-
Assess the current security environment, identify key risks, and develop a comprehensive enterprise security strategy. Prepare an annual operational plan/roadmap and lead the implementation across the organization.
-
Oversee all aspects of the information security program, including people, processes, technology, and compliance. Ensure the ability to meet third-party assessment requirements and ideally bring experience with Operational Technology.
-
Manage and report security incidents, ensuring a consistent response. Prepare post-incident reports, share lessons learned, and present findings to senior management and the board.
-
Drive the development of an enterprise-wide cybersecurity agenda, delivering annual classroom and web-based training for staff, contractors, and third parties.
-
Evaluate emerging cybersecurity trends and IT technologies, providing guidance to internal teams on their adoption. Regularly brief senior leadership on relevant security trends and data.
-
Continuously monitor for potential internal and external threats. Regularly conduct vulnerability and penetration testing to identify and address security weaknesses.
-
Manage the IT Security budget and work to ensure compliance with key regulations such as PCI DSS, GDPR, and others, with a particular focus on ISO27001 and NIS2 compliance.
-
Oversee the management of third-party security vendors and ensure the integrity of the organization’s systems.
-
Contribute to the performance management process, ensuring delivery of both personal and team objectives.
-
Ensure full compliance with Health and Safety standards and practices.