Regional Information Security Officer (RISO)
Internship London, UNITED KINGDOM Sales
Job description
We are currently seeking a Regional Information Security Officer to ensure the streamlined alignment of the Group and Region for all Information Security and IT Security matter.
· The primary purpose of this role is to ensure strong regional alignment with the Global CISO team/strategy and promote any regional requirements for integration in the Global Information Security strategy.
· The secondary purpose of this role is to manage and deliver several InfoSec Transformation Programs activities that fall within this domain.
· The third purpose of this role is to become a credible and recognised Information Security Single Point Of Contact (SPOC) across the region able to influence at Senior level, educate the business functions; interact successfully with all oversight functions (risk, audit, legal…) and local regulators.
Responsibilities:
· Be the Regional entry point for the Global InfoSec team and the local functions for IT Security and Information Security.
· Provide InfoSec consultancy and advisory on cross-functional initiatives and special initiatives that occur as a result of an ad-hoc request received from the Business, the regulator or the IT Team.
· Ensure the adoption and compliance with the Chanel Information Security Policy (CISP) as well as the global Information security processes and tools.
· In close collaboration with the Global InfoSec Assurance team, be the local point of contact for all auditors (internal or external) and coordinate and/or lead (self-assurance) all IT audits execution.
· In close collaboration with the Global InfoSec Assurance team, manage the 3rd parties security assurance and annual re-certification activities for the region.
· In close collaboration with the Global InfoSec Assurance team, monitor the IT & Information Security risks at local and regional level.
· Be a member of the regional incident response team taking the lead on all InfoSec and IT Security matters.
· Establish, own and manage InfoSec Testing/Assurance framework, leveraging on Group tools and processes while ensuring local criteria are in scope.
· Act as a local business enabler for the Global InfoSec services delivery and evangelise IT security via training session delivery ensuring that InfoSec is not seen as a blocker, but as a partner to endeavours and goals.
· Own projects delivery and initiatives within the InfoSec Transformation Program, providing tactical project management where necessary, SME guidance where appropriate and by calling on the resource of other teams and departments as required.
· Act as a collaborator across the CISO team and wider business, sharing knowledge and insight and helping develop individuals.
· Produce presentations and analysis describing Information Security and CISO team activities for a range of audiences with varying levels of seniority.
· Manage the InfoSec regional annual budget in coordination with the local management as well as the Global CISO.
· Liaise with other pillars to standardise Management Information (MI) reporting, with ownership of all MI data produced by the Operations pillar. Coordinate the production of MI, reporting packs and presentation materials within the CISO team and communicate the outputs to relevant internal and external parties.
Position Requirements
· A university degree in a technology and/or Business subject
· More than 10 years InfoSec/ IT Security experience in large international organisation
· Security certifications like but not limited to:
· CISSP
· CISM
· CISA
· CGEIT
· CRISC
· ISO 27001/5
· Knowledge of applicable data privacy practices and laws
· Knowledge of network protocols and IT infrastructure
· Proven experience working successfully with external service providers
· Strong understanding of project management principles
· Excellent interpersonal skills
· Ability to present ideas in business-friendly and user-friendly language
· Highly self-motivated and directed with ability to effectively prioritise tasks
· Proven analytical, evaluative, and problem-solving abilities
· Extensive experience working in a team-oriented, collaborative environment
· Excellent English written and oral communication skills.
· French and Regional languages are desirable
Relationship matrix
· Internal :
· Global CISO Team
· Corporate / Divisions IT Teams
· Business & oversight functions
· Auditors (internal & external)
· CHANEL Senior Leaders
· External
· Suppliers
· Auditors
· Regulators