EMEA Information Security Officer - East region - Global Cybersecurity Services
Aon Sp. z o.o.
⚲ Kraków, Podgórze
Wymagania
- CISSP
- CISM
Opis stanowiska
Nasze wymagania: Broad Cybersecurity knowledge and experience of implementing and operating an effective control regime in a large, complex corporate environment. Solid knowledge and understanding of Cybersecurity domains, including: application security, vulnerability management, network and cloud security, security operations (incident management), physical security, supplier risk management and cyber awareness. Experience of effective Cyber Risk Management within a large corporate environment. Fostering strong partnerships by influencing and building effective relations with diverse stakeholders at a range of seniority, up to and including C-level. Exceptional communication skills, with the ability to communicate to a diverse range and seniority of stakeholders, including technical and non-technical audiences. Demonstrable regulatory management experience. Experience of Compliance assurance and Audit practice is desirable. Understanding and experience of delivering compliance standards, including: ISO27001, DORA, Cyber Essentials+ Mile widziane: Security certification (CISSP,CISM) is an advantage. O projekcie: The Information Security Officer (ISO) – East region will support the Eastern part of Europe Middle East and Africa (EMEA) within the EMEA Regional Security Office (RSO). Reporting directly to the EMEA Regional Security Officer, this role is key in leading the regional and solution line operational security risk level to within acceptable levels via leading remediation programs and deployment of Global Cybersecurity Services (GCS) controls. The role will act as a key contact for all matters relating to Cybersecurity and requires a broad understanding of security controls and their effective implementation within corporate environments. The role will also require good relationship leadership skills across the assigned region / sub-region to enable business adoption. As an Information Security Officer you will be accountable for service delivery to the assigned region / sub-region and solution lines. The role with need to have effective relationships with senior leadership to support the delivery of the regional / sub-regional business goals and operate an effective security risk management regime against an agreed security risk mitigation strategy. As the trusted security lead, this position requires presenting to local leaders, regulators and clients as needed. Prior experience of regulatory management is required. This is a highly visible role within Aon to be able to embed effective security controls at scale within the firm. We are looking for you to bring new insights and a dedication toward continual learning. You will stay actively engaged with business leaders, IT executives and external clients. The role requires gravitas and an ability to be influential and persuasive. Aon deeply values inclusiveness, collaboration and a "better together" approach to deliver distinctive value to colleagues and clients. Zakres obowiązków: The RSO service provides a regional / sub-regional / solution line connection to GCS to ensure they are appropriately leveraged to mitigate security risks and provides the following security services: Cybersecurity Leadership: • Provide Cybersecurity reporting to leadership committees and Boards. • Represent Cybersecurity to appropriate Regulatory bodies. • Own the Cybersecurity strategy for the assigned area, manage its delivery via leverage of GCS services and accelerate local control adoption. • Own the colleague security culture programme. • Represent the region / sub-region in the Security Incident Management process. • Remediation Management, e.g. Internal Audit findings. • Cybersecurity Compliance and Conduct management. Cybersecurity Risk Management: • Managing a Cybersecurity Risk committee to support cyber risk management. • Track remediation of Cybersecurity Audit and Compliance findings. • Review Cybersecurity Metrics and lead remediation programs within the region / sub-region. • Lead or Sponsor Cybersecurity initiatives within area of accountability • In conjunction with Data Privacy, ensure necessary security controls are in place. GCS Service Delivery Management: • Manage GCS Service delivery escalations. • Support GCS project implementation within the assigned area of accountability. • Contribute to the ‘voice of the Business’ in development of GCS service enhancements. • Cybersecurity Intake & Relationship Management • Regulatory & Compliance Assessment Support • Continuity and Disaster Recovery Support • Data Governance Support Client Support/Escalation Management: • Represent Cybersecurity on Client calls or escalations. • Provide first line security advice, guidance and Policy and Standard support to Client teams. • Support the engagement of GCS services via the correct process.