Job Detail

Director of Security Operations

Inseriert am: 21.09.2018


Director of Security Operations

Lombard Odier recherche une personne susceptible de remplir ce cahier des charges :

Métier : Spécialiste Sécurité Informatique
Bureau : Genève
Niveau d'expérience : Senior
Type de contrat : CDI


To ensure that Bank Lombard Odier & Co Ltd manages information security risk within its IT environment and operates in a compliant, consistent and secure manner – safeguarding both Bank Lombard Odier & Co Ltd and its customers’ data and services.


Your mission:



  • Manage a team of 4-6 Security Subject matter Experts (SMEs) – prioritise demand, address individual development needs and skills gaps to deliver effective in-house security capabilities and drive achievement of objectives (at individual and team levels);

  • Lead planning, successful delivery and operationalisation of tactical and strategic CISO roadmap initiatives - working in partnership with the Head of Security Architecture and Engineering;

  • Provide risk consulting and security advisory support to the IT project teams – manage security work-streams for IT projects ensuring that legislative and InfoSec risks are considered to safeguard Lombard Odier and its customers’ data through security assessments with risk ratings, options and recommendations;

  • Manage report and coordinate activities across IT areas to address audit actions within agreed timelines.

  • Maintain Cyber Response Plans in line with emerging threats and security capabilities – direct periodic Cyber Response planning and exercises and improvements across the business units (working with the Head of Crisis Management);

  • Accountable for the effective cyber monitoring and response against threats and risks to LO’s assets – manage 24x7 SOC activities and incident handling, threat intelligence, vulnerability management and security awareness training;

  • Manage the delivery of Ethical Hacking engagements in line with the Security Testing Strategy and schedule as well as established security testing principles for applications, systems and network infrastructure – mange remediation activities and define improvement plans to inform the security roadmap;

  • Lead, develop and implement processes and supplier security assurance ;

  • Develop and maintain Regulatory Compliance & Policies/Standards. Set and manage strategic development and tactical implementation of compliance plans. Manage execution of plans and actions;

  • Deliver monthly risk scorecard and reporting against established InfoSec metrics;

  • Deliver Security Roadmap scorecard for project delivery against scope, dates and budget.


 


Desired profile :



  • 10+ years of professional experience in InfoSec and managing/developing InfoSec teams within financial services;

  • Certifications in areas of specialty; CISM, CISSP, CISA, preferred;

  • Good management skills and ability to motivate a direct team with experience in managing remote teams and working across geographic boundaries;

  • Demonstrable engagement on InfoSec matters with C-suite execs, maintaining strong relationships and influencing decisions by senior colleagues;

  • Strong technical skills and IT knowledge, InfoSec concepts, trends and practices, Risk Management, IT Governance and Compliance and, Regulatory Frameworks;

  • Must have experience of being able to cope with multiple, significant issues in parallel;

  • Ability to investigate, question and interpret security risks within all areas of LO’s business and drive decisions – often based on uncertainty and emerging facts (for example, security breaches);

  • Experience of driving, leading and delivering key initiatives, processes and policies that have potentially wide reaching implications for LO (e.g. RBAC);

  • Utilises innovative and new thinking to develop plans and initiatives, rather than rely on precedent;

  • Very strong communication and presentation skills. Ability to translate IT security language into business language and tailor communications to senior level management and business stakeholders;

  • Good understanding of IT Compliance and Audit frameworks and best practices;

  • Written and oral English language proficiency, fluent in French;

  • Ability to take ownership of tasks from the beginning through to conclusion;

  • Meticulous, proactive and able to multi-task; Resident in Switzerland or willing to relocate to Switzerland



Si vous vous reconnaissez dans cette description, nous nous réjouissons de recevoir votre dossier qui sera traité avec la plus stricte confidentialité.

Réf. : 629 / MII