Job Overview
BHFS USA is looking for an experienced Director – Chief Information Security Officer (CISO) to set out the security strategy for BHFS USA, implement security standards and monitor compliance against security policies.
Responsibilities and Duties
- Review existing and define new security policies for BHFS
- Coordinate and implement group IT security policies and requirements
- Monitoring of compliance with security standards and executing information security risk assessments
- Report on emerging new threats and provide solutions and education accordingly
- Enforce strong security adherence across the organization, develop and deliver training and security awareness programmes.
- Work at local level and across the Brands to enhance and implement security standards
- Respond to incidents, establish appropriate standards and controls. Report to Exec Team, ensuring awareness of current and emerging threats
- Specify and oversee the implementation of IT security measures
- Organize penetration testing
- Execute external and internal IT vulnerability assessments and own the delivery of remediation.
- Be the ‘go to’ expert for BHFS-USA on all matters relating to IT security
- Provide regular reports to global CPTO and Exec Team of BHFS
- Support on business and IT projects to ensure all comply with security policy and best practice
- Own and run IT security audits
Qualifications
- Bachelor’s degree or equivalent program in Computer Science, Business Information Systems, Information Security or Information Technology
- Relevant Professional certification essential: CISSP, CISA, CISM or CRISC
- Minimum 5 years in a Senior Information Security or similar role
- Excellent knowledge and experience of ISO27001 and ISO27002
- Experience in managing PCI-DSS certifications
- Experience in working in Payments business is essential
- Experience in working in large international organizations is an advantage
- Experience of formal risk assessment methodologies
- In depth understanding of networks, databases and business applications as they relate to security
- Excellent interpersonal skills and ability to influence and negotiate with senior stakeholders
- Succinct Communicator – ability to break down complex issues and communicate at all levels in the organization
- Ability to work in a cross-functional matrix environment
- Excellent understanding of vulnerability management and associated tools and solutions
- Keeps up to date on all matters pertaining to IT security
- Highly motivated. Ability to work under pressure and under own initiative
- Solution driven with demonstrated ability to meet deadlines and deliver results
- Strong knowledge of PSD2 and GDPR
- Travel will be 20%