CrawlJobs Logo

Security Strategy and Risk Management Head of Department

United States, Irvine 181240.00 - 259160.00 USD / Year · Job Posted December 09, 2025
Apply Position
Job Link Share

Job Description

The Security Strategy and Risk Management Head of Department is a senior leadership role accountable for driving the unified governance, risk, compliance, strategy, and planning disciplines that underpin the Information Security program. This leader integrates both Integrated Risk Management (IRM) and Security Strategy & Planning (SS&P) functions into a cohesive organizational capability, ensuring the security program is well-governed, risk-informed, strategically aligned, and operationally effective.

Job Responsibility

  • Lead enterprise-wide risk assessment, risk issue management, and risk exception management
  • Maintain and enhance risk management frameworks aligned with industry best practices
  • Deliver insightful, data-driven risk reporting to senior leadership
  • Oversee the Information Security compliance and control assurance program
  • Lead coordination of internal and external audits, assessments, and certification processes
  • Lead the Third-Party Risk Management (TPRM) program
  • Oversee creation, governance, maintenance, and communication of Information Security policies, standards, and procedures
  • Direct the Information Security Training and Awareness program
  • Partner with the CISO to define and maintain the Information Security strategic roadmap
  • Lead budget planning, forecasting, tracking, and optimization for the full Information Security organization
  • Oversee resource and capacity planning across global security teams
  • Develop and maintain dashboards and reporting structures for Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and OKRs
  • Build, lead, and mentor a team across IRM, strategy, and planning functions

Requirements

  • 15–20 years of progressive experience across Information Security, GRC/Risk Management, customer/vendor security management and/or strategic operations
  • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration or a related discipline
  • Excellent stakeholder management, communication, and leadership skills
  • Demonstrated experience working across multi-disciplinary teams to achieve common objectives
  • Proficient in English for effective communication and coordination

Nice to have

  • Masters degree in Cybersecurity, Risk Management or Business Administration is preferred
  • Industry-recognized credentials such as PMP, PRINCE2, CISA, CISM, or CISSP are highly desirable
  • Familiarity with ISO 27001, NIST CSF, SOC2 Type II or similar security and risk management frameworks is an advantage
  • Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication
  • Background in cybersecurity consulting or advisory services, particularly in risk management, is a plus

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Security Strategy and Risk Management Head of Department

8 matching positions

Cyber Security Defense Head of Department

The Cyber Security Defense Head of Department (HOD) will lead and mature our org...
Location
Location
United States , Irvine
Salary
Salary:
181240.00 - 259160.00 USD / Year
haeaus.com Logo
Hyundai AutoEver America
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 15–20 years of progressive experience across the various cyber defense disciplines (SOC, Incident Response, Red/Blue teams, or similar defensive/offensive functions)
  • Proven experience leading cyber defense teams
  • Demonstrated ability to hire, mentor, and lead high-performing technical teams
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related discipline
  • Strong knowledge of threat detection, incident response, adversary tactics (MITRE ATT&CK), vulnerability management, and secure software development
  • Excellent incident management, communication, and executive reporting skills
  • Proficient in English for effective communication and coordination
  • In the absence of IR team members, utilize a flexible work schedule to facilitate the security incident response process for high/critical incidents
Job Responsibility
Job Responsibility
  • Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements and the evolving threat landscapes
  • Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, AppSec, Red/Blue Teaming, and Adversary Simulation
  • Serve as a senior advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats
  • Oversee 24x7 SOC operations, ensuring effective monitoring, detection, and response to security events, across levels 1-3
  • Drive continuous enhancement of detection engineering, threat hunting, and security analytics
  • Implement best-in-class security tooling, automation, and operational processes
  • Lead internal Red Team and offensive security capabilities, including penetration testing
  • Define testing methodologies, operational rules of engagement, and reporting standards
  • Translate offensive findings into actionable improvements for defensive teams and architecture
  • Oversee the Incident Response program, ensuring rapid and effective handling of security incidents
  • Fulltime
Read More
Arrow Right

