Offers “Unilever”

Expires soon Unilever

Cyber Risk Framework Manager

  • MEXICO
  • Sales

Job description

Function: Cyber Security

Scope : Global

Location : Bosques, CDMX.

Terms & Conditions : Full time position. Hybrid. Have a high level of English.

ABOUT UNILEVER

Unilever is one of the world’s leading suppliers of Food, Home, and Personal Care products with sales in over 190 countries and reaching 3.4 billion consumers a day. Unilever has more than 400 brands found in homes around the world, including Persil, Dove, Knorr, Domestos, Hellmann’s, Wall’s, Ben & Jerry’s, Marmite, Magnum, and Lynx. Faced with the challenge of climate change and the need for human development, we want to move towards a world where everyone can live well and within the natural limits of the planet. That’s why our purpose as Unilever is ‘to make sustainable living commonplace’.

At Unilever, we’re determined to achieve a culture where everyone can thrive, a culture where all individuals are treated fairly and respectfully, and where their uniqueness is celebrated. We’re taking a holistic approach that focuses on how we can use the scale and reach of our business to have the greatest impact in our own workplace and beyond. We’ve set clear goals to eliminate any bias and discrimination in our policies and practices, accelerate diverse representation in our leadership, and remove barriers for people with disabilities. At the same time, we’re setting out to spend more with diverse businesses and increasing representation of diverse groups in our advertising.

Unilever’s Cyber Security organization is a multi-disciplinary team responsible for protecting the Confidentiality, Integrity and Availability of our Information and Operations. Our Cyber Security organization runs a 24x7 Security Operations Centre, oversees a robust Security Architecture and associated technology landscape, provides Cyber Security Solution Engineering and Risk Advisory to our business, and assesses the security of our vast technology estate, including factories, to name but a few areas. Cyber Security sits as part of the Business Operations organisations, as a peer to Unilever’s Technology and Data functions and the broad Supply Chain agenda. Cyber Security is tasked with elevating, reporting on and influencing cyber risk mitigation across Unilever. The Cyber Security function is made up of the Governance, Risk, Assurance, and Compliance (GRAC) team, the Tech & Ops team, the BISO teams, and the Office of the CISO.

JOB PURPOSE

Using a risk led and threat informed approach, this critical role will ensure we have a robust framework for identifying, assessing and reporting cyber risk to support the prioritization of treatment in line with Unilever’s risk appetite.

At its core, the purpose of the role is to surface cyber risk and drive informed decision-making.  The primary outcome will be to enable the Business Information Security Officers (BISOs), Technical Information Security Officers (TISOs) and Information Security Leads (ISLs) to drive cyber risk remediation and, therefore, cyber risk reduction throughout the Unilever business.

WHAT WILL YOUR MAIN RESPONSIBILITIES BE

The Cyber Risk Framework Manager will sit within Unilever’s Cyber Security function. The successful candidate will be responsible for the execution, oversight and governance of Unilever’s Cyber Risk Management Framework, both centrally and by the wider cyber security leads across Unilever.

The role will ensure a consistent approach is used across the organisation for Cyber Risk management, in terms of identification, scoring, prioritisation and risk-decision making. Key to this role is the maintenance of the formal Framework and the provision of education, communication, support and oversight to those stakeholders involved in its execution. The role holder will also be accountable, with Risk Analyst support, for ensuring risk management tooling is correctly configured and risk data maintained.

The successful candidate will ensure a regular refresh of data used within the Risk Register and supporting framework components. Working with Cyber team colleagues, this includes data for cyber threat intelligence, vulnerability analysis and impact analysis. The Cyber Risk Framework Manager will also ensure that risk treatment decisions are formally captured, including risk acceptance, and that validation/sign-off occurs at the correct point of seniority within the organisation.

The role holder will use their subject matter expertise to provide consultancy support to the wider Cyber leadership team, acting as a source of advice and education for those operating cyber risk management. The successful candidate will be expected to remain up to date regarding industry risk management methodologies; and support the Senior Risk Manager in continuously evolving and improving the framework/register.

·  The Cyber Risk Framework Manager will support the interpretation and effective communication of risk analysis output to enable meaningful and impactful risk reporting and decision making.  As such the role is instrumental in helping Unilever effectively manage cyber risk across the global organization.
·  Execute the Cyber Risk Framework, ensuring its consistent use across the BISO/TISO organisation.
·  Create formal risk statements and define the templates for how we communicate Cyber Risk.
·  Ensure Framework integration/alignment with other Frameworks (e.g., Enterprise/Privacy/3rd Party)
·  Enable the aggregation of BISO/TISO risk registers for an enterprise view of the cyber risk landscape.
·  Engage with the Enterprise Risk team e.g., for fulfilment of the Risk Control Statement & updates.
·  Support the cyber insurance review, documentary submission and associated processes.
·  Coordinate the operation of quarterly Cyber Risk Boards and subsidiary risk meetings

WHAT YOU WILL NEED TO SUCCEED

Skills:

A suitable candidate will have:

·  Subject matter expertise in developing, maintaining, operating and governing Risk Management frameworks.
·  Excellent written and verbal communication skills, and the ability to be understood by both technical and non-technical personnel
·  The ability to manage conflicting priorities and multiple tasks in order to meet key deadlines.
·  Stakeholder management and interpersonal skills at both a technical and non-technical level.
·  Ability to work in a collaborative environment.
·  Ability to drive process teams to understand reporting situation, explores options and come to consensus on preferred solution.
·  Strong presentation skills.
·  Ability to work with internationally located stakeholders.
·  Ability to work with vague requirements to build prototypes/sketches and go through multiple iterations before agreeing on a workable solution.

Experience:

·  A suitable candidate will have:
·  Experience in Cyber Security, preferably in a Governance, Risk and Compliance (GRC) role.
·  Experience developing, maintaining, operating and governing Risk Management Frameworks.
·  Experience within a customer-focused environment.
·  Understanding of global best practice standards (e.g. NIST, CIS, ISO), Information Security standards and controls, and the “three lines of defence” model for appropriate segregation of duties and risk transparency.

Unilever is an organisation committed to equity, inclusion and diversity to drive our business results and create a better future, every day, for our diverse employees, global consumers, partners, and communities. We believe a diverse workforce allows us to match our growth ambitions and drive inclusion across the business. At Unilever we are interested in every individual bringing their ‘Whole Self’ to work and this includes you! Thus if you require any support or access requirements, we encourage you to advise us at the time of your application so that we can support you through your recruitment journey.

Make every future a success.
  • Job directory
  • Business directory