Manager -Regional Information Security Officer NAFTA

Mercedes-Benz Group

• $108K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of cybersecurity experience, ideally with IT product rollouts
  • Strong understanding of cloud security, including Azure
  • Possession of CISSP certification is required; CCSP or AZ500 recommended
  • Knowledge of regulatory frameworks like GDPR and ISO/IEC 27000
  • Proficient in risk assessment and implementing security controls

Responsibilities

  • Lead the development of a comprehensive cybersecurity strategy aligned with business goals
  • Assess cybersecurity maturity and direct remediation efforts to enhance posture
  • Define and enforce cybersecurity policies, ensuring regulatory compliance
  • Oversee the implementation of the information-security program, fostering a security-first culture
  • Manage third-party cybersecurity risks and ensure supplier compliance
  • Monitor and report cybersecurity threats and prepare incident response plans
  • Promote security awareness across the organization through targeted training initiatives

Benefits

  • 401(K) plan with matching contributions
  • Competitive vacation and personal time off
  • Access to a Mercedes-Benz car program
  • Flexible work arrangements
  • Performance-based bonuses
Full Job Description
Job Overview:Assure fulfillment of the Regional Information Security Officer (RISO) line function and lead the Information Security Team within the Mercedes Benz Financial Services Americas organization. The ISO works closely with the global Cybersecurity team and supports business units or areas in identifying and mitigating information security risks and contributes to corporate information security initiatives. The ISO is accountable for the implementation and continuous improvement of information security within the respective business unit or area. Additionally, the role is responsible for securing and governing cloud and AI platforms , ensuring resilient architecture, compliant data usage, and trusted deployment of AI capabilities across the organization In addition, the ISO provides strategic direction for cybersecurity initiatives, ensuring they align with Mercedes-Benz's global security standards, regulatory frameworks such as A22.1 and Regulations for Information Security (RISE 2.0), and the organization's overall risk appetite. The ISO acts as a trusted advisor to senior leadership, offering insights on emerging threats, security-related business impacts, and required investments to maintain resilience The role also plays a key part in fostering a culture of security awareness across all business units. This includes partnering closely with BISOs, ISAs, IT, Compliance, Legal, and broader corporate security functions to embed secure-by-design practices into systems, processes, and projects. By enabling transparency, continuity, and cross-functional collaboration, the ISO ensures Mercedes-Benz operations remain secure, compliant, and prepared for evolving cyber risks Responsibilities:Strategic Cybersecurity Leadership Develop and lead the enterprise-wide cybersecurity strategy aligned with business objectives and evolving threat landscapes. Drive continuous improvement of cybersecurity maturity by assessing posture, identifying gaps, and leading remediation initiatives. Advise senior leadership on cyber risks, emerging threats, regulatory impacts, and required investments. Governance, Policy & Compliance Management Define, maintain, and enforce cybersecurity policies, standards, procedures, and architectural principles. Ensure compliance with A22, Regulations for Information Security (RISE), ISO/IEC 27000, GDPR, CCPA, and other applicable regulations. Oversee risk management programs, including risk identification, assessment, prioritization, and mitigation. Govern the secure and ethical adoption of AI and emerging technologies across the enterprise. Manage exceptions, deviations, and escalations related to non-compliance with security or privacy requirements. Cybersecurity Program Oversight Manage the implementation and continuous improvement of the enterprise information-security program. Evaluate organizational security maturity and deliver structured improvement plans. Embed a security-first culture through awareness, education, and shift-left practices. Integrate Security-by-Design and DevSecOps principles across the SDLC for secure code development. Operational Security & Incident Response Identify, track, and remediate vulnerabilities, audit findings, and operational security gaps. Ensure alignment with RISE requirements and contribute feedback for global improvements. Support incident-response activities including triage, containment, remediation, and lessons learned. Conduct Cyber Security Assessments and support internal/external audits. Collaboration with Global, Regional & Local Security Stakeholders Collaborate with Global Cyber Security (GCS) to ensure alignment with global security strategies and frameworks. Partner with Local Compliance and the DPO/LCO to integrate data-protection requirements into cybersecurity practices. Work with Business Information Security Officers (BISOs) to align security controls with business needs and risk profiles. Maintain strong communication channels across security governance bodies, ensuring transparent, consistent reporting. Contribute to global awareness programs, ISO forums, and multi-stakeholder security initiatives. Data Protection, Privacy & Information Governance Establish and enforce data-privacy controls and secure-handling requirements aligned with regulatory and industry standards. Implement data classification, protection, and lifecycle governance to safeguard sensitive information. Support privacy-by-design and secure data-provisioning practices (e.g., masking, minimization). Third-Party & Supply-Chain Risk Management Lead the vendor risk-management program, evaluating and monitoring third-party cybersecurity posture. Ensure supplier compliance with contractual, security, and regulatory expectations. Monitoring, Metrics & Reporting Monitor IT infrastructure, cloud, and applications for security threats, anomalies, and vulnerabilities. Define and track KPIs and KRIs to measure program effectiveness. Deliver regular executive-level reporting on risks, incidents, compliance, and security posture. Business Continuity & Disaster Recovery (BC/DR) Oversee development, testing, and enhancement of BC/DR capabilities. Support crisis-management processes and ensure resilience against cyber incidents, outages, and operational disruptions. Security Awareness & Culture Building Drive enterprise-wide security-awareness programs and targeted training initiatives. Promote a culture of shared responsibility and proactive risk mitigation across all teams. AI & Emerging Technology Cybersecurity Implement AI-specific cybersecurity controls, ensuring safe, ethical, and compliant adoption of AI systems. Develop governance frameworks for AI risk management, including model-security reviews, monitoring, and red-teaming of AI systems. Identify and mitigate risks associated with AI misuse, prompt injection, model poisoning, data leakage, and adversarial attacks. Guide cross-functional teams on secure integration of AI/ML pipelines, including data governance, training-data protections, and secure deployment. Evaluate security implications of emerging technologies (AI, IoT, blockchain, edge computing, autonomous systems) and ensure secure adoption. Cloud Security & Secure Cloud Architecture Oversee cloud-security controls across multi-cloud environments, ensuring alignment with enterprise standards and Zero-Trust principles. Ensure secure cloud architecture, including IAM, encryption, network segmentation, and workload protection. Collaborate with platform, DevOps, and application teams to embed security-by-design into cloud deployments and migrations. Manage cloud risks through continuous monitoring, configuration governance, and regular security assessments. Ensure SaaS, PaaS, and IaaS services follow the shared-responsibility model and meet security and compliance requirements. Leadership & Communication Inspire, motivate, and guide diverse technical and non-technical teams while fostering strong cross-functional collaboration. Lead day-to-day team operations, providing coaching, guidance, and support to ensure high performance and professional growth. Cultivate a team culture centered on innovation, knowledge sharing, accountability, and operational excellence. Ensure the team has the necessary skills, capabilities, and talent to deliver on cybersecurity and business objectives. Provide clarity and direction in ambiguous or complex situations, enabling teams to execute with confidence. Drive team performance with a focus on speed, agility, stability, and continuous improvement. Offer constructive feedback and empower team members to take ownership of their responsibilities and outcomes. Qualifikationen Qualifications: Applicants must be legally authorized to work in the U.S. at the time of application. Relocation assistance will not be provided for this position. This position requires a minimum of 5 years of overall work experience. Preferred experience includes: Strong background in cybersecurity including large-scale IT product rollouts Experience with Networking, Cloud-based applications, Server hardening/security baseline standards, patch management, and remediations Education:High School Diploma/(GED) is required, Bachelor's Degree is preferred. Recommended majors include: Computer/Information Science or Information Technology Certifications The ideal candidate must have CISSP (Certified Information Systems Security Professional). CCSP (Certified Cloud Security Professional) or AZ500 Azure Security Engineer are highly recommended Additional Knowledge: Knowledge of IT guidelines and corporate IT policies, IT standards, knowledge of IT organization (e.g., for escalation paths for non-standard requests) Ability to assess risk and implement effective security controls during and after the development process Deep understanding of IT application architecture, integration, and lifecycle management Understanding of Zero Trust Architecture (ZTA), AI security governance, and cloud security frameworks Skills: Proficiency in DevOps tools and practices, coupled with deep knowledge in cybersecurity. Strong communication skills to translate complex technical concepts into business terms Strong proficiency with common management frameworks, regulatory requirements, and industry-leading practices Additional Skills: Excellent leadership and communication skills to drive security initiatives and foster collaboration Proven leadership in cross-functional environments, including mentoring and team development Contribute to overall strategy development related to IT security and IT more broadly and the business Posting Statement If you were not re-directed successfully after clicking the "Apply for this job" button, please click the following link to search and apply for the role on the local career portal: https://daimler.taleo.net/careersection/ex/jobsearch.ftl Mercedes-Benz Financial Services offers competitive salary, performance-based bonuses and a full suite of benefits including 401(K) with match, generous vacation and personal time, a Mercedes-Benz car program as well as flexible work arrangements #LI-JM2 or #LI-DNI (remove if posted externally)

Similar Jobs

More Jobs at Mercedes-Benz Group

More Information Technology Jobs

Find similar Manager -Regional Information Security Officer NAFTA jobs: