Sr. Information Security Officer, Managing Director

State Street Corporation
Munich, Germany
Diese Stelle ist in deinem Land nicht verfügbar.

Sr. Information Security Officer, Managing DirectorState Street Bank International GmbH ('SSBI') seeks to recruit a Senior Information Security Officer, Managing Director (Sr.

ISO) to improve the overall protection of SSBI, its customers and partners from an evolving and sophisticated threat landscape.

The candidate should have a proven track record in global cyber security and as a risk leader who has experience in delivering on strategic oues with business operational quality and a focus on business needs.

The candidate should have experience in large scale cyber transformations and execution.

The SSBI Sr. ISO reports to the SSBI Chiefernance Officer and closely cooperates with the SSBI Head of IT and the wider management team. Key stakeholders include :

  • Information Security Officers
  • Business and Functional Leaders
  • Cyber Fusion Center
  • Cyber Architecture & Security Engineering
  • First Line Risk and Controls
  • 3LOD Partners

The SSBI Senior Information Security Officer (Sr. ISO) will drivepliance with GCS security controls in their business unit / region / country / functional area which they represent.

The Sr. ISO will serve as a trusted and influential information security advisor to senior-level business management in a large organization.

The SSBI Sr. ISO roles and responsibilities are defined under five domain areas with the following objectives and specific responsibilities for each domain :

Information Security program development and management

Objective : Develop and manage the information security program within the business unit to drivepliance with information security supplemental requirements and reduce risk

  • Identify senior business management and build relationship to ensure effective information securityernance is established - strategy with goals and objectives, strategic alignment, roles and responsibilities, performance measurement, oues
  • Understand context of the business unit - internal and external issues, organizational structure, organizational drivers, geography, strategy, legal and regulatory requirements
  • Develop an information security strategy aligned to the business unit strategy, defining the goal of information security, objectives and the desired state
  • Develop and maintain an information security policy, associated standards and procedures
  • Define the activities to be performed within the information security program, and assign ownership
  • Establish relevant metrics to evaluate the effectiveness of the information security program
  • Monitor and review information security program, to ensure continual development and improvement

Risk and Incident Management

Objective : Manage information security risk and incident response, from assessment through mitigation of risk, and throughout the entire lifecycle of incident management

  • Support the business unit in identifying high risk / critical processes and technology, ensuring they are inventoried, ownership is assigned and that regular reviews are carried out
  • Assess information security risk associated with high risk / critical business processes and technology, and apply information security supplemental requirements to mitigate risk
  • Integrate information security risk review into lifecycle processes such as Incident Management, ASAP, ISRMP, TPRM, BCP, SDLC, Change and Project management
  • Attend risk and technologymittees. Identifying, documenting andmunicating Information Security risks. If risk and technologymittees do not exist, work with the business unit to establish forums for discussion
  • Act as Information Security representative during regulatory and statutory engagements
  • Review and approve non-standard access for high risk access ( blocked web sites, mass storage, application access, non-standard device and non-expiring passwords, process and system IDs)
  • Participate in security incident response program representing the business area to detect and respond to incidents in a timely manner.

Post incident, provide support to the business to identify control gaps.

Measurement

Objective : Develop metrics for measuring the information security program and related activities

  • Establish and agree on appropriate reporting with senior management to give a view of the state of information security throughout the business unit
  • Identify failed business controls and provide support on remediation to drivepliance with information security supplemental requirements
  • Create development plans for all information security resources to ensure continual improvement

munication

Objective : Establish internal and externalmunication channels that support information security

  • Report on potential business impact of proposed new information security supplemental requirements, and of security risks from new business initiatives
  • Report significant changes in information security risk to appropriate level of management for review on both a periodic and an event driven basis
  • Provide regularmunication on threat intelligence relevant to the business unit, and issue guidance on supporting controls
  • Report on impact or potential impact of security incidents to senior management

Education

Objective : Maintain up to date knowledge of evolving information security threat landscape and provide information security awareness, training and education to key stakeholders

Design and develop an interactive and engaging program for information security awareness and training, which is relevant to the business unit and epasses the current threat landscape

