Security Chapter Lead
Publiée le 16/05/2024
SOPRA STERIA PSF
Overview: As the Security Chapter Lead and Head of Security Office, you will be responsible for providing leadership and direction to our security team within the bi-dimensional matrix organization. Your primary focus will be on ensuring the security and integrity of our IT infrastructure, systems, and data. You will lead the Security Office, driving the development and implementation of security policies, practices, and controls aligned with industry standards and regulatory requirements. Collaborating closely with cross-functional teams across squads, you will integrate security into all aspects of our operations and development lifecycle.
Key Responsibilities:
- Security Strategy and Governance:
- Develop and maintain the security strategy and roadmap for the organization, in alignment with business objectives, regulatory requirements, and industry best practices.
- Establish and enforce security policies, standards, and procedures across squads and chapters, ensuring compliance with relevant laws, regulations, and contractual obligations.
- Provide strategic guidance and recommendations to senior leadership and the Security Office on the organization's security posture and risk management.
- Security Operations and Incident Response:
- Oversee security operations, including monitoring, detection, and response to security incidents and breaches across the organization.
- Lead the Security Incident Response Team (SIRT), coordinating efforts to investigate and mitigate security incidents in a timely and effective manner.
- Develop and maintain incident response plans, playbooks, and procedures, conducting regular tabletop exercises and simulations to test and improve response capabilities.
- Security Architecture and Engineering:
- Define and maintain the security architecture and design principles for IT systems, applications, and infrastructure, incorporating security-by-design principles into development processes.
- Collaborate with architecture and engineering teams to evaluate, select, and implement security technologies, tools, and solutions to mitigate risks and enhance security posture.
- Conduct security reviews, assessments, and audits of systems and applications, identifying vulnerabilities and recommending remediation measures.
- Security Awareness and Training:
- Develop and deliver security awareness and training programs for employees, contractors, and stakeholders, promoting a culture of security awareness and compliance.
- Provide guidance and support to squads and chapters on security best practices, secure coding principles, and threat mitigation techniques.
- Monitor and measure the effectiveness of security awareness and training initiatives, adjusting strategies as needed to address evolving threats and risks.
- Security Compliance and Assurance:
- Manage security compliance initiatives, including regulatory compliance assessments, audits, and certifications (e.g., GDPR, ISO 27001, SOC 2).
- Collaborate with internal audit, compliance, and legal teams to ensure adherence to security requirements and contractual obligations.
- Maintain security documentation, evidence, and artifacts to demonstrate compliance with security standards and regulations.
Qualifications:
- Bachelor's degree in Information Security, Computer Science, or a related field; advanced degree or relevant certifications (e.g., CISSP, CISM, CISA) are a plus.
- Proven experience (min 5 years) in information security, with a focus on security strategy, governance, operations, and compliance.
- Strong understanding of security frameworks, standards, and best practices (e.g., NIST Cybersecurity Framework, CIS Controls, OWASP Top 10).
- Experience in leading and managing cross-functional security teams in a dynamic and fast-paced environment.
- Excellent communication, leadership, and stakeholder management skills, with the ability to influence and collaborate effectively at all levels of the organization.
- Strong analytical, problem-solving, and decision-making skills, with a strategic mindset and attention to detail.
Requirements:
- Fluency in English (written and spoken) is required; proficiency in any other European language is a plus.