Area Security Officer

Randstad España
Randstad España
Barcelona, SpainOn-siteCompetitiveAdded 14 days agoSenior · 5+ yearsPermanentRemote: Remote

Original Advert

Strategy and Governance:

Collaborate with the Group CISO and Region Security Officer to implement cybersecurity strategies for the Area of the Region, aligned with the global security vision and business objectives
Participate and maintain the robust cybersecurity governance framework in the Area, ensuring alignment with NIST CSF, ISO 27001, and other relevant standards
Participate in meetings to provide updates on the Area's security posture and initiatives

Risk Management and Compliance :

Oversee risk assessments and management processes for the assigned Area, integrating with the global risk management framework
Ensure compliance with relevant cybersecurity regulations and standards, including privacy laws (e.g., GDPR) applicable to Area operations
Collaborate with Legal & Compliance to address security-related regulatory requirements and audits

Business demand management

Help to manage the incoming requests from customers and third parties. Assess and categorize, fulfill. Report on volumes and trends
Take support and assistance from stakeholders, especially DxT central teams but also application owners and their corresponding organization and partners.
Go up the commercial stream: by engaging with S&M leads spot needs earlier and engage directly with the customers

Awareness and Behavior

Through scouting and studies identify the best practices and disruptive technics in relation to user behavior change
Stay tuned to last updates in user-related threats and compromise scenarios (e.g. AI, deep fakes...). Influence DxS compliance and Area program and initiatives
Engage with corporate communication team to foster culture change around cybersecurity

Governance, Risk & Compliance platforms ownership

Strong usage of LogicGate and KnowBe4 platforms
Grow and improve the platforms: implement modules and processes, introduce innovative features
Keep independent from DxS team managers

Reporting and Metrics:

Develop and maintain cybersecurity dashboards and KPIs for the assigned Area
Provide regular reports to the Group CISO, Regional SO and other relevant stakeholders on the Area's security posture, incidents, and initiatives

Innovation and Research:

Stay informed about emerging cybersecurity threats, technologies, and best practices
Evaluate and recommend new security solutions and approaches for implementation in the assigned Area

Security Operations and Incident Response:

Work closely with DxT Team for the day-to-day cybersecurity operations in the Area, including monitoring, threat detection, and vulnerability management
Participate the incident response team for Area-related security incidents, coordinating with the global security team as needed
Oversee the implementation and maintenance of security technologies and solutions specific to Area needs

Policy and Process Management:

Ensure alignment with global policies and collaborate with DxS team
Push for improvement initiatives for security processes within the Area
Collaborate with HR and other departments to integrate security policies into Area operations and culture

Awareness and Training :

Oversee cybersecurity awareness and training programs for Area staff
Conduct or participate in regular briefings for executive leadership on cybersecurity matters affecting the Area
Foster a culture of security awareness and best practices among Area employees

Vendor and Third-Party Risk Management:

Oversee the security aspects of vendor relationships and third-party integrations specific to Area operations
Help to conduct security assessments of potential vendors and partners working with the Area

Education:

Master's degree in computer science, information technology, security and/or related field, or equivalent experience

Experience:

5+ years of experience in information security
Experience in managing or taking part in IT projects for large, complex organizations
Experience working in multinational environments and collaborating with global teams

Knowledge:

Understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001) and their practical application
Knowledge of cybersecurity technologies, best practices, and emerging threats
Strong grasp of relevant regulations and compliance requirements
Understanding of business operations and how security integrates with various business functions
Highl level of French and English.

Skills and Abilities:

Eagerness to advocate for security and compliance
Strategic thinking and decision-making abilities
Communication skills, with the ability to effectively engage with both technical and non-technical stakeholders
Ability to influence and drive changes in the organization
Familiarity with project and program management
Adaptability and resilience in a fast-paced, evolving threat landscape

Need a visa? No sponsorship mentioned here. Browse visa jobs