Additionally, the ISO will manage projects related to the examination and implementation of new information security products and characterize information security solutions for related projects. The ISO will also advise on compliance with privacy and cyber protection laws and regulations, conduct information security and privacy protection surveys, and oversee ISO 27001 compliance, focusing on all aspects of cybersecurity within Application Security (AppSec), Infrastructure Security (DevSec), Governance, Risk, and Compliance (GRC), Security Information and Event Management (SIEM)/Security Operations Center (SOC), incident response, and IT security.
Responsibilities
Develop, update, and maintain a cybersecurity strategy.
Manage a risk-based cybersecurity program to secure corporate IP, technology, information, computer systems, networks, and data.
Provide guidance on proposed cybersecurity best practices to different business functions.
Develop comprehensive cybersecurity guidance, processes, and procedures based on industry standards.
Stay informed on trends and issues in the security industry, including current and emerging technologies and regulatory and compliance issues.
Advise, counsel, and educate executive and management teams on the importance of cybersecurity.
Requirements: 5+ years of experience as an ISO, with a focus on reviewing and recommending security business solutions (GRC).
Experience in a large global company.
Certifications in one or more of the following areas: CISO, CISM, GISO, IAM, CISSP.
Demonstrated knowledge of recognized security industry standards and leading practices (e.g., SOX, ISO 27001/2/3, ISO 27018, GDPR, PCI, OWASP, NIST, DISA, CIS, etc.).
Broad knowledge of cybersecurity technologies, solutions, and tools (e.g., encryption technologies, SIEM, DLP, etc.).
Strong knowledge of cloud technologies, platforms, and services.
Broad knowledge of operational and security processes/controls (e.g., vulnerability management, patch management, configuration management, access management, etc.).
Previous experience as a system administrator and/or security administrator is an advantage.
This position is open to all candidates.