This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security Strategy and Risk Management Head of Department is a senior leadership role accountable for driving the unified governance, risk, compliance, strategy, and planning disciplines that underpin the Information Security program. This leader integrates both Integrated Risk Management (IRM) and Security Strategy & Planning (SS&P) functions into a cohesive organizational capability, ensuring the security program is well-governed, risk-informed, strategically aligned, and operationally effective.
Job Responsibility:
Lead enterprise-wide risk assessment, risk issue management, and risk exception management
Maintain and enhance risk management frameworks aligned with industry best practices
Deliver insightful, data-driven risk reporting to senior leadership
Oversee the Information Security compliance and control assurance program
Lead coordination of internal and external audits, assessments, and certification processes
Lead the Third-Party Risk Management (TPRM) program
Oversee creation, governance, maintenance, and communication of Information Security policies, standards, and procedures
Direct the Information Security Training and Awareness program
Partner with the CISO to define and maintain the Information Security strategic roadmap
Lead budget planning, forecasting, tracking, and optimization for the full Information Security organization
Oversee resource and capacity planning across global security teams
Develop and maintain dashboards and reporting structures for Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and OKRs
Build, lead, and mentor a team across IRM, strategy, and planning functions
Requirements:
15–20 years of progressive experience across Information Security, GRC/Risk Management, customer/vendor security management and/or strategic operations
Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, Business Administration or a related discipline
Excellent stakeholder management, communication, and leadership skills
Demonstrated experience working across multi-disciplinary teams to achieve common objectives
Proficient in English for effective communication and coordination
Nice to have:
Masters degree in Cybersecurity, Risk Management or Business Administration is preferred
Industry-recognized credentials such as PMP, PRINCE2, CISA, CISM, or CISSP are highly desirable
Familiarity with ISO 27001, NIST CSF, SOC2 Type II or similar security and risk management frameworks is an advantage
Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication
Background in cybersecurity consulting or advisory services, particularly in risk management, is a plus
Welcome to CrawlJobs.com – Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.