Furthermore, the Sr. ISO (MD) is responsible for :

  • Global collaboration : Collaborate with Global Cyber Security and assigned business partner teams to ensure the business aligns plans addressing security policies and standards are enforced in their products and services
  • Team management : Create a high performing team and environment that promotes continuous growth opportunities

Education & Preferred Qualifications

The Sr. ISO (MD) should possess the following skills / experience

  • 12+ years of experience in cyber security risk and controls, a security related field or other information risk management function
  • Experience withmunicating with the European Central Bank,
  • Modern technical aptitude and experience developing and implementing large-scale innovation.
  • Interaction witherning bodies, ECB, Bafin, Bundesbank, Prüfungsverband, etc.
  • Depth with modern technology stacks - n-tier, cryptography, data science, machine learning, cloud (hybrid)
  • Project Management experience leading large and small technical teams.
  • Experience operating in regulated environment
  • CISA, CISM, CISSP or similar certification required or an agreed upon plan to achieve this certification within 1 year of hire
  • Bachelor's degree or equivalent in a relevant field

Critical Leadership Capabilities

  • Driving results
  • Strategic Thinking
  • Collaborating & Influencing
  • Change Management
  • Senior Executivemunication
  • Personnel Management
  • Project Management

Job ID R-741469

Vor 5 Stunden
Ähnliche Stellenangebote
Gesponsert
第一銀行 FirstBank
Frankfurt Rhine-Main Metropolitan Area, Germany

ISO Information Security Officer on a part-time basis. To build up a firm operation and develop a prosperous business we are looking for a qualified ISO Information Security Officer to join our team. To apply a deep understanding of industry standards relating to current data/cyber security products...

State Street Corporation
München, Bayern

Information Security Officer, Managing DirectorState Street Bank International GmbH ('SSBI') seeks to recruit a Senior Information Security Officer, Managing Director (Sr. The SSBI Senior Information Security Officer (Sr. Objective: Develop and manage the information security program within the busi...

State Street
München, Bayern

State Street Bank International GmbH (‘SSBI’) seeks to recruit a Senior Information Security Officer, Managing Director (Sr. The SSBI Senior Information Security Officer (Sr. Objective: Develop and manage the information security program within the business unit to drive compliance with information ...

Gesponsert
MODE Recruitment
München, Bayern

Chief Information Security Officer - Fully Remote. Founded 8 years ago, this sustainability-focused B2B platform is taking the industry by storm! This advanced Team - which has more than doubled in the past year - is looking for an Information Security Offiver to come on board and lead the ISO funct...

Materna Information & Communications SE Karriere
bundesweit, Germany

Die Cyber Security bildet deshalb eines unserer neun Fokusfelder. ...

BayWa r.e.
München, Bayern

Due to our dynamic growth, we are expanding our team and currently looking for a Junior Deputy Information Security Officer (m/f/d). As part of your role, you will be enhancing our existing ISMS, scheduling internal as well as external audits and you will be the local responsible for information sec...

appliedAI
München, Bayern

We are looking for an experienced Information Security Officer to join our team. To lay the foundation, we need to ensure internal information security of the company, build and ensure security of the internal production processes, and build a secure environment for the internal products development...

Computer Futures
München, Bayern

Euro (je nach Berufserfahrung) * mind.Arbeiten * Weiterbildungsmöglichkeiten * und weitere Standard-Benefits, wie freies Parken, Urlaubs- und Weihnachtsgeld, betriebliche Altersvorsorge und noch vieles mehr! Haben wir dein Interesse geweckt? Dann melde dich bei mir, auch wenn du das Gefühl hast, das...

GULP – experts united
München, Bayern

Knowledge in the development of information security policies and implementation of security measures. Special emphasis is placed on security and integrity in the information systems. Information Security Consultant. Challenging and varied work in the field of information security. ...

State Street
München, Bayern

With immediate effect we are looking for a Global Chief Privacy Officer & SSBI Data Protection Officer, Managing Director. Work collaboratively with the Chief Data Office, Chief Information Security Officer and other internal stakeholders across governance forums, strategic projects and engagements ...