Regional Security Manager for Eastern Europe (Chief Information Security Officer)
Job purpose
The Regional Security Manager for Eastern Europe manages the cybersecurity posture of Redion European based entities in tight coordination with the Redion Group Security function and in cooperation with the local IT functions present in the countries. This scope represents around 750 employees and 4 operational entities and IT departments and teams.
He/she defines and cascades the Group security policy (prevention protection detection resilience remediation) in his/her scope and ensures its application in all countries. He/she has an advisory assistance information training and alerting role in particular with the business directors and/or the management of the region. He/she ensures proper alignment with the Group CSO/CISO.
He/she ensures the implementation of operational processes and solutions to guarantee data protection and information systems security level but is also the main regional coordinator for BCM related topics and physical security which remains the responsibility of local teams.
The position is offered in Czech Republic Poland Hungary or Serbia.
Primary duties and responsibilities
The Regional Security Manager oversees and leads the division that ensures Redion is in a position to anticipate cyber threats and incidents and establish the right level of protection for customers people and operations. He/she ensures the brand is trusted as #safe #secure #resilient.
The Regional Security Manager is responsible for:
Defining and implementing a Security Strategic Plan at the Redion entities in scope in line with the Security Strategic Plan of the Group
Determining methods to implement enforce and advise the Redion entities in scope on Security related issues
Mitigating Redion risk exposure at entities in scope level ensuring that appropriate risk treatment plans are defined to comply with the defined risk appetite
Leading the Redion Security transformation journey to put in place at entities in scope level an organization based on key disciplines: Information Security Physical Security Operational Resilience Business Continuity
Establishing the holistic management of security
Ensuring right and well-informed security decisions are taken escalating when required to executive management and risk
Ensuring the provisioning of adequate resources (financial human technological etc.) to implement the Security Strategic Plan
Securing and monitoring the necessary budget and investments to deliver the mission
Coordinating and executing locally the Group security initiatives making sure main actions and activities are conducted by the relevant function while ensuring proper reporting to the holding security team
In cooperation with Group Security planning coordinating and executing the local penetration test campaigns for critical applications
Main interactions
Reports hierarchically to the Eastern Europe COO function with a hard reporting line to the Group CSO
Other Regional Security Managers local Chief Information Security Officers Chief Operations Officers and Chief Executive Officers
Group and Local Data Protection Officer
Group and Local Risk Officer
Group and Local Chief Transformation Officer
Group and Local Chief Operations Officer
Regional Chief Executive Officer
Qualifications
Team Management & Leadership: ability to engage with Business Leaders of its perimeter as well as with CSO/COO/CISO hierarchy
Organized self-sufficient with the ability to manage teams globally and drive change
Ability to prioritize and execute tasks in a high-pressure environment
Excellent written oral and interpersonal communication skills (English)
Demonstrated experience understanding security risks identifying gaps and creating risk-mitigating and remediation plans drawing up an IT Security roadmap
Demonstrated understanding of the technical aspects of information and IT technology and core security components: network firewall proxy VPN anti-malware email protection and filtering system security controls vulnerability assessment penetration testing
In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectors risk management incident management
Good grasp of PCI-DSS ISO 27001 NIST and other security norms standards & frameworks
One or more of the following certifications is a plus: CISM or CISSP; Microsoft Certified Systems Engineer: Security; GIAC Security Essentials; Certification Risk ISO 27005 IRAM 2 or eBios Risk Manager (ANSSI)
Analysis and synthesis skills
Availability to occasionally travel in the countries of responsibility and to Paris where the holding company is located
Personal attributes
Passionate about driving and sustaining change in an organization through committed leadership
Integrity dedicated to the principles of developing a strong collaborative organization with well-developed coaching skills
A creative results-oriented leader who is particularly good at balancing multiple priorities and issues
A team player up and down the organizational structure across countries and IT / Security departments
Confidence self-motivation and broad business understanding to thrive in a senior autonomous role
Ability to form open effective and trusting relationships with country CxO members
Good skills in Microsoft Office Suite especially Excel and PowerPoint
Required Skills:
Qualifications Team Management & Leadershipo Ability to engage with Business Leaders of its perimeter as well as withCSO/COO/CISO hierarchy at Europ Assistanceo Organized self-sufficient with ability to manage teams globally and drive change Ability to prioritize and execute tasks in a high-pressure environment Excellent written oral and interpersonal communication skills (English) Demonstrated experience understanding security risks identifying gaps and creating risk-mitigating and remediation plans drawing up IT Security roadmap Demonstrated experience understanding of technical aspects of information and IT technologyand core security components more such as network firewall proxy VPN anti-malware emailprotection and filtering system security controls vulnerability assessment penetrationtesting... In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectorsrisk management incident management etc Good grasp of PCI-DSS ISO 27001 NIST and other security norms standards & frameworks One or more of the following certifications is a plus: o CISM or CISSPo Microsoft Certified Systems Engineer: Securityo GIAC Security Essentialso Certification Risk ISO 27005 IRAM 2 or eBios Risk Manager (ANSSI) Analysis and synthesis skills Availability to occasionally travel in EA countries where Europ Assistance is present; mainlycountries of responsibility and Paris where Holding company is located
Required Education:
Bachelors
Regional Security Manager for Eastern Europe (Chief Information Security Officer)Job purposeThe Regional Security Manager for Eastern Europe manages the cybersecurity posture of Redion European based entities in tight coordination with the Redion Group Security function and in cooperation with the l...
