management frameworks, policies, and procedures across SOCAR and SOCAR Group entities
Integrate IT, Information Security, Operational Technology (OT), and digital risks into SOCAR’s Enterprise Risk Management (ERM) framework
Support risk assessments for IT infrastructure, applications, cloud services, operational technology, third-party providers and emerging technologies
Monitor IT and information security risk registers, mitigation actions and remediation activities
Support Risk and Control Self-Assessment (RCSA) processes
Monitor compliance with internal policies and industry standards, including COBIT, NIST, ISO 27001, ISO 31000 and ITIL
Assess IT General Controls, monitor IT incidents and support root cause analysis
Prepare risk reports, dashboards, KRIs and analytical summaries for senior management
Xüsusi tələblər
Bachelor's degree in Information Technology, Information Security, Computer Science, Risk Management, or a related field
Minimum 3 years of professional experience in IT Risk Management, IT Audit, Information Security, Software Development, or a related field
Fluency in Azerbaijani and Upper-Intermediate level English proficiency
Strong understanding of IT risk management principles, information security controls, and enterprise risk management practices
Knowledge of internationally recognized frameworks and standards, including COBIT, NIST, ISO 27001, ISO 31000, and ITIL
Experience in the oil & gas, energy, petrochemical, utilities, mining, manufacturing, or other asset-intensive industries will be considered an advantage
Professional certifications such as CRISC, CISA, CISSP, CGEIT, CISM, ISO 27001, ISO 31000, or ITIL Foundation will be considered an advantage