Security Risk Officer
As a Security Risk Officer within Global Information security (GIS) team, you will focus on security risks across the organization. This will be done in collaboration with members of GIS team, Information Security Officers (ISOs) in the domains (regions, corporate functions and enterprise platforms), as well as security and risk Subject Matter Experts (SMEs) within DLL. This role operates in a dynamic cybersecurity environment where priorities may evolve rapidly. The successful candidate is expected to demonstrate flexibility, adaptability, and a proactive mindset, taking ownership of emerging topics beyond explicitly defined responsibilities when needed.
This role will support GIS in ensuring that security risk management practices are uniformly and appropriately incorporated into DLL.
Day to day:
The Security Risk Officer fulfills the following tasks:
- Conduct Information security risk identification and assessment across various domains and areas
- Keep oversight of and monitor security risk management practices and ensure execution of security risk management across the organization according to policies and procedures.
- Continuously monitor trends across the organization and the threat landscape to anticipate and plan for future impact of Information security risk to DLL
- Constructively engage with ISOs in the domains (regions, corporate solutions and enterprise technology)
- Establish information security risk ownership and accountability within the domains.
- Act as a subject matter expert (SME) on security risk management for the domains.
- Establish periodic reports and dashboards to measure and monitor information security risk practices of the organization
- Continuous improvement of security risk management practices in the organization. This includes updates to existing risk management policies and procedures as well as their implementation
- Stay updated on the latest security threats, trends and technologies
- Proactively identify and take ownership of emerging security risk topics, even if outside the formally defined scope of the role
- Support ad-hoc initiatives, cross-functional efforts, and urgent security matters as required
- Contribute to broader GIS objectives beyond core security risk management activities when needed
All members enjoy:
- Two working days per year volunteering for a local charity.
- Health and Wellness program including healthy food, free health checks, fun health & vitality activities.
- Flexible hours with possibility to work from home
- Career development opportunities: online learning, member development programs.
- Click this link for an overview of all the benefits in your region.
Essentials:
Education, Training & Previous Experience Requirements
- Bachelor or master's in information technology / computer science or related.
- 5+ years of experience working in security risk management, security governance, and optionally security regulatory requirements
- Experience working in a global organization with central and de-central security function
- Certifications (at least one of): CISSP/CISM/CRISC/CISA/CGEIT/CGRC.
- Excellent English verbal and written communication skill
Technical and Business Experience Requirements
- Experience with security risk assessment, monitoring and advice
- Experience with cloud security
- Knowledge on a wide range of security topics like IAM, IDS/IPS, access control systems, PIM, Azure, encryption, PIM
- Experience with reporting and data analysis tools like PowerBI and MS Excel
- Experience with security frameworks and methodologies, such as ISO/IEC 27001 or 27002, NIST Cybersecurity Framework (CSF)
- Experience working with business leaders and enterprise projects
- Experience with using GRC tools (like OneTrust and/or Archer)
- Experience with DevOps, AppSec, Agile, Safe.
Knowledge and Skills Requirements
- Strong communicator and storyteller (active listener, constructive feedback, assertive, adaptive, conflict resolution)
- Demonstrates an ability to challenge, and manage choices
- Strong problem-solving and trouble-shooting skills
- Aptitude for understanding internal organizational environments and their relationship to the external business environment and risks
- Able to effectively analyze risk and review such analysis within the context of business problems
- Strong ability to convey complex security risks in a manner that is easily understood and actionable
- Ability to constructively challenge prevailing thoughts and processes
- Able to consistently, effectively defend ideas and solutions
- Adept at improving outcomes through proactive team coaching and development
- Ability to measure and report on the effectiveness of security risk management program
- Ability to translate security objectives into security risk management policies and procedures
- Ability to align security initiatives with the organization's overall business strategy
Key Behavioral Requirements
- Demonstrates a "can-do" attitude and ownership mindset, proactively driving outcomes
- Comfortable working in ambiguous and evolving environments
- Ability to multitask and reprioritize effectively based on organizational needs
- High level of flexibility and willingness to step outside defined role boundaries when required
- Strong collaboration mindset across teams and disciplines
Choose wellbeing
DLL's wellbeing ambition is to educate, equip and empower members to build connections, manage their mental, emotional, physical and financial wellness and maintain balance between work and the other priorities that make up their lives.
Our four wellbeing categories are as follows:
- Connection – Build meaningful connections with other DLL members
- Health – Manage mental, emotional and physical health
- Finance – Provide learning opportunities to help members achieve personal financial health
- Lifestyle – Maintain balance between work and life priorities
These are the things that matter to our members and the wellbeing of our members matters to DLL