Regional Security Manager for Eastern Europe (Chief Information Security Officer)
Job purpose
The Regional Security Manager for Eastern Europe manages the cybersecurity posture of Redion European based entities in tight coordination with the Redion Group Security function and in cooperation with the local IT functions present in the countries. This scope represents around 750 employees and 4 operational entities and IT departments and teams.
He/she defines and cascades the Group security policy (prevention protection detection resilience remediation) in his/her scope and ensures its application in all countries. He/she has an advisory assistance information training and alerting role in particular with the business directors and/or the management of the region. He/she ensures proper alignment with the Group CSO/CISO.
He/she ensures the implementation of operational processes and solutions to guarantee data protection and information systems security level but is also the main regional coordinator for BCM related topics and physical security which remains the responsibility of local teams.
The position is offered in Czech Republic Poland Hungary or Serbia.
Primary duties and responsibilities
The Regional Security Manager oversees and leads the division that ensures Redion is in a position to anticipate cyber threats and incidents and establish the right level of protection for customers people and operations. He/she ensures the brand is trusted as #safe #secure #resilient.
The Regional Security Manager is responsible for:
Defining and implementing a Security Strategic Plan at the Redion entities in scope in line with the Security Strategic Plan of the Group
Determining methods to implement enforce and advise the Redion entities in scope on Security related issues
Mitigating Redion risk exposure at entities in scope level ensuring that appropriate risk treatment plans are defined to comply with the defined risk appetite
Leading the Redion Security transformation journey to put in place at entities in scope level an organization based on key disciplines: Information Security Physical Security Operational Resilience Business Continuity
Establishing the holistic management of security
Ensuring right and well-informed security decisions are taken escalating when required to executive management and risk
Ensuring the provisioning of adequate resources (financial human technological etc.) to implement the Security Strategic Plan
Securing and monitoring the necessary budget and investments to deliver the mission
Coordinating and executing locally the Group security initiatives making sure main actions and activities are conducted by the relevant function while ensuring proper reporting to the holding security team
In cooperation with Group Security planning coordinating and executing the local penetration test campaigns for critical applications
Main interactions
Reports hierarchically to the Eastern Europe COO function with a hard reporting line to the Group CSO
Other Regional Security Managers local Chief Information Security Officers Chief Operations Officers and Chief Executive Officers
Group and Local Data Protection Officer
Group and Local Risk Officer
Group and Local Chief Transformation Officer
Group and Local Chief Operations Officer
Regional Chief Executive Officer
Qualifications
Team Management & Leadership: ability to engage with Business Leaders of its perimeter as well as with CSO/COO/CISO hierarchy
Organized self-sufficient with the ability to manage teams globally and drive change
Ability to prioritize and execute tasks in a high-pressure environment
Excellent written oral and interpersonal communication skills (English)
Demonstrated experience understanding security risks identifying gaps and creating risk-mitigating and remediation plans drawing up an IT Security roadmap
Demonstrated understanding of the technical aspects of information and IT technology and core security components: network firewall proxy VPN anti-malware email protection and filtering system security controls vulnerability assessment penetration testing
In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectors risk management incident management
Good grasp of PCI-DSS ISO 27001 NIST and other security norms standards & frameworks
One or more of the following certifications is a plus: CISM or CISSP; Microsoft Certified Systems Engineer: Security; GIAC Security Essentials; Certification Risk ISO 27005 IRAM 2 or eBios Risk Manager (ANSSI)
Analysis and synthesis skills
Availability to occasionally travel in the countries of responsibility and to Paris where the holding company is located
Personal attributes
Passionate about driving and sustaining change in an organization through committed leadership
Integrity dedicated to the principles of developing a strong collaborative organization with well-developed coaching skills
A creative results-oriented leader who is particularly good at balancing multiple priorities and issues
A team player up and down the organizational structure across countries and IT / Security departments
Confidence self-motivation and broad business understanding to thrive in a senior autonomous role
Ability to form open effective and trusting relationships with country CxO members
Good skills in Microsoft Office Suite especially Excel and PowerPoint
Required Skills:
Qualifications Team Management & Leadershipo Ability to engage with Business Leaders of its perimeter as well as withCSO/COO/CISO hierarchy at Europ Assistanceo Organized self-sufficient with ability to manage teams globally and drive change Ability to prioritize and execute tasks in a high-pressure environment Excellent written oral and interpersonal communication skills (English) Demonstrated experience understanding security risks identifying gaps and creating risk-mitigating and remediation plans drawing up IT Security roadmap Demonstrated experience understanding of technical aspects of information and IT technologyand core security components more such as network firewall proxy VPN anti-malware emailprotection and filtering system security controls vulnerability assessment penetrationtesting... In-depth knowledge of security concepts such as cyber-attacks and techniques threat vectorsrisk management incident management etc Good grasp of PCI-DSS ISO 27001 NIST and other security norms standards & frameworks One or more of the following certifications is a plus: o CISM or CISSPo Microsoft Certified Systems Engineer: Securityo GIAC Security Essentialso Certification Risk ISO 27005 IRAM 2 or eBios Risk Manager (ANSSI) Analysis and synthesis skills Availability to occasionally travel in EA countries where Europ Assistance is present; mainlycountries of responsibility and Paris where Holding company is located