大手証券会社 Regional Chief Information Security Officer (CISO)の求人
求人ID:1387984
募集終了
転職求人情報
職種
Regional Chief Information Security Officer (CISO)
ポジション
Regional Chief Information Security Officer (CISO)
おすすめ年齢
20代
30代
40代
50代以上
年収イメージ
年収イメージ:1200万円〜2000万円以上(経験・能力を考慮の上当社規定により決定)
仕事内容
・Global Collaboration: Work closely with the Group CISO to support and implement global security initiatives and policies.
・Strategic Leadership: Develop, implement, and monitor a strategic, comprehensive information security and risk and control management program while maintaining and enhancing an information security management framework and all related policies and processes - according to the group strategy and roadmap. Protect the company while reducing risk, fulfilling compliance, audit and regulatory requirements. Together with planning for budget associated to security activities in Japan.
・Partnership Collaboration: Liaise with relevant business units (such as Internal Audit, Law, Finance, Safety & Security, Risk Management, HR teams), and external agencies as needed to ensure that the company maintains a strong security posture. Partner closely with all stakeholders, including business stakeholders, to identify business specific security requirements and implement them appropriately.
・Advisory Role: Provide leadership and guidance on information security topics, advising and collaborating on security processes, business continuity, and disaster recovery plans. Assist with overall technology planning, providing a current knowledge and future vision of technology and systems. Provide appropriate security controls for the business and Information Technology to ensure security policies, processes, and solutions are implemented on new products, services, and systems.
・Risk Management: Identify, assess, and mitigate information security risks across the region. Conduct regular risk assessments and audits.
・Policy Development: Create and enforce security policies, standards, and procedures to ensure compliance with regulatory requirements and best practices. Drive information security policies, standards, guidelines and oversee the dissemination of security policies and practices; identify knowledge gaps to increase the awareness of relevant information security practices across all the company’s entities.
・Security Governance: Lead governance, risk and control activity of the company Japan entity by implementing business centric risk management. Manage third party stakeholders and associated risks.
・Compliance: Ensure compliance with regional and international regulations, including data protection laws and industry standards.
・Security Awareness: Ensure that the company Japan entity has a healthy security culture with appropriate understanding of culture and language. Develop and implement security awareness programs to educate employees about security best practices and emerging threats. Lead the key security awareness events in the Japan region.
・Reporting: Provide regular reports on the status of the regional information security program to senior management and the Group CISO.
・Strategic Leadership: Develop, implement, and monitor a strategic, comprehensive information security and risk and control management program while maintaining and enhancing an information security management framework and all related policies and processes - according to the group strategy and roadmap. Protect the company while reducing risk, fulfilling compliance, audit and regulatory requirements. Together with planning for budget associated to security activities in Japan.
・Partnership Collaboration: Liaise with relevant business units (such as Internal Audit, Law, Finance, Safety & Security, Risk Management, HR teams), and external agencies as needed to ensure that the company maintains a strong security posture. Partner closely with all stakeholders, including business stakeholders, to identify business specific security requirements and implement them appropriately.
・Advisory Role: Provide leadership and guidance on information security topics, advising and collaborating on security processes, business continuity, and disaster recovery plans. Assist with overall technology planning, providing a current knowledge and future vision of technology and systems. Provide appropriate security controls for the business and Information Technology to ensure security policies, processes, and solutions are implemented on new products, services, and systems.
・Risk Management: Identify, assess, and mitigate information security risks across the region. Conduct regular risk assessments and audits.
・Policy Development: Create and enforce security policies, standards, and procedures to ensure compliance with regulatory requirements and best practices. Drive information security policies, standards, guidelines and oversee the dissemination of security policies and practices; identify knowledge gaps to increase the awareness of relevant information security practices across all the company’s entities.
・Security Governance: Lead governance, risk and control activity of the company Japan entity by implementing business centric risk management. Manage third party stakeholders and associated risks.
・Compliance: Ensure compliance with regional and international regulations, including data protection laws and industry standards.
