This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Reporting to Head of I&T GRC, Governance and Risk Lead will be responsible for driving information and cyber security awareness, delivering security awareness training including phishing and facilitation of cyber scenario desktop simulations across central and manufacturing site teams. You will review, manage and where required prepare responses to internal and external customer enquiries in relation to information and cyber security arrangements. You will support IT, procurement, legal, data protection and digital security and business stakeholder in relation to supplier information and cyber security due diligence and requirements. As the successful candidate you will also lead risk-based party security assurance, management, and continuous improvement activities. In addition, facilitate and coordinate IT risk management risk register, tools, process, reporting and review. You will take responsibility for managing a subset of aspects of ISO 27001 related documentation and control activities. As the I&T Governance and Risk Lead you will have the responsibility of aspects of the I&T GRC scope, delegated and assigned by the Head of I&T GRC.
Job Responsibility:
Driving information and cyber security awareness
Delivering security awareness training including phishing and facilitation of cyber scenario desktop simulations across central and manufacturing site teams
Reviewing, managing and where required preparing responses to internal and external customer enquiries in relation to information and cyber security arrangements
Supporting IT, procurement, legal, data protection and digital security and business stakeholder in relation to supplier information and cyber security due diligence and requirements
Leading risk-based party security assurance, management, and continuous improvement activities
Facilitating and coordinating IT risk management risk register, tools, process, reporting and review
Managing a subset of aspects of ISO 27001 related documentation and control activities
Managing and continuously improving I&T and Security risks processes in accordance with company risk appetite and tolerance
Engaging risk review and assurance activities across existing suppliers
Providing IT and business advice on aspects of security standards and regulations
Engaging with I&T system owners to provide training in relation to information security, cyber resilience, phishing, and facilitation of cyber scenario desktop simulations
Requirements:
Working knowledge of technology and security standards, controls and consequences across both IT and manufacturing environments in manufacturing or similar industries
Experience working with information security standards and frameworks such as and regulations such as ISO27001, NIST CSF, PCI DSS, NISD and NIS2
Proven analytical, problem-solving, planning, project delivery and supplier work packages management skills
Demonstrable experience of engaging across all levels of a company in relation to information and cyber security risks
Working towards or achieved professional certifications (ISO27001 lead, ISC2, CISM or CRISC) advantageous
Nice to have:
Working towards or achieved professional certifications (ISO27001 lead, ISC2, CISM or CRISC)