Information Security officer
Role details
Job location
Tech stack
Job description
The RISO supports the divisional CISO and is responsible for ensuring all information governance risks are appropriately managed and monitored in specific DGFF regions.
This consists of implementing the DHL policies, processes, standards and compliance models and of applying effective information security solutions by finding the right balance between risk protections and providing benefits for the company.
Even if the focus is on one specific region, in the global role reporting to the divisional CISO, the RISO can work on topics impacting multiple DGFF regions, on divisional strategic information security related projects and supports x-divisional projects and initiatives.
To have a dedicated entry point into the region the RISO is responsible for; they will have a dotted reporting line to the Hillebrand Gori IT Director.
What will you do?
-
Being responsible for the management of, and contributing to the Information Security Management System of Hillebrand Gori (based on ISMS of DGFF).
-
Derive, plan and communicate the regional information security strategy based on the DGFF Divisional Information Security strategy, work with the local IT teams on their implementation.
-
Implement on regional level the DHL policies, processes, standards and compliance models required to meet legal and regulatory requirements, protect the DGFF customer data, and protect the brand and reputation of DGFF and DHL.
-
Provide active leadership through subject matter expertise and consultancy on Information Security.
-
Be an ambassador of Information Security to external parties, suppliers, customers and across the industry.
-
Lead and coordinate the development of global IT security strategy with the process, data, application and technology leads in the relevant business and IT communities.
-
Monitor and report compliance to DHL Information Security related Standards.
-
Develop a roadmap, in conjunction with the relevant IT systems owners, for bringing existing IT systems in line with the IT security standards.
-
Provide awareness, consulting and education to both regional business and IT communities on the importance of IT security.
-
Coordinate regional IT security communications to regional management and staff ensuring appropriate visibility to existing and new risks and appropriate mitigation actions and plans.
-
Where requested, work with business and customer facing IT teams to present global Division IT Security strategy to existing and / or new major customer and supplier accounts.
-
Represent DGFF in x-divisional projects and working groups.
-
Manage regional information security incidents.
-
Preparation, execution, and follow-up of internal and external audits conducted in the region with accountable product and topic owners.
-
Contribute to the identification and mitigation of IT and information security risks.
-
Support and improve IT continuity and resilience capabilities.
-
Support DGFF Data Protection Officer and country Data Protection Official in the region with assessment and Implementation of Information Security related Data Protection controls.
-
May manage or supervise some -professional employees, * a fun place to work, with room for recreation; weekly and monthly drinks, quarterly company meet-ups, regular company festivities
Requirements
-
Project management skills
-
Strong written and communications skills
-
Sound Interpersonal communications
-
Sound analytic and reasoning skills
-
Problem solving skills
-
Broad IT service / technical understanding
-
Sound understanding of concepts, processes, and compliance models related to information security
-
Understanding the concepts of business continuity management
-
Cultural Awareness
-
Strong diplomacy and negotiating skills
-
Education:
-
Educated to degree level or equivalent (preferable in Cybersecurity, Computer Science, or Information Technology).
-
Candidates with a formal information security accreditation, e.g. CISSP, CISM, CISA, ISO 27001 Lead Auditor, are preferred.
-
Experience
-
5 years working experience in an IT role (IT Infrastructure, Application development, IT Security)
-
2 years minimum in Information Security or related role
-
1 year's minimum working within multinational - multicultural organization
Benefits & conditions
Pulled from the full job description
- Pension plan
- Commuter assistance
- Flexible schedule, Are you looking for a role where you can apply deep expertise and deliver direct business value? Then we'd like to meet you.
What can you expect from us?
-
A salary tailored to your qualities and experience
-
A contract for 40 hours
-
Reimbursement for travel expenses, work from home allowance and internet allowance
-
Pension scheme with BeFrank
-
Flexible working hours and possibility to work from home
-
Personal growth and challenging work with endless possibilities to realize your ambitions in an international environment