Our Risk Management Function is looking for a Head of Group Information Security Management
Your responsibilities
The primary target of this role is to ensure protection and integrity of Uniper’s information assets, where appropriate based on an effective information security management system (ISMS). The Head of Group Information Security Management is reporting to the Chief Risk Officer (CRO).
Key responsibilities include:
- Lead the international team of 10+ information security professionals.
- Develop the information security strategy, policies, and overall information security framework.
- Report information security matters to the relevant management bodies and act as key contact for auditors and authorities.
- Ensure compliance with information security requirements and examine information security incidents.
- Initiate and monitor the implementation of information security measures, as well as advise on issues of information security, e.g., help to resolve conflicting goals, support the preparation of respective contingency plans.
- Regularly perform measures to raise awareness (e.g. phishing simulations) and prepare training sessions on information security.
Your profile
- Completed degree in business information technology, computer science, or a similar field.
- Several years of experience in information security, a security related field or other information risk management function. Preferably previous experience as information security team lead / Chief Information Security Officer.
- Profound knowledge of information security industry standards and regulatory requirements, e.g. ISO 27001, NIST CSF, NIS 2. Proven track record of implementing new regulation and maintaining compliance.
- Detailed understanding of respective subject matter content, e.g., modern IT technology stacks, control system architecture.
- Relevant professional qualifications / certifications, e.g., CISM, CISSP.
- Capable of assessing trade-offs holistically and making risk-informed decisions.
- Convincingly manage conflicting stakeholder requirements.
- Excellent communication skills across various hierarchical levels in the organization.