Applications are invited for a career opportunity as Senior ICT Officer – Cybersecurity, Governance and Compliance. The officer may be required to provide after-hours, emergency or scheduled support where ICT incidents, cybersecurity events, system outages, maintenance activities or operational disruptions require urgent attention.
The primary function of the Senior ICT Officer – Cybersecurity, Governance and Compliance is responsibility for leading ICT governance, cybersecurity coordination, compliance monitoring, risk management and control assurance activities for the Company. The role supports the Chief Information and Communication Technology Officer (CICTO) in strengthening the Company’s cybersecurity posture, ICT governance framework, data protection readiness, audit preparedness, policy compliance and remediation tracking. It ensures that ICT policies, procedures, standards and security control requirements are developed, implemented, monitored and maintained in support of the Company’s operational, regulatory and strategic requirements. The role also provides governance oversight, assurance, coordination and reporting over cybersecurity, ICT risk, compliance and data protection matters. Routine firewall administration, network administration, server administration, application development and day-to-day technical configuration remain with the relevant operational ICT roles. This role reviews, guides, monitors and escalates where required to ensure alignment with approved policies, standards and control requirements.
Qualifications, Knowledge, Skills and Abilities Required
A degree Information Technology, Cybersecurity, Information Systems, Computer Science, Risk Management or a related field.
Five (5) to seven (7) years’ experience in ICT, cybersecurity, governance, risk, compliance, information systems or a related area.
Experience coordinating audits, remediation plans, cybersecurity assessments, ICT risk activities or control improvement initiatives.
Working knowledge of cybersecurity frameworks, data protection principles, ICT governance and operational resilience.
Experience supervising technical staff or coordinating cross-functional ICT activities would be an asset.
ISC2 CGRC or equivalent governance, risk and compliance certification; CISA, CISSP, CEH or equivalent cybersecurity management certification; Data protection, privacy or risk management training; ICS or OT cybersecurity awareness training and Project management or IT service management training would be an asset.
Strong understanding of cybersecurity governance, risk and compliance; the ability to interpret technical risks and present them in business terms and strong documentation, reporting and follow-up skills.
Sound judgement and discretion and the ability to coordinate multiple stakeholders and drive remediation to completion.
Strong written and verbal communication skills and leadership and supervisory capability.
Duties and Responsibilities include, but are not limited to:
Cybersecurity Governance and Strategy Support
Support the CICTO in the development, review and implementation of the Company’s cybersecurity strategy, cybersecurity roadmap, control improvement program and related risk-reduction initiatives.
Support the CICTO in preparing budget estimates, resource requirements, procurement justifications and expenditure forecasts for cybersecurity, governance, compliance and risk-related initiatives.
Develop, maintain and coordinate ICT security policies, standards, procedures and control requirements.
Support the implementation of a layered cybersecurity program across corporate ICT, cloud services and operational technology environments.
Monitor cybersecurity risks and ensure that identified risks are documented, tracked and escalated where required.
Coordinate cybersecurity improvement plans, vulnerability remediation tracking and control strengthening activities.
Provide oversight of managed detection and response services and external cybersecurity providers.
Review cybersecurity reports and ensure that material risks, recurring weaknesses or unresolved issues are brought to the attention of the CICTO.
Maintain and support continual improvement of the Company’s information security management practices, policies and control evidence.
Governance, Risk and Compliance
Maintain ICT governance frameworks, procedures and reporting mechanisms.
Support ICT risk assessments, risk registers, control reviews and compliance reporting.
Coordinate ICT input into internal and external audit responses.
Track corrective actions arising from audits, assessments, vulnerability scans, cybersecurity reviews and control improvement activities.
Ensure ICT activities align with approved policies, procedures and change-control requirements.
Maintain evidence of compliance for access control, cybersecurity, incident management, data protection and operational resilience.
Provide governance input into ICT projects to ensure that security, compliance and risk requirements are considered from the planning stage.
Data Protection and Privacy Coordination
Support the Company’s data protection compliance activities from an ICT perspective.
Assist with ICT-related data protection procedures, data-handling requirements and evidence gathering.
Support privacy impact assessments where ICT systems, applications or data processing activities are involved.
Coordinate with internal stakeholders on data breaches, data access requests and privacy-related ICT controls.
Ensure that access control, retention, data minimization and secure data-handling requirements are considered in ICT systems and projects.
Work with the Senior ICT Officer – Data, Business Intelligence & Automation to ensure that data, reporting, automation and internal application initiatives include appropriate security, privacy and access-control considerations.
Incident, Vulnerability and Remediation Oversight
Coordinate ICT’s response to cybersecurity incidents, control weaknesses and vulnerability findings.
Ensure incidents are documented, escalated and reviewed in accordance with approved procedures.
Track remediation actions assigned to ICT teams, vendors, managed service providers or other responsible parties.
Ensure lessons learned are captured and used to improve policies, controls, procedures and user awareness.
Support business continuity and disaster recovery planning from a cybersecurity, governance and control assurance perspective.
Coordinate cybersecurity advisories, awareness notices and guidance to employees in response to emerging threats, social engineering attempts, account compromise, messaging platform risks and other user-facing cybersecurity concerns.
Leadership and Supervision
Provide direction and oversight to assigned ICT Officers.
Ensure operational ICT teams comply with approved policies, standards and control requirements.
Support training, development, performance management and improvement of staff within the cybersecurity, governance and compliance reporting line.
Provide guidance to operational ICT roles on cybersecurity controls, compliance expectations, audit evidence and remediation requirements.
May be required to act for the CICTO when required and authorized.
The BNECL is an equal opportunity employer committed to fostering a diverse and inclusive workplace.
Deadline for Applications
Applications should be submitted to the Human Resources Department, Barbados National Energy Company Limited, Woodbourne, St. Philip or emailed to humanresources@bnecl.com.bb with the subject line “Career Opportunity – Senior ICT Officer – Cybersecurity, Governance and Compliance” no later than Friday, July 31 2026.
Unsuitable applications will not be acknowledged
