About this role
Your main responsibilities will include:
- Provide leadership, direction, and advocacy to effectively manage the cybersecurity program.
- Develop and implement the agreed cybersecurity strategy in alignment with the business and IT strategy.
- Oversee staff, infrastructure, policy enforcement, and/or other resources.
- Drive the development of policies & standards and advocate for change that will support new initiatives or required changes and enhancements.
- Apply knowledge of risk assessment data of identified threats to decision-making processes.
- Acquire and manage the necessary resources, including third party security service providers, to support security goals, and reduce overall organizational risk.
- Advise senior management on risk levels and security posture.
- Communicate the value of security throughout all levels of the organization's stakeholders.
- Monitor threats, conduct investigations, support inquiries, and take preventive measures to improve business resilience.
- Develop and provide security guidance for new and existing systems,
- applications, and services; this includes weighing business needs, internal governance standards, and third-party compliance requirements.
- Partner with subsidiary IT teams to establish and track regional and global priorities for security initiatives.
- Provide regular reporting on security initiatives to the Head of Group IT and senior management.
- Provide leadership regarding security for assets and data, both on-premises and cloud-based.
- Evaluate emerging technologies and product categories to determine where they fill gaps, overlap with existing solutions, or extend capabilities.
- Implement and maintain security systems, applications, and services that provide detection, preventions, containment and deterrence mechanisms to protect corporate data.
- Lead the selection, testing, and deployment of new security solutions.
- Document security requirements by evaluating business needs, internal governance standards, and third-party & customer compliance requirements.
- Manage relationships with existing and future managed security service providers (MSSPs) that contribute to the portfolio of security services.
- Manage and coordinate response to security incidents.
- Facilitate compliance with audit, legal, regulatory, and customer contract requirements.
- Analyse and evaluate security operations to identify risks or opportunities for improvement.
Your profile:
- The position requires a Bachelor's degree and at least fifteen (15) years of related experience with a minimum of six (6) years of technical experience in one or
- more of the following: computer and network security, cloud-based security
- architecture, vulnerability testing, intrusion detection/prevention, security
- monitoring and event correlation, or computer forensic analysis.
- Relevant Information Security certifications (ex. CISSP, CCSP, GIAC, MCSE, CEH, CHFI, CISA, CISM, CRISC, etc.)
- Highly-developed communications skills (written/verbal) and interpersonal savvy
- Results/action-orientation; project management skills.
- Organizational and political agility; developed negotiation and influence skills.
- Unquestionable personal code of ethics, integrity, diversity and trust.
- Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment.
- Prior experience working in a global, decentralized organization.
- Extensive knowledge of cybersecurity principles.
- Extensive knowledge of cyber threats and vulnerabilities.
- Skill in de-conflicting cyber operations and activities.