Information Security Officer

Sompo International
London, UK
6 days ago
Apply on eu.experteer.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Software as a Service Cloud Computing Cyber Security Information Security Management Software Engineering Systems Integration Software Vulnerability Management Matrix Reports Information Technology

Job description

Experteer Overview In this role you will manage and modernize Sompo’s global information security program, aligning with external and corporate requirements. You will lead a broad, multi-location security effort, influencing policy, architecture, and incident readiness. You’ll drive risk-based improvements, vulnerability management, and security communications to keep the organization secure amid evolving threats. This is a mission-driven opportunity to shape security across a large, diverse technology footprint. Pay / Benefits * Maintain and continuously improve technical security controls across systems and processes with documented designs and real-time instrumentation * Oversee vulnerability management and real-time reporting for organization-wide threat data * Operate a security alerting function that evolves with the threat landscape * Maintain tested incident response procedures capable of handling events at any scale * Engage in the software development lifecycle to align with the information security program * Establish a communications program to inform users about threats, policy changes, and security recommendations * Lead security strategy and architecture communication to non-technical and executive audiences * Coordinate with cross-functional teams and external partners to minimize security risk Tasks * 15+ years in technical, security, and risk management roles * 7+ years in a senior management role within information security * Technical familiarity with security controls for Windows, cloud, and SaaS environments * Experience integrating regulatory requirements and industry standards into procedures and designs * Ability to translate metrics into KPIs and risk quantifiers * Strong written, verbal, and interpersonal communications skills * Leadership experience managing a hybrid team (direct reports, matrix reports, contractors) * Bachelor in computer science, information security, or a related field * Recognized information security certification (CISSP, CISM, etc.) Key requirements * two medical plans with HSA * 401(k) plan with contributions * paid time off and holidays * parential leave benefits * tuition reimbursement * Employee Assistance Program

Requirements

the the information security program * Establish a communications program to inform users about threats, policy changes, and security recommendations * Lead security strategy and architecture communication to non-technical and executive audiences * Coordinate with cross-functional teams and external partners to minimize security risk Tasks * 15+ years in technical, security, and risk management roles * 7+ years in a senior management role within information security * Technical familiarity with security controls for Windows, cloud, and SaaS environments * Experience integrating regulatory requirements and industry standards into procedures and designs * Ability to translate metrics into KPIs and risk quantifiers * Strong written, verbal, and interpersonal communications skills * Leadership experience managing a hybrid team (direct reports, matrix reports, contractors) * Bachelor in computer science, information security, or a related field * Recognized information security aaaaaaaaaa and (CISSP, CISM, etc.) Key requirements * two medical plans with HSA * 401(k) plan with contributions * paid time off and holidays * parential leave benefits * tuition reimbursement * Employee Assistance Program

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all