Apply

Information Security Officer

Posted 2024-11-07

View full description

💎 Seniority level: Junior, 1-2 years

🔍 Industry: InsurTech

🏢 Company: OneDegree

🗣️ Languages: English, Cantonese

⏳ Experience: 1-2 years

🪄 Skills: Problem Solving

Requirements:
  • Bachelor's degree in Information Technology, Information Security, Computer Science or a related field.
  • 1-2 years of experience in information security management.
  • Holder of relevant industry recognized security testing certification e.g. CISSP, CISM, CRISC, CISA etc., will be an advantage.
  • Strong understanding of information security practices.
  • Excellent communication skills, with the ability to explain complex security concepts to non-technical stakeholders.
  • Proactive and detail-oriented with strong problem-solving skills.
  • Fluency in English and Cantonese is essential.
Responsibilities:
  • Draft and maintain information security policies and procedures to ensure compliance with regulatory requirements and industry best practices.
  • Conduct regular risk assessments on IT systems and business processes, identifying vulnerabilities and managing the risks.
  • Implement global security initiatives within the local business context, ensuring alignment with the global security strategies.
  • Serve as the primary contact for all information security-related questions from stakeholders, providing timely and accurate responses.
  • Collaborate with IT and business teams to enhance information security awareness and adherence to security practices throughout the organization.
  • Monitor and report on the effectiveness of security measures and compliance with established policies.
Apply

Related Jobs

Apply

📍 Germany

🧭 Temporary

🔍 Video solutions

🏢 Company: movingimage

  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, or related field; advanced degrees preferred.
  • Relevant certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor, AZ-500 or equivalent.
  • Minimum of 5 years of experience in information security or a related role, preferably in a SaaS or technology environment.
  • Experience in audits and maintaining compliance with ISO/IEC standards.
  • Hands-on experience with risk and vendor management, incident response practices.
  • Knowledge of DevSecOps principles and secure SDLC practices.
  • Familiarity with frameworks like GDPR, DORA, and BSI IT Grundschutz.
  • Strong analytical and problem-solving skills.
  • Proven track record in developing security policies and procedures.
  • Familiarity with SIEM tools.
  • Good working knowledge of Confluence and JIRA.

  • Lead preparation for ISO 27001 upgrade from 2013 to 2022.
  • Develop, implement, and monitor an integrated management system aligned with ISO 27001, ISO 9001, ISO 20000-1, and TISAX requirements.
  • Facilitate internal and external audits for compliance.
  • Create and maintain security documentation, including policies and incident response plans.
  • Conduct risk assessments to identify vulnerabilities.
  • Collaborate with DevSecOps and Engineering teams.
  • Stay informed about cybersecurity threats and develop protective measures.
  • Deliver security awareness programs for employees.
  • Review vendor security postures and conduct risk assessments.
  • Facilitate post-incident reviews and corrective actions.

AgileCybersecurityJiraProduct DevelopmentCollaborationDocumentationCompliance

Posted 2024-11-15
Apply
Apply

🔍 Wholesale

  • Excellent communication skills to interact with a diverse range of professionals.
  • Bachelor’s or master’s degree in information technology, computer science, cybersecurity, business administration, or a related field.
  • Experience in developing and implementing information security policies and compliance.
  • Strong knowledge in information security governance, risk management, and compliance principles.
  • In-depth knowledge of management systems, audits, vulnerabilities, and audit findings.
  • Familiarity with ISO 27001 or comparable standards.
  • Experience working in an agile environment.

  • Implement and adapt the METRO AG ISMS for local compliance.
  • Plan and execute IT and IS risk assessments.
  • Develop and execute a yearly action plan to reduce risks and improve maturity.
  • Conduct awareness campaigns and training for local teams.
  • Report IT and IS information to the CISO organization.
  • Oversee incident response management in coordination with CISO.
  • Assist legal department with local information security regulations.
  • Collaborate with local data protection and security officers.
  • Perform local information security assurance reviews.
  • Manage relationships with local cybersecurity agencies.
Posted 2024-11-02
Apply
Apply

📍 United States

💸 150000 - 190000 USD per year

🔍 Oil & Defense Industry

🏢 Company: EVOTEK, Inc.

  • Experience with Cyber Compliance Assessments and regulatory standards including NIST 800-171, CMMC, DFARS.
  • 10+ years of Cybersecurity experience, ideally in oil or defense sectors.
  • Proven track record in threat and vulnerability assessment.
  • Ability to develop strategic enterprise information security programs.
  • Experience with customer-facing products.
  • Effective communication across diverse audiences.
  • Self-starter capable of leading tasks independently.

