This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
TUI Group is the world’s number one integrated tourism business. The Security Domain is a global team within TUI technology responsible for leading Information Security risk management across TUI. We are a multi-disciplinary team of experts across Architecture, Engineering, DevOps and Agile Delivery providing services across the UK, Ireland, Sweden, Norway, Denmark, Finland, Germany, Belgium and The Netherlands. We are looking for a talented and dedicated security leader to join the Governance, Risk and Compliance (GRC) team which supports the Group CISO in their responsibility to ensure information security risks are managed in alignment to our business goals across TUI Group. Information Security Officer is a senior leadership role (a member of the GRC Leadership Team), responsible for overseeing and supporting the application of TUI’s Information Security management framework across the Group. Providing leadership, governance and a risk-based approach in managing security within specific areas of our business. You will partner with our business and technology leaders to deliver visibility and effective management of Information Security.
Job Responsibility:
Promote and inspire a security first culture at TUI
Direct the development, implementation, delivery and support of an enterprise Information Security strategy aligned to the strategic requirements of the business
Lead the provision of Information Security resources expertise, guidance and systems necessary to execute strategic and operational plans across all of the organisation’s information systems
Ensure that each Domain is motivated and empowered to deliver the prioritised roadmap
Protect the TUI brand and its customers
Detect and respond to incidents, strengthen our defences, reduce the attack surface and secure our behaviours
Drive adoption of and adherence to security policies, standards and controls through the provision of expert advice and guidance
Protect our most critical assets and ensure appropriate assurance and rigorous testing is in place
Ensure security incidents are managed effectively through engagement with the security operations team, and that lessons learned and audit findings are remediated
Protect the integrity, availability, authenticity, non-repudiation and confidentiality of information and data in storage and in transit
Manage risk in a pragmatic and cost-effective manner to ensure stakeholder confidence
Report on the overall effectiveness of the security programme on each Domain against defined key performance indicators and drive continuous improvement
Build strong working relationships, explain and present complex ideas to audiences at all levels in a persuasive and convincing manner
Instil secure ways of working and influence others to do the right thing to Protect our Smile
Lead workstreams focussed on the development of the GRC team from a people, process and tooling perspective
Requirements:
An experienced authentic leader with a good understanding of technology and managing Information Security risks in the enterprise
Passionate about Information Security, delivering business value and driving continuous improvement
Strong people leadership skills and experience in building a positive enabling security culture based on trust, quality and pragmatic risk management
Great communicator and influencer comfortable working across hierarchical, organisational, cultural and market boundaries
Experience of managing teams, mentoring and developing security talent from different cultural backgrounds
Professionally qualified holding a recognised security accreditation (CISSP/CISM/CISA etc.,) or equivalent experience with demonstrable Continuous Professional Development
Maintain a good understanding of latest security threats and the mitigating strategies
Ability to provide advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards
Experience of the implementation, operation and maintenance of an Information Security Management framework such as ISO27001 or NIST CSF
Good understanding of integrating security into software or product development lifecycle and cloud security
Experience of securing Amazon Web Services workloads is desirable
Certification in cloud security or architecture a nice-to-have
Good understanding of the international regulatory context, particularly data privacy
Good understanding of technology standards and control frameworks such as CIS, NIST, PCI, OWASP, ITIL and COBIT
Adept at articulating IT security and technical issues to technical and non-technical audiences in a clear and actionable manner
Experienced at gaining commitment at business unit board level
Strong commercial acumen when taking actions or making decisions
Open minded, inquisitive, life-long learner
Comfortable with ambiguity, highly autonomous
Nice to have:
Certification in cloud security or architecture
What we offer:
Attractive remuneration
Bonus opportunity
Exclusive travel perks & discounts
Extensive health & wellbeing support
Flexible working
Opportunities to upskill, reskill and grow your career
Access the TUI Tech Learning Hub
Participate in tech communities and collaborate on global projects and teams
Get involved with local charity and sustainability initiatives like the TUI Care Foundation and the Sustainable Tech Community
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.