Head of Enterprise Risk Management

Job Title: Head of Enterprise Risk Management (9 month FTC). Division: Risk and ...
Location
Location
United Kingdom , London
Salary
Salary:
Not provided
socialvalueportal.com Logo
Social Value Portal Ltd
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in Risk Management, Finance, Economics, Actuarial Science, or a related discipline
  • and/ or Professional qualifications in risk or insurance (IRM Diploma, CII Advanced Diploma)
  • Excellent management skills with the ability to influence and manage a team of professionals
  • Accomplished relationship manager
  • Readily able to influence and negotiate at senior levels within the business
  • Ability to manage time, meet deadlines, and prioritise
  • Motivational skills, team worker as well as able to work on own initiative
  • Ability to work under pressure and to tight deadlines
  • Change management skills – have a track record for designing and implementing robust change management to review and improve existing practices and procedures
  • General commercial and financial knowledge
Job Responsibility
Job Responsibility
  • Implement, maintain, and raise awareness of the Enterprise Risk Framework, including: Corporate Risk Profile
  • Risk Appetite
  • Risk Taxonomy
  • Control Environment
  • Key Risk Indicators
  • and Governance
  • Develop, implement, and maintain effective enterprise, emerging and operational risk frameworks across the group
  • Develop, implement and maintain effective 2nd Line control assurance methodologies, plans and processes
  • Lead the ongoing development of our GRC system, supporting processes and enhancements in the control environment
  • Maintain risk policies and standards, develop suitable KRIs and other relevant risk metrics
  • Fulltime
Read More
Arrow Right

Cyber Defense Head of Department

The Cyber Security Defense Head of Department (HOD) will lead and mature our org...
Location
Location
United States , Irvine
Salary
Salary:
181240.00 - 259160.00 USD / Year
haeaus.com Logo
Hyundai AutoEver America
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 15–20 years of progressive experience across the various cyber defense disciplines (SOC, Incident Response, Red/Blue teams, or similar defensive/offensive functions)
  • Proven experience leading cyber defense teams
  • Demonstrated ability to hire, mentor, and lead high-performing technical teams
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or a related discipline
  • Strong knowledge of threat detection, incident response, adversary tactics (MITRE ATT&CK), vulnerability management, and secure software development
  • Excellent incident management, communication, and executive reporting skills
  • Proficient in English for effective communication and coordination
  • In the absence of IR team members, utilize a flexible work schedule to facilitate the security incident response process for high/critical incidents
Job Responsibility
Job Responsibility
  • Develop and execute the Cyber Defense strategy aligned with organizational goals, customer requirements and the evolving threat landscapes
  • Establish frameworks, processes, and KPIs for SOC, Incident Response, TVM, AppSec, Red/Blue Teaming, and Adversary Simulation
  • Serve as a senior advisor to the CISO and executive leadership on cyber risks, readiness, and emerging threats
  • Oversee 24x7 SOC operations, ensuring effective monitoring, detection, and response to security events, across levels 1-3
  • Drive continuous enhancement of detection engineering, threat hunting, and security analytics
  • Implement best-in-class security tooling, automation, and operational processes
  • Lead internal Red Team and offensive security capabilities, including penetration testing
  • Define testing methodologies, operational rules of engagement, and reporting standards
  • Translate offensive findings into actionable improvements for defensive teams and architecture
  • Oversee the Incident Response program, ensuring rapid and effective handling of security incidents
  • Fulltime
Read More
Arrow Right

Head of IT & Security

As Head of IT & Security at Dexory, you will own and drive the strategy, executi...
Location
Location
Wallingford
Salary
Salary:
Not provided
dexory.com Logo
Dexory Using
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience in a senior IT leadership role (Head of IT, IT Director or equivalent) in a high-growth mid-sized technology company (100–500 employees) or scaling organisation
  • Strong background managing IT infrastructure for a high-technology company (servers, workstations, network, cloud, endpoints), service delivery, onboarding/off-boarding, vendor management and IT budgeting
  • Solid experience in IT security and compliance: risk assessment, incident management, identity & access management, policy formulation, and experience with relevant standards (e.g. ISO 27001, SOC1/SOC2, GDPR)
  • Excellent stakeholder management and cross-functional collaboration skills – able to translate business needs into IT/security solutions and influence senior leadership
  • Strong team leadership and people development experience: building and managing teams (internal and via partners) across IT and security disciplines
  • Excellent verbal and written communication skills
  • ability to present to senior management, articulate trade-offs and make strategic decisions
  • A proactive, results-driven mindset, comfortable in a fast-paced, evolving environment.
Job Responsibility
Job Responsibility
  • Define and execute the IT strategy in alignment with business objectives: infrastructure (on-premises, cloud, hybrid), end-user computing, collaboration tools, service desk and lifecycle management
  • Define and own the IT security & compliance strategy: policies, controls, risk frameworks, audits, vendor assessment, incident response, identity & access management and data governance
  • Manage the IT / Security budget and vendor contracts, ensuring cost-effectiveness and service delivery for employees across multiple teams and countries
  • Lead the IT onboarding and off-boarding processes: ensure every new team member is provisioned with the right systems, access rights, collaboration tools, security training, and that existing team members are properly de-provisioned
  • Ensure the operational stability of the IT estate: network, servers, endpoints, cloud services, backups, disaster recovery, patching, monitoring – while maintaining high service levels across the business
  • Collaborate cross-functionally with Heads of Departments (Operations, Engineering, HR, Finance, Product) to ensure their systems and workflows are supported, secure and scalable
  • Build, lead and mentor the IT & security team and managed service partners – drive a culture of service, reliability, security awareness and proactive innovation
  • Monitor and report on key metrics/KPIs: uptime, service desk performance, security incident rate, audit/compliance status, cost per user, vendor performance
  • Lead incident response and business continuity planning: coordinate investigation of security incidents, implement corrective actions and ensure resilience of systems and processes
  • Stay up-to-date with current and emerging technologies, threats and regulatory requirements relevant to our sector and growth stage
What we offer
What we offer
  • Private healthcare via Bupa with 24/7 medical helpline
  • Life insurance
  • Income protection
  • Pension: 4+% employee with option to opt into salary exchange, 5% employer
  • Employee Assistance Programme - mental wellbeing, financial and legal advice/support
  • 25 holidays per year
  • Full meals onsite in Wallingford
  • Fun team events on and offsite, snacks of all kinds in the office
Read More
Arrow Right

