Sr. Information Security Officer, Managing Director

vor 2 Wochen


Frankfurt am Main, Deutschland State Street Vollzeit

State Street Bank International GmbH (‘SSBI’) seeks to recruit a Senior Information Security Officer, Managing Director (Sr. ISO) to improve the overall protection of SSBI, its customers and partners from an evolving and sophisticated threat landscape.

The SSBI Sr. ISO reports to the SSBI Chief Governance Officer and closely cooperates with the SSBI Head of IT and the wider management team. Key stakeholders include:
- Information Security Officers- Business and Functional Leaders- Cyber Fusion Center- Cyber Architecture & Security Engineering- First Line Risk and Controls- 3LOD Partners

The SSBI Senior Information Security Officer (Sr. ISO) will drive compliance with GCS security controls in their business unit/region/country/functional area which they represent. The Sr. ISO will serve as a trusted and influential information security advisor to senior-level business management in a large organization.

The SSBI Sr. ISO roles and responsibilities are defined under five domain areas with the following objectives and specific responsibilities for each domain:
Information Security program development and management

Objective: Develop and manage the information security program within the business unit to drive compliance with information security supplemental requirements and reduce risk- Identify senior business management and build relationship to ensure effective information security governance is established - strategy with goals and objectives, strategic alignment, roles and responsibilities, performance measurement, outcomes- Understand context of the business unit - internal and external issues, organizational structure, organizational drivers, geography, strategy, legal and regulatory requirements- Develop an information security strategy aligned to the business unit strategy, defining the goal of information security, objectives and the desired state- Develop and maintain an information security policy, associated standards and procedures- Define the activities to be performed within the information security program, and assign ownership- Establish relevant metrics to evaluate the effectiveness of the information security program- Monitor and review information security program, to ensure continual development and improvement

Risk and Incident Management

Objective: Manage information security risk and incident response, from assessment through mitigation of risk, and throughout the entire lifecycle of incident management- Support the business unit in identifying high risk/critical processes and technology, ensuring they are inventoried, ownership is assigned and that regular reviews are carried out-
- Integrate information security risk review into lifecycle processes such as Incident Management, ASAP, ISRMP, TPRM, BCP, SDLC, Change and Project management- Attend risk and technology committees. Identifying, documenting and communicating Information Security risks. If risk and technology committees do not exist, work with the business unit to establish forums for discussion- Act as Information Security representative during regulatory and statutory engagements-
- Participate in security incident response program representing the business area to detect and respond to incidents in a timely manner. Post incident, provide support to the business to identify control gaps.

Measurement

Objective: Develop metrics for measuring the information security program and related activities- Establish and agree on appropriate reporting with senior management to give a view of the state of information security throughout the business unit- Complete the quarterly ISO maturity assessment to provide a clear understanding of the maturity of the implementation of the ISO framework- Identify failed business controls and provide support on remediation to drive compliance with information security supplemental requirements- Create development plans for all information security resources to ensure continual improvement

Communication

Objective: Establish internal and external communication channels that support information security- Report on potential business impact of proposed new information security supplemental requirements, and of security risks from new business initiatives- Report significant changes in information security risk to appropriate level of management for review on both a periodic and an event driven basis- Provide regular communication on threat intelligence relevant to the business unit, and issue guidance on supporting controls- Report on impact or potential impact of security incidents to senior management

Education

Objective: Maintain up to date knowledge of evolving information security threat landscape and provide information security awareness, training and education to key stakeholders- Design and develop an interactive and engaging program for information security awareness and training, which is relevant to the business unit and encompasses the current threat landscape

Furthermore


  • Managing Director

    vor 2 Wochen


    Frankfurt am Main, Deutschland techculture GmbH Vollzeit

    Zur Ausgründung einer Business-Unit eines erfolgreich agierenden IT-Dienstleisters suchen wir zum nächstmöglichen Zeitpunkt einen Managing Director (m/w/d) Cyber Security. Gesucht wird eine Leader-Persönlichkeit (m/w/d) mit Herzblut für das Thema Cyber Security und ausgeprägten unternehmerischen Fähigkeiten. Die Verantwortung erstreckt sich über...


