Strategic Business Unit Security Officer
IT Services MNC, headquartered in Canada is looking for a Director & Head for the Security & Strategic Business Unit.
Strategic Business Unit Security Officer (SBU SO)
Position Description :
The Strategic Business Unit Security Officer (SBU SO) is a Security leadership position with the authority delegated from the SBU President, to manage the Security Program for the Strategic Business Unit (SBU). The SBU SO is the Security point of contact (POC) to support the SBU in responding to all client security related matters.
The SBUSO manages the SBU Security Posture :
- Implementing the Enterprise Security Management Framework (ESMF) within the SBU:
- Assessing and mitigating SBU security risks;
- Ensuring that CLIENT security policies & standards are applied to internal and shared (multi-client) systems;
- Approving & managing security exception requests;
- Implementing security awareness and on-going communication;
- Developing, implementing and testing Business Continuity plans, including Crisis Management plans;
- (Where applicable) Maintain compliance to ISO 27001 certification and ensuring its alignment to ESMF.
- Central Point of Contact for Security within the SBU:
- Being the POC for CLIENT security in communicating and supporting client proposals and audits within the BU, in alignment with CLIENT security directive.
- Representing the voice of the SBU to contribute to the evolution of ESMF;
- Acting as an extended member of the Enterprise Security team to provide guidance and advice to SBU management and Members with regard to the CLIENT security program (scope covers Information Security, Privacy, Physical, BCP, IP protection & People Security);
- Managing Security Incidents and Crisis Management:
- Overseeing the management of the security incidents (including client incidents as needed): escalation to management, risk based incident management;
- Establishing SBU/BU crisis management capabilities.
- Reporting on Security Metrics:
- SBU security posture / dashboard: risk level, policy compliance report, incident reports.
The SBU SO's direct reports include the Business Unit Security Officers (BU SOs).
Primary Responsibilities (direct and team) :
- Primary contact for security with clients for all security matters.
- Manage security risks at the SBU level: consistency, tracking and management reporting.
- Lead major incidents and crisis, escalation to SBU management.
- Enforce SBU adherence to CLIENT security baseline rules. Scope includes: Information security, Privacy, Physical, BCP, IP protection & people security.
- Leading ISO 27001 certification / re-certification within the SBU (if applicable).
- On-going security evaluation and certification for the SBU.
- Leading the implementation of security controls to mitigate risks for the SBU.
- On-going security awareness / training (educating members), BU SO coach, mentoring and training.
- Manage BU SOs activities, deliverables.
- Oversee and manage BU SOs performance.
Experience and Education :
- Minimum of ten (15) years of directly related IT experience with at least five (8-10) years of information security experience.
- Experience engaging with clients at all levels to understand needs and present appropriate solutions.
- Must be able to communicate information security-related concepts to a broad range of technical and non-technical staff.
- Must have experience in large scale, enterprise-wide security intrusion monitoring, detection, and incident handling/remediation activities.
- Good understanding of the business in the SBU.
- Good ability to communicate on management level as well as with members, to get the security message across.
- Good understanding of security requirements from clients in the geography.
- Good ability to communicate with clients, to demonstrate CLIENT commitment to security.
- Team leading/management skills/experience to support BU SOs and lead the security work in Nordics
- Ability to apply business thinking on security.
- Good knowledge of ESMF and managing security risks.
- Good understanding of security technologies to support the line organization.
Didn’t find the job appropriate? Report this Job