As an IT Security Officer, you will be responsible for the implementation, monitoring, and supervision of day-to-day information security activities within a well-established player in the mobility services industry.You will play a key role in the continuous improvement of information security and cybersecurity policies, as well as in the oversight of the risk assessment process, ensuring the confidentiality, integrity, and availability of data and systems. Your ultimate objective is to protect the organisation's information assets against internal and external threats in a regulated and evolving environment.
Governance & Compliance
- Implement and maintain information security policies and procedures in line with international standards and regulatory frameworks (e.g. ISO 27001, NIST, GDPR, DORA).
- Design, implement, and continuously improve the Information Security Management System (ISMS).
- Oversee and maintain Business Continuity and resilience plans, including back-up testing, recovery procedures, and crisis scenarios.
Risk Management
- Manage Third-Party Risk Assessments, including security evaluations of new vendors and partners.
- Conduct security assessments and risk analyses for internal projects and specific business requests.
- Define, monitor, and follow up on risk mitigation plans.
- Track developments related to threats, vulnerabilities, and emerging technologies to continuously adapt the security strategy.
Security Operations (SecOps)
- Supervise daily security operations and proactive monitoring activities.
- Act as the main coordination point for security services delivered by external providers.
- Oversee incident and data breach management, including investigations and corrective actions.
- Produce security incident reports and ensure proper escalation and follow-up until full resolution.
- Ensure robust controls to preserve data confidentiality, integrity, and availability.
Security Architecture & Secure Development
- Define and implement standards for secure coding and secure architecture design.
- Participate in architecture and governance committees to ensure security requirements are embedded in all projects.
- Work closely with IT, legal, and business teams to integrate security by design and by default.
Training & Awareness
- Design and deliver security awareness programs across the organisation.
- Train employees on best practices, security policies, responsibilities, and secure behaviours.