  • Frankfurt am Main, Deutschland CMC Markets Vollzeit

    You will be the Information Security Officer for the CMC Markets GmbH organisation, part of CMC Markets Group. CMC Markets GmbH has the primary local responsibility for CMC Markets across Europe, and the relationship with BAFIN as the regulatory oversight. In this role you will be the European contact point for all Information Security issues, ensuring that...


  • Frankfurt am Main, Hessen, Deutschland AllUnity GmbH Vollzeit 80.000 € - 120.000 € pro Jahr

    Location: Germany based, preferably in Frankfurt am MainAbout UsAllUnity is a joint venture between DWS Group, Flow Traders, and Galaxy Digital, operating as a BaFin-regulated e-money institution. The company's mission is to create a new infrastructure for Europe's digital financial markets by issuing a regulated euro stablecoin. AllUnity positions itself as...


  • Frankfurt am Main, Hessen, Deutschland AllUnity Vollzeit 80.000 € - 120.000 € pro Jahr

    Location Germany based, preferably in Frankfurt am MainAbout Us AllUnity is a joint venture between DWS Group, Flow Traders, and Galaxy Digital, operating as a BaFin-regulated e-money institution. The company's mission is to create a new infrastructure for Europe's digital financial markets by issuing a regulated euro stablecoin. AllUnity positions itself...


  • Frankfurt am Main, Hessen, Deutschland AllUnity Vollzeit 80.000 € - 120.000 € pro Jahr

    Location:Germany based, preferably in Frankfurt am MainAbout UsAllUnity is a joint venture between DWS Group, Flow Traders, and Galaxy Digital, operating as a BaFin-regulated e-money institution. The company's mission is to create a new infrastructure for Europe's digital financial markets by issuing a regulated euro stablecoin. AllUnity positions itself as...


  • Frankfurt am Main, Deutschland Ankura Vollzeit

    Ankura is a team of excellence founded on innovation and growth. Managing Director, Performance Improvement Managing Director, Performance Improvement

  • Managing Director

    vor 2 Wochen


    Frankfurt am Main, Deutschland BitGo Vollzeit

    **BitGo - Managing Director (**_Geschäftsführer Markt)_** of BitGo Deutschland GmbH** BitGo is the leader in custody and security solutions and is the largest independent digital asset custodian in the world. Founded in 2013, BitGo is the first digital asset company to focus exclusively on serving institutional clients. In 2018, it launched BitGo Trust...


  • Frankfurt am Main, Hessen, Deutschland luxsearch® Vollzeit 60.000 € - 90.000 € pro Jahr

    Eine Fondsgesellschaft sucht in der Second Line of Defense. Fokus auf moderner Identitäts- und Zugriffsverwaltung – konzeptionell, sicherheitsnah. Ideal für IT-Spezialisten, die Azure, Entra ID und IAM-Strategien gestalten wollen, statt nur Tickets abzuarbeiten.Was du bekommstBis zu € Jahresgehaltstarkes GesamtpaketBis zu 4 Tage HomeofficeBonus auf...


  • Frankfurt am Main, Hessen, Deutschland Page Executive Vollzeit 120.000 € - 240.000 € pro Jahr

    Opportunity to enter the Crypto industry as Managing Director (m/f/d)Exciting leadership role at the forefront of financial innovationAbout Our ClientMy client is a Crypto company which is looking for a Managing Director Back Office (m/f/d), based in Frankfurt or ready to regularly commute. A direct professional background in the Crypto sector is NOT a...

  • Managing Director

    Vor 3 Tagen


    Frankfurt am Main, Deutschland Club Med Resort Vollzeit

    As Managing Director for Germany, you will be responsible for: Building and developing the country strategy. Managing country Sales contribution and developing Club Med Brand and market shares. Focusing on development & local expertise (market & customers insight) Developing the country team. Missions: - Full responsibility of the P&L Manage country...