信息安全部门及企业风险管理主管
Head of Information Security & Enterprise Risk Management
职位职责
信息安全部门及企业风险管理负责人是高级管理人员,负责设计、管理并持续强化跨复杂多业务、多技术环境的企业级网络安全、信息风险和技术风险框架。
该职位需要在高级网络安全架构、全球监管合规和大规模风险管理方面具备深厚的专业知识。
主要职责
1. 企业信息安全领导
- 设计并主导符合全球标准(ISO、NIST、COBIT)及不断演变的威胁环境的企业级信息安全战略
- 在本地部署、云、混合、OT 和 IoT 环境中建立并管理安全架构
- 作为网络风险接受、升级和缓解的最终决策者
2. 网络风险与威胁管理
- 领导高级网络威胁情报、攻击模拟和事件响应计划
- 监督安全运营中心(SOC)模型,包括 SIEM、SOAR、威胁狩猎和法医调查
- 领导重大网络事件、勒索软件事件或数据泄露的危机响应
3. 企业风险管理(技术和数字风险)
- 将技术风险、网络风险、数据风险和第三方风险整合到更广泛的企业风险管理(ERM)框架中
- 进行定量网络风险评估(例如 FAIR 方法论)
- 向董事会和执行委员会展示风险情景和财务影响建模
4. 监管、合规与治理
- 确保符合全球和跨境法规,包括:
- GDPR、ISO 27001/27701
- NIST CSF、PCI-DSS
- 行业特定的网络法规(金融、基础设施、公用事业、房地产等)
- 主导与信息安全和技术风险相关的内部和外部审计
- 作为网络和 IT 风险事项的主要监管和审计对接人
5. 第三方与供应链风险
- 建立供应商网络风险、云服务提供商、MSP 和海外合作伙伴的治理机制
- 监督尽职调查、合同安全条款和持续监控计划
6. 领导力与能力建设
- 组建并培养一支高度专业化的安全与风险团队(安全架构师、GRC 专家、SOC 分析师)
- 开发长期的网络安全能力提升计划
- 为首席执行官、董事会和集团高管提供可信的顾问建议
所需资格(高度专业化)
教育背景
查看英文原文
Role Purpose
The Head of Information Security & Enterprise Risk Management is a senior executive responsible for designing, governing, and continuously strengthening an enterprise-wide cyber security, information risk, and technology risk framework across a complex, multi-business, multi-technology environment.
This role requires deep specialization in advanced cyber security architecture, global regulatory compliance, and large-scale risk governance.
Key Responsibilities
1. Enterprise Information Security Leadership
- Design and own the enterprise-wide information security strategy, aligned with global standards (ISO, NIST, COBIT) and evolving threat landscapes
- Establish and govern security architecture across on-premise, cloud, hybrid, OT, and IoT environments
- Act as the final authority on cyber risk acceptance, escalation, and mitigation
2. Cyber Risk & Threat Management
- Lead advanced cyber threat intelligence, attack simulation, and incident response programs
- Oversee Security Operations Center (SOC) models, including SIEM, SOAR, threat hunting, and forensic investigations
- Lead crisis response for major cyber incidents, ransomware events, or data breaches
3. Enterprise Risk Management (Technology & Digital Risk)
- Integrate technology risk, cyber risk, data risk, and third-party risk into the broader ERM framework
- Conduct quantitative cyber risk assessments (e.g., FAIR methodology)
- Present risk scenarios and financial impact modeling to the Board and Executive Committee
4. Regulatory, Compliance & Governance
- Ensure compliance with global and cross-border regulations, including:
- GDPR, ISO 27001/27701
- NIST CSF, PCI-DSS
- Industry-specific cyber regulations (financial, infrastructure, utilities, real estate, etc.)
- Lead internal and external audits related to information security and technology risk
- Serve as the primary regulatory and auditor counterpart for cyber and IT risk matters
5. Third-Party & Supply Chain Risk
- Establish governance for vendor cyber risk, cloud service providers, MSPs, and offshore partners
- Oversee due diligence, contract security clauses, and continuous monitoring programs
6. Leadership & Capability Building
- Build and mentor a highly specialized security and risk team (security architects, GRC experts, SOC analysts)
- Develop long-term cyber capability uplift programs
- Serve as trusted advisor to CEO, Board, and Group Executives
Required Qualifications (Highly Specialized)
Education
- Bachelors Degree in Computer Science, Cybersecurity, Information Systems, or Engineering
- Masters Degree in Cybersecurity, Information Assurance, Risk Management, or related field (strongly preferred)
Mandatory Global Certifications
Candidates must possess multiple of the following:
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- ISO 27001 Lead Implementer / Lead Auditor
- Cloud Security Certifications (CCSP, AWS/Azure Security Specializations)
Experience Requirements
- 15+ years of progressive experience in:
- Information Security
- Cyber Risk Management
- Enterprise Technology Risk
- Minimum 7–10 years in a regional or global leadership role
- Proven leadership across large, complex organizations (multi-entity, multi-system, multi-jurisdiction)
The role requires hands-on experience in:
- Designing enterprise-scale cyber security programs across:· Cloud, on-premise, hybrid, OT, and legacy systems
- Leading major cyber incident response at enterprise or regional level
- Implementing global security frameworks across multiple countries
- Presenting cyber risk in financial and strategic terms to Boards
- Managing cross-border data privacy and regulatory compliance
Behavioral & Leadership Competencies
- Board-level gravitas and executive presence
- Ability to translate deep technical risk into business language
- Strong crisis leadership and decision-making under pressure
- Proven mentor and builder of local capability
Originally posted on Himalayas