  • Develop, drive, and implement the client's overall information security program including goals and policies.
  • Establish security architecture standards and implement technical controls.
  • Drive domestic and international projects to meet cybersecurity requirements.
  • Monitor compliance with security policies, including third-party compliance.
  • Oversee incident response and data loss prevention.
  • Implement risk assessment programs for information security and privacy matters.
  • Coordinate security reporting and assessments as required.

LeadershipProject ManagementCybersecurityProject CoordinationCross-functional Team LeadershipStrategyCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-10-26
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Cybersecurity Consulting

🏢 Company: Cyber Advisors

  • Minimum of 10+ years of experience in information security, with at least 5 years in a senior security leadership role.
  • Experience consulting for diverse industries, with a solid understanding of industry-specific risks.
  • In-depth knowledge of security frameworks such as NIST, SOC2, ISO 27001, TISAX, CIS Controls.
  • Hands-on experience with security tools and technologies including firewalls, IDS/IPS, DLP, SIEM, and encryption solutions.
  • Relevant security certifications such as CISSP, CISM, CISA, CRISC or equivalent, and a bachelor's degree in information security or related field.

  • Develop and execute tailored security strategies for each client, aligning with their business goals and risk profile.
  • Conduct risk and vulnerability assessments, ensuring regulatory compliance with frameworks like GDPR, CCPA, HIPAA, and PCI DSS.
  • Lead incident response during security breaches, providing clients with guidance on containment and recovery.
  • Build comprehensive security programs, conduct security awareness training, and oversee governance mechanisms.
  • Maintain long-term client relationships and regularly report on security posture and improvements to client leadership.

LeadershipCloud ComputingCybersecurityAmazon Web ServicesAzureCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-10-24
Apply
Apply

📍 Georgia, Armenia, Serbia, Poland

🧭 Full-Time

🔍 Social discovery and dating services

🏢 Company: Social Discovery Group

  • Experience in IS for over 5 years, with at least 3 years in a managerial role.
  • Higher technical education.
  • Good understanding of real-world trends and threats related to IS.
  • Experience in operating and configuring IS tools such as DOE, DLP, anti-virus, IDS/IPS, and vulnerability scanners.
  • Ability to organize teams for IS incident investigations.
  • Past system administration skills in Windows and Linux.
  • Knowledge of network technologies and security.
  • Experience in organizing protection against DDoS attacks on high-load websites.
  • Experience with external infrastructure security audits.
  • Ability to advocate for resources to fulfill IS tasks.

  • Management of the Information Security Department.
  • Administration of existing Information Security (IS) means.
  • Testing and commissioning of new IS means.
  • Monitoring IS events and handling IS incidents including access management.
  • Organizing protection of websites from DDoS and hacking attacks.
  • Creation and formalization of IS policies and regulations.
  • Communications with IS solution and service providers and related departments.

LeadershipCybersecurityCross-functional Team LeadershipCommunication SkillsAnalytical SkillsCollaboration

Posted 2024-10-23
Apply
Apply

📍 USA

🧭 Full-Time

💸 210000 - 300000 USD per year

🔍 Healthcare

🏢 Company: Zscaler

  • 10 years of experience in leadership roles focused on technology improvement and development within healthcare.
  • A BS or BA degree is required.
  • Expertise in supporting GTM teams within the healthcare provider community.

  • Act as Zscaler's technical executive sponsor for the largest healthcare providers.
  • Provide technical leadership within the Healthcare GTM team in a customer-facing role.
  • Oversee technology resources, establishing vision, strategies, and growth plans.
  • Support growth strategy by expanding customer relationships and developing new business opportunities.
  • Conduct research on industry trends and improve technology standards across the organization.

LeadershipBusiness DevelopmentStrategyBusiness development

Posted 2024-08-28
Apply
Apply

📍 United States

🧭 Full-Time

🔍 Technology/Consumer Services

  • Minimum 15 years of experience in technology, with at least 10 years in information security.
  • Strong technical background and experience with AWS or other cloud platforms, mobile, and IoT devices preferred.
  • Proven capability in developing and implementing security strategies.
  • Excellent analytical, problem-solving, decision-making, communication, and interpersonal skills.
  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field; Master's degree preferred.

  • Develop and implement a comprehensive information security strategy to protect assets.
  • Align security initiatives with business objectives.
  • Identify, assess, and mitigate information security risks.
  • Oversee daily cybersecurity activities, manage incident responses.
  • Establish security awareness training and culture.
  • Collaborate with IT, legal, compliance, and product teams.

LeadershipProject ManagementCybersecurityJavaJavascriptPeople ManagementProduct ManagementC (Programming language)Project Coordination

Posted 2024-07-21
Apply