This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Director of Information Security at NTT DATA will lead the organization's information security program, ensuring compliance with security regulations and managing risks. The ideal candidate will have significant experience in risk management and information security, along with strong leadership and communication skills. A bachelor's degree in a related field is preferred, and relevant certifications such as CISSP and CISM are required. This role offers an exciting opportunity to shape the security strategy of a leading technology services provider.
Job Responsibility:
Contributes towards the development and drives the implementation of an organization-wide information security strategy aligned with the NTT's business objectives
Contributes towards establishing and maintaining information security policies, procedures, standards, and guidelines that comply with industry best practices and regulatory requirements
Oversees the identification, assessment and management of information security risks across the organization, including data, systems, networks, and third-party relationships
Promotes a culture of security awareness among employees through training, education, and regular communication
Oversees the development and execution of incident response plans to effectively address and mitigate security incidents
Ensures NTT's compliance with relevant security regulations, laws, and industry standards
Assesses and selects appropriate security technologies and solutions to protect NTT's digital assets
Implements security monitoring tools and systems to detect and respond to security threats and providing regular reports to executive leadership and stakeholders
Stays informed about emerging security threats and industry trends to continuously enhance the organization's security posture
Evaluates security risks associated with third-party vendors and service providers and implementing risk mitigation strategies
Effectively communicates security incidents, responses, and mitigation efforts to relevant stakeholders
Coordinates and manages internal and external security audits and assessments
Provides guidance and leadership to the information security team, ensuring adherence to security policies and procedures
Requirements:
Significant knowledge of security frameworks and standards (for example, ISO 27001, NIST, CIS, etc.)
Significant knowledge about PCI, HIPAA, NIST, GLBA and SOX compliance assessments
Significant understanding of security technologies, tools, and best practices
Excellent communication and presentation skills with the ability to effectively convey complex security concepts to non-technical stakeholders
Significant leadership and team management skills to lead and motivate a diverse security team
Strategic thinking and problem-solving abilities with a focus on delivering results
Significant business acumen and the ability to align security objectives with overall business objectives
Bachelor's degree or equivalent in business administration or a technology-related field such computer science or information technology or related preferred
An advanced degree such as an MBA or Masters in an IT related field with a security focus preferred
Related Cybersecurity, risk management and data privacy certifications preferred such as CompTIA Security+, CISSP, CISM, CISA, and/or CEH
Significant experience in a combination of risk management, information security and IT roles in a global organization
Proven track record of successfully developing and implementing enterprise-wide information security strategies and initiatives
Significant experience with contract and vendor negotiations and management
Significant experience in Agile (scaled) software development or other best in class development practices
Significant experience with Cloud computing / Elastic computing across virtualized environments
Significant experience in risk management, compliance and regulatory requirements related to information security
Significant working with national and international regulatory compliance frameworks such as NIST, ISO, SOX, EU GDPR, CCPA and PCI DSS
Significant experience and working knowledge of the following areas of technical expertise - information policy formulation, information security management, business risk management, IT risk assessment and management, IT continuity management, IT governance formulation, and organizational change management, IT financial management and IT audit