Sr. Information Security Officer, Managing Director

Vor 5 Tagen


Munich, Deutschland State Street Corporation Vollzeit

State Street Corporation Munich, GermanyPosted 16 hours ago Permanent Competitive
- Sr. Information Security Officer, Managing Director
- State Street Bank International GmbH ('SSBI') seeks to recruit a Senior Information Security Officer, Managing Director (Sr. ISO) to improve the overall protection of SSBI, its customers and partners from an evolving and sophisticated threat landscape.- The SSBI Sr. ISO reports to the SSBI Chief Governance Officer and closely cooperates with the SSBI Head of IT and the wider management team. Key stakeholders include:
- Information Security Officers
- Business and Functional Leaders
- Cyber Fusion Center
- Cyber Architecture & Security Engineering
- First Line Risk and Controls
- 3LOD Partners

The SSBI Senior Information Security Officer (Sr. ISO) will drive compliance with GCS security controls in their business unit/region/country/functional area which they represent. The Sr. ISO will serve as a trusted and influential information security advisor to senior-level business management in a large organization.
- The SSBI Sr. ISO roles and responsibilities are defined under five domain areas with the following objectives and specific responsibilities for each domain:
**Information Security program development and management**
Objective: Develop and manage the information security program within the business unit to drive compliance with information security supplemental requirements and reduce risk- Identify senior business management and build relationship to ensure effective information security governance is established - strategy with goals and objectives, strategic alignment, roles and responsibilities, performance measurement, outcomes
- Understand context of the business unit - internal and external issues, organizational structure, organizational drivers, geography, strategy, legal and regulatory requirements
- Develop an information security strategy aligned to the business unit strategy, defining the goal of information security, objectives and the desired state
- Develop and maintain an information security policy, associated standards and procedures
- Define the activities to be performed within the information security program, and assign ownership
- Establish relevant metrics to evaluate the effectiveness of the information security program
- Monitor and review information security program, to ensure continual development and improvement

**Risk and Incident Management**
Objective: Manage information security risk and incident response, from assessment through mitigation of risk, and throughout the entire lifecycle of incident management- Support the business unit in identifying high risk/critical processes and technology, ensuring they are inventoried, ownership is assigned and that regular reviews are carried out
- Integrate information security risk review into lifecycle processes such as Incident Management, ASAP, ISRMP, TPRM, BCP, SDLC, Change and Project management
- Attend risk and technology committees. Identifying, documenting and communicating Information Security risks. If risk and technology committees do not exist, work with the business unit to establish forums for discussion
- Act as Information Security representative during regulatory and statutory engagements
- Participate in security incident response program representing the business area to detect and respond to incidents in a timely manner. Post incident, provide support to the business to identify control gaps.

**Measurement**
Objective: Develop metrics for measuring the information security program and related activities- Establish and agree on appropriate reporting with senior management to give a view of the state of information security throughout the business unit
- Complete the quarterly ISO maturity assessment to provide a clear understanding of the maturity of the implementation of the ISO framework
- Identify failed business controls and provide support on remediation to drive compliance with information security supplemental requirements
- Create development plans for all information security resources to ensure continual improvement

**Communication**
Objective: Establish internal and external communication channels that support information security- Report on potential business impact of proposed new information security supplemental requirements, and of security risks from new business initiatives
- Report significant changes in information security risk to appropriate level of management for review on both a periodic and an event driven basis
- Provide regular communication on threat intelligence relevant to the business unit, and issue guidance on supporting controls
- Report on impact or potential impact of security incidents to senior management

**Education**
Objective: Maintain up to date knowledge of evolving information security threat landscape and provide information security awareness, training and education to key stakeholders- Design and develop an interactive



  • Munich, Deutschland FNZ Vollzeit

    Role Description At FNZ, our purpose is to make wealth management more accessible, bringing easier, fairer and more inclusive solutions to people worldwide. Here in the Global Information Security team, we are on a mission to embed cyber resilience across FNZ, protecting the platforms that support investment solutions for over 20 million people. We are...


  • Munich, Deutschland Findr Vollzeit

    Director Cyber Security – Munich - €175kA leading European fintech group is growing its digital and crypto operations — and they’re looking for a Director of Cyber Security to take ownership of security strategy across their trading and digital asset platforms.This is a senior role reporting directly to the CTO. You’ll lead a talented Cyber...


  • Munich, Deutschland JetBrains Vollzeit

    Our Munich office has an immediate opening for a Personal Assistant to Managing Director. This is a great opportunity to become part of the expanding JetBrains family and build yourself an exciting future with us. **Responsibilities**: - Acting as the first point of contact and taking the load from the managing director: dealing with correspondence and...


  • Munich, Deutschland Zync Group Vollzeit

    **Information Security Officer - Munich (Remote - In Office 1 day per week) - €110K** Do you want to work for a company that takes the future into its own hands when it comes to creating the very best technology? Well, today is your lucky day because I'm currently hiring for a role within a HUGE Tech company that does exactly this! They are constantly...


  • Munich, Bayern, Deutschland Nemetschek Group Vollzeit 60.000 € - 120.000 € pro Jahr

    Nemetschek are one of Germany's largest software companies and a true pioneer in digital transformation for the architecture, engineering, construction, operations and media industries. With a remarkable growth trajectory — delivering double-digit revenue growth year after year and recently reaching close to €1 billion in annual revenues — Nemetschek...


  • Munich, Deutschland Zync Group Vollzeit

    **URGENT HIRE: Junior Information Security Officer - Munich / Home Office (up to 50%) - Up To €100K + Amazing Company benefits** I'm hiring a Junior Information Security Officer on behalf of an independent and innovative financial service provider with strong substance and growth. They're one of Germany's market leaders with over 1,000 sales partners &...


  • Munich, Deutschland Zync Group Vollzeit

    **URGENT HIRE: Junior Information Security Officer - Munich / Home Office (up to 50%) - Up To €100K + Amazing Company benefits** *** I'm hiring a Junior Information Security Officer on behalf of an independent and innovative financial service provider with strong substance and growth. They're one of Germany's market leaders with over 1,000 sales partners...


  • Munich, Deutschland Zync Group Vollzeit

    I’m hiring for an Expert in Information Security on behalf of an international company that makes a major difference to greater safety and energy efficiency on roads & rails worldwide. They are a global market leader with thousands of employees globally! - With a drive for keeping their employees happy, they focus on providing fantastic employee benefit...


  • Munich, Bayern, Deutschland Schulz & Cie. Consulting GmbH Vollzeit 80.000 € - 120.000 € pro Jahr

    Supporting the management in defining and adapting the information security guideline and advising on all information security issuesDrawing up information security guidelines and, if necessary, other relevant regulationsControls for compliance with the information security guidelines and monitoring of the specifications vis-à-vis IT service...


  • Munich, Deutschland KBR Vollzeit

    **Title**: LCV EUCOM OEW Germany: Sr. Security Technician - Contingency **Job Overview**: Responsible for personnel engaged in the Physical Security function for the organization that includes monitoring the systems associated with the flow of personnel and vehicular traffic, personnel/visitor security clearances, management of loss prevention and detection...