Head of Enterprise Architecture

Define and maintain the enterprise architecture strategy and roadmap to support ...
Location
Location
Egypt , New Cairo
Salary
Salary:
Not provided
ethicshr.com Logo
Ethics HR
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s/Master’s degree in Computer Science, Information Technology, Enterprise Architecture, or related field from a reputable university
  • Minimum of 10 years of experience in enterprise architecture, IT strategy, or technology leadership within banking or financial services with 3 years in a leadership role managing teams or departments
  • Desirable Certification / TOGAF 10 & COBIT 2019
  • Strong understanding of CBE regulations, IT governance, and risk management frameworks
  • Expertise in cloud platforms, core banking systems, digital banking technologies, and integration frameworks
  • Excellent oral and written communication skills
  • Strong stakeholder management, strategic thinking, and analytical skills
  • Ability to lead complex transformation initiatives in a fast-paced, start-up environment
Job Responsibility
Job Responsibility
  • Define and maintain the enterprise architecture strategy and roadmap to support business objectives and digital transformation initiatives
  • Design and enforce technology standards, frameworks, and guidelines across applications, infrastructure, and data
  • Collaborate with business, technology, and risk teams to ensure solutions are aligned with regulatory, security, and operational requirements
  • Evaluate and select technology platforms, tools, and solutions to optimize scalability, security, and efficiency
  • Review and approve architectural designs, ensuring consistency with enterprise standards and best practices
  • Provide governance over project architecture to ensure adherence to EA principles and minimize technical debt
  • Conduct impact assessments for new technology initiatives and provide recommendations to senior leadership
  • Develop and maintain documentation of architectural artifacts, reference models, and guidelines
  • Mentor and lead the EA team, fostering a culture of innovation and compliance
Read More
Arrow Right

Head of IT

We're looking for Head of IT to join our Binariks team. As Head of IT, you will ...
Location
Location
Ukraine , Lviv
Salary
Salary:
Not provided
binariks.com Logo
Binariks
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience in IT leadership, IT management, or senior system administration roles
  • Strong communication and organizational skills
  • Strong self-management and ability to prioritize and delegate tasks effectively
  • Hands-on experience with Windows, macOS, and Linux environments
  • Experience with monitoring and observability systems such as Zabbix, Wazuh and Grafana
  • Strong networking knowledge and experience with infrastructure vendors such as Fortinet and Aruba Networks
  • Experience supporting corporate users and office infrastructure
  • Experience working with IT vendors and procurement processes
  • Experience with MDM and endpoint management systems such as ManageEngine Endpoint Central
  • Experience with BitLocker, FileVault, endpoint protection, firewall management and backup systems
Job Responsibility
Job Responsibility
  • Develop and implement the IT strategy aligned with business and engineering needs
  • Define department goals, priorities, and technology roadmaps
  • Ensure high availability, reliability, and security of IT systems and services
  • Oversee office IT infrastructure, networks, end-user devices, cloud services, and internal systems
  • Maintain and improve IT processes, documentation, and operational standards
  • Plan and manage IT budgets, licenses, and technology investments
  • Manage system administrators, support engineers, and infrastructure specialists
  • Organize task planning, delegation, prioritization, and performance evaluation
  • Collaborate closely with engineering, HR, finance, legal, and business teams
  • Manage corporate IT infrastructure, including networking, monitoring, endpoint management, and office systems
What we offer
What we offer
  • 18 days of paid annual leave
  • 10 sick leaves
  • Additional days off for special occasions
  • Medical Care
  • Health check-up
  • Play Room
  • IT Cluster membership
  • Business Trip
  • Tech Talks
  • Training & Conferences
  • Fulltime
Read More
Arrow Right