・Security Awareness: Ensure that the company Japan entity has a healthy security culture with appropriate understanding of culture and language. Develop and implement security awareness programs to educate employees about security best practices and emerging threats. Lead the key security awareness events in the Japan region.
・Reporting: Provide regular reports on the status of the regional information security program to senior management and the Group CISO.
必要スキル
・Bachelor’s Degree or Advanced degree
・10+ years of leadership experience in large, complex and global organizations.
・Broad experience across business and infrastructure disciplines as well as regulatory interaction including regulatory portfolio management, internal & external audit facilitation, performance and risk assessment, and technology & operational service delivery at both Global and Regional level.
・Experience evaluating and designing business and operational measures, managing complex change agenda, and driving strategy formulation and service delivery.
・Demonstrated executive experience leading a relevant business of similar size and complexity, including significant leadership across multiple locations as well as non-staff resource allocation, and leading through influence in a matrixed organization.
・Information security experience, possessing a strategic and operational understanding of risk frameworks as well as regional trends and best practices for managing information security within large, complex and global organizations.
・Ability to translate complex and technical security language and concepts into business risks and business cases.
・Ability to communicate with knowledge and credibility to all levels of management, including appropriate management committees, offering well considered information security solutions and recommendations.
・Demonstrated ability to develop strong relationships with regional external oversight and/or regional regulators.
・Japanese and English proficiency is critical as the position requires involvement with the global heads of security functions located in various regions.
・10+ years of leadership experience in large, complex and global organizations.
・Broad experience across business and infrastructure disciplines as well as regulatory interaction including regulatory portfolio management, internal & external audit facilitation, performance and risk assessment, and technology & operational service delivery at both Global and Regional level.
・Experience evaluating and designing business and operational measures, managing complex change agenda, and driving strategy formulation and service delivery.
・Demonstrated executive experience leading a relevant business of similar size and complexity, including significant leadership across multiple locations as well as non-staff resource allocation, and leading through influence in a matrixed organization.
・Information security experience, possessing a strategic and operational understanding of risk frameworks as well as regional trends and best practices for managing information security within large, complex and global organizations.
・Ability to translate complex and technical security language and concepts into business risks and business cases.
・Ability to communicate with knowledge and credibility to all levels of management, including appropriate management committees, offering well considered information security solutions and recommendations.
・Demonstrated ability to develop strong relationships with regional external oversight and/or regional regulators.
・Japanese and English proficiency is critical as the position requires involvement with the global heads of security functions located in various regions.
就業場所
就業形態
正社員
企業名
大手証券会社
企業概要
国内大手証券会社
企業PR
日本をベースとしたグローバル金融機関。インベストメント・バンキング、グローバル・マーケッツ、アセット・マネジメント、リテールビジネス等を行っています。
業務カテゴリ
組織カテゴリ
備考
情報セキュリティ(自社向け)の求人情報
日系金融機関の求人情報
リスクマネジメントの求人情報
転職体験記
- 製造業に対する実行支援を得意とするエンジニアリング企業へ(50代/男性/私立大学卒)
- 金融機関のリスク管理部門にこだわって、グローバルバンクへ(30代/男性/国立大学院卒)
- 希望の職種を限定し、成長中のIT企業へ(50代/男性/国立大学院卒)
- これまでの経験を活かして、サイバーセキュリティ企業へ(50代/男性/私立大学卒)
- 希望する職種にこだわって、大手外資系金融機関へ(30代/男性/国立大学院卒)
- 希望のミドル部門、かつ希望以上の年収の条件で日系信託銀行に内定(30代/男性/国立大学卒)
- 国内系資産運用会社から、国内最大金融グループ系PEファンド運用会社へ(50代/男性/私立大学卒)
- これまでの業務経験を活かして、総合セキュリティサービス企業へ(30代/男性/大学校卒)
- 今までの実務キャリアを活かして、シリコンバレーに本社を置くベンチャーキャピタルへ(60代/女性/海外大学院卒)