Careerswift

Careerswift Fast Apply

Job search platform trusted by thousands of job seekers.
View all jobs at CORE Team
Actively HiringHot

Country CISO

About the Role

The Country CISO is responsible for all aspects of information security and cyber security across all of Information System (IS) of the country including: building, maintaining and regularly reviewing a robust cybersecurity strategy with solid cybersecurity policies, protocols and procedures across enterprise security architecture in consistency with group, security operations center, datacenter security, network security including cloud and applications security with appropriate security measures and initiatives, resilience and support business for business continuity. The country CISO shall ensure all previous activities are in full compliancy with national, supra-national and international regulations his business is subject to. His role also includes regular reporting to senior management and other stakeholders on threats and risks the business and the country may face. In doing so, the country CISO will advise for improvements in development, implementation and management of a country cybersecurity including all appropriate control objectives for system integrity, availability, reliability, resilience, confidentiality, and assurance to company, industry and international standards.



List the essential functions required for this position to exist. Also, list the responsibilities that must be completed in achieving the objectives of the position. Include all important aspects of the job -- whether performed daily, weekly, monthly, or annually; and any that occur at irregular intervals. Focus these responses on direct actions or key functions. 

• Ensure Country approach and strategy in IS Security is compliant with legal and regulatory requirements, Group of companies  standards and aligned with business objectives. 

• Liaise with legal in regards to regulations requirements on which the country must be compliant to 

• Liaise with Trade Compliance Officer in regards to export control requirements in systems and manage any e-discovery requirements that Company is required to undertake. 

• Promote and respect Group of companies IS standards and strategy. 

• Undertake governance responsibilities for IS security policy in Country. Design, preparation and dissemination of policies and procedures which achieve, and maintain, compliance to the various security rules under which country operates.

• Gain acceptance of proposed security solutions by the various security accrediting bodies within Group of companies DGDI Region CISO 

• Define clear policies, procedures, and performance criteria for Site Security Officers and IT staff who are involved in daily operational support processes that may impact security and cybersecurity risks or compliance obligations for the company. 

• Ensure appropriate budget and resources are allocated to support the cybersecurity program at country level 

• Ensure confidentiality, integrity, availability, resilience and traceability of information systems assets. The Country CISO supports also the business, who is responsible, for the business continuity. 

• Regular review and update country risk assessment. 

• Review the proposed enterprise architecture strategies and designs for the country related projects to ensure that no new risks are introduced into the country or the company, and to encourage changes to reduce risks keeping in mind the business and users’ usage needs


Maintain an understanding of current and emerging security threats that may affect the country and the company now or in the future. 

• Review strategies, operational changes and projects to ensure appropriate security controls are applied. Regular review, audit and update current implementation of Security Controls for the company measuring their effectiveness as per the expectations from risk assessment and threats. 

• Pilot the SOC service in terms of cybersecurity services and SLAs 

• Coordinate locally with the SOC and under the supervision of Group of companies Cert, the Incident Response Activities (refer to 87208650-INF GRP-EN - Group ISS incident handling procedure) 

• Ensure security incidents are reported, coordinated and managed with the Central Security body through DGSI Region CISO and Group of companies Cert (refer to 87208650-INF-GRP-EN - Group ISS incident handling procedure) 

• Ensure regular reporting to the country director, DGDI Region CISO, Operations and other stakeholders on the country business risks and threats, with security program & plans in place to reduce the risks to an acceptable level defined and approved by country decision-makers, achievements, issues and goals. 

• Support forensic investigations and analysis as required on country assets in support of functions (HR, legal, …) led investigations. 

• Ensure Security awareness and training programs are part of the country security strategy and sessions are deployed annually



Minimum Requirements: Skills, Experience & Education Include minimum experience qualifications, required proficiencies with specialized knowledge, computer proficiencies, etc. 

• Bachelors (Masters preferred) Information Technology and/or Information Security (Degree or equivalent). 

• 10+ years of leadership experience overseeing security initiatives in a large, preferably global enterprise. 

• Obtained one or more of the following certifications: Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Global Information Assurance Certification (GIAC), Project Management Professional (PMP) or other related certifications. 

• Demonstrable experience of emergency preparedness, critical incident management, business continuity and disaster recovery. 

• Experienced with large IT Infrastructure and/or IT security projects, e.g., firewall deployment, NAC implementation, web proxy upgrade etc. 

• Prior experience with information security framework, secure network architecture and design, cloud computing, and secure application architecture/design. 

• Proven experience of leading a dispersed, multi-site team. 

• Strong working knowledge of information security technologies, markets and vendors including firewall, intrusion detection, assessment and monitoring tools, encryption, certificate authority, and cloud networks. 

• Experienced in developing policies and procedures for identity and access management, security programs, security procedures, security standards, requirement definition, and project management plans. 

• Adept in creating business cases and user cases including the ramification of various system, network and application security decisions and recommendations. 

• Articulate with strong verbal and written communication skills including technical and non-technical audiences. 

• English C1 level minimum or above


Preferred Qualifications Preferred attributes for the position, which are not required in the minimum qualifications (e.g., master degree) 

Experienced in working within a centralized/decentralized matrix business environment. Knowledge of SEI’s CMMI model for secure software development. Broad experience of conducting risk assessments including presenting recommendations to c-suite

Required Skills

Cybersecurity Strategy, Information Security Governance, Cybersecurity Risk Management, Security Leadership, Security Architecture, Regulatory Compliance, Incident Response, Incident Management, Security Policy & Standards, Security Program Management, Executive Stakeholder Management, Business Continuity, Disaster Recovery, Enterprise Security

Job Details

Company

CORE Team

Location

Lviv, Львівська область, Україна

Seniority

Executive

This position is currently active and accepting applications through Careerswift.