Head of IT

We're seeking a dynamic Head of IT to join our team. As Head of IT, you will lea...
Location
Location
Ukraine , Lviv
Salary
Salary:
Not provided
binariks.com Logo
Binariks
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Proven experience in IT leadership, IT management, or senior system administration roles
  • Strong communication and organizational skills
  • Experience managing or mentoring technical teams
  • Strong self-management and ability to prioritize and delegate tasks effectively
  • Hands-on experience with Windows, macOS, and Linux environments
  • Experience with monitoring and observability systems such as: Zabbix
  • Wazuh
  • Grafana
  • Strong networking knowledge and experience with infrastructure vendors such as: Fortinet
  • Aruba Networks
Job Responsibility
Job Responsibility
  • IT Strategy & Operations: Develop and implement the IT strategy aligned with business and engineering needs
  • Define department goals, priorities, and technology roadmaps
  • Ensure high availability, reliability, and security of IT systems and services
  • Oversee office IT infrastructure, networks, end-user devices, cloud services, and internal systems
  • Maintain and improve IT processes, documentation, and operational standards
  • Plan and manage IT budgets, licenses, and technology investments
  • Team Leadership & Management: Lead, mentor, and develop the IT team
  • Manage system administrators, support engineers, and infrastructure specialists
  • Organize task planning, delegation, prioritization, and performance evaluation
  • Support team growth, motivation, and knowledge sharing
What we offer
What we offer
  • 18 days of paid annual leave
  • 10 sick leaves
  • Additional days off for special occasions
  • Medical Care
  • Health check-up
  • Play Room
  • IT Cluster membership
  • Business Trip
  • Tech Talks
  • Training & Conferences
  • Fulltime
Read More
Arrow Right

Head of Digital Architecture & AI Systems

Lead the definition, governance, and evolution of enterprise digital architectur...
Location
Location
Salary
Salary:
Not provided
hiremoters.ai Logo
HiRemoters
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Bachelor’s degree in communications, public policy, international relations, marketing, digital strategy, or a related discipline
  • 10+ years experience in enterprise architecture, digital transformation, or large-scale systems design roles
  • Strong expertise in enterprise architecture frameworks (TOGAF, Zachman, or equivalent)
  • Advanced knowledge of Microsoft ecosystem including Dynamics 365 (CRM and FinOps), Azure cloud services, Power Platform (PowerBI, Power Automate, Power Apps)
  • Experience with data platforms and data architecture (Azure Data Factory, Synapse, SQL databases, data lakes, ETL/ELT pipelines)
  • Strong understanding of API-based integration architectures, middleware platforms, and system interoperability principles
  • Experience with AI/ML environments and tools (Azure AI, OpenAI integrations, machine learning workflows, analytics platforms)
  • Knowledge of cybersecurity architecture principles including identity and access management, encryption, and secure cloud architectures
  • Understanding of enterprise reporting environments and business intelligence platforms
  • Experience with system design for compliance-driven environments (data protection, audit readiness, financial systems)
Job Responsibility
Job Responsibility
  • Lead the definition, governance, and evolution of enterprise digital architecture, ensuring that systems, platforms, data environments, integrations, and AI capabilities support the Foundation’s mission, programs, beneficiary lifecycle, grants ecosystem, and partner engagements
  • Establish and maintain a scalable, secure, and integrated technology foundation that enables operational excellence, regulatory compliance (including PDP and financial compliance), and data-driven decision-making across the organization
  • Own enterprise architecture governance, technical standards, and system design principles across the company
  • Define integration standards, API governance, and platform interoperability frameworks
  • Ensure that all system developments align with the digital transformation roadmap and long-term institutional needs
  • Provide technical oversight for system changes, upgrades, and digital initiatives across departments
  • Embed privacy-by-design and compliance-by-design principles into system architecture
  • Ensure alignment of systems and data structures with UAE PDP Law requirements and data protection best practices
  • Support e-invoicing readiness by ensuring ERP architecture can support regulatory compliance and traceability
  • Collaborate with Legal and Cybersecurity to ensure secure, compliant handling of beneficiary, partner, and grant-related data
What we offer
What we offer
  • Flexible and Remote Working
  • Career Growth
  • Performance Recognition
  • Health and Fitness Benefits
  • Extra Paid Annual Leave
  • Special Birthday Perk
  • Fulltime
Read More
Arrow Right