Chief Information Security Officer (CISO)
Department:
Job Summary
Testronic is a global leader in Quality Assurance and technology services for the games and entertainment industries. We work with some of the worlds leading game developers and publishers providing Functional QA Compliance QA Localization QA Compatibility QA and other specialized services.
With diverse teams across Europe Asia and North America we foster an inclusive collaborative culture built on four core values: We Care Deeply Passion for Quality Trust in Unity and Pride in Ownership. Whether youre starting your career or looking for your next challenge Testronic offers opportunities to learn grow and make a meaningful impact.
About the Role
We are looking for a Chief Information Security Officer (CISO) to lead Testronics information and cyber security programme at a global CISO will define and deliver the security strategy oversee enterprise security risk and governance lead the Information Security function and provide senior leadership and Board-level advice on cyber security resilience and compliance.
Responsibilities:
Information Security Strategy
- Develop and deliver Testronics global information security strategy aligned with business objectives technology plans and risk appetite.
- Translate security objectives into measurable programmes capabilities and annual priorities.
- Monitor the security landscape and adapt the strategy to emerging threats technology and regulatory requirements.
Governance & Risk Management
- Own the global information security governance framework policies and risk management processes.
- Ensure material security risks have clear ownership treatment plans and appropriate escalation.
- Oversee the Information Security Management System and promote security accountability across the organisation.
Board & Senior Leadership
- Provide clear regular reporting to the Board and senior leadership on cyber risk security posture incidents compliance and resilience.
- Advise executives on significant security risks and support informed business decisions.
- Communicate complex security topics in clear business and financial terms.
Security & Incident Management
- Act as the senior escalation point for significant information security incidents.
- Lead or support executive-level response to major cyber incidents working with IT Legal Privacy Communications and business teams.
- Ensure incident response exercises lessons learned and remediation activities are effectively managed.
Security Programme & Assurance
- Oversee security programmes covering corporate technology cloud applications products and third parties.
- Provide oversight of security architecture vulnerabilities penetration testing control testing and independent assurance.
- Monitor the effectiveness of internal and outsourced security services and ensure key security improvements are delivered.
Compliance & External Stakeholders
- Oversee information security requirements arising from legislation regulations customer contracts and recognised standards.
- Support ISO 27001 and other relevant certification and assurance programmes.
- Represent Testronic in significant security matters involving clients auditors regulators insurers and other external stakeholders.
Leadership & Business Partnership
- Lead develop and build a capable global Information Security function.
- Work closely with IT Legal HR Facilities Commercial QA and other departments to embed security into business and technology decisions.
- Manage the security budget strategic suppliers and major security investments.
- Ensure security risks are considered in acquisitions outsourcing and major organisational or technology changes.
Requirements
- Significant senior-level experience in information and cyber security.
- Experience developing and implementing an enterprise security strategy.
- Experience advising Boards executives or senior governance committees.
- Strong experience in enterprise security risk management and governance.
- Experience leading security programmes across complex technology environments.
- Experience managing significant cyber security incidents or crisis situations.
- Experience leading and developing multidisciplinary security teams.
- Strong understanding of security governance architecture operations assurance and operational resilience.
- Knowledge of cloud infrastructure identity application and product security.
- Experience with security frameworks ISO 27001 and third-party risk.
- Strong stakeholder programme budget and supplier management skills.
- Knowledge of relevant UK legal regulatory and contractual requirements.
GOOD TO HAVE: CISSP CISM CCISO ISO/IEC 27001 Lead Implementer/Lead Auditor CRISC or equivalent qualifications.
Required Experience:
Chief
About Company
We are a unique outsource partner with over 20 years experience providing award-winning QA Testing, Localization and Player Support services to entertain providers across the planet.