Client is seeking a CISO / Chief Information Security Officer to strengthen the group’s strategic information security work and ensure that digital security risks are addressed as an integrated part of business governance. Cyber risk and digital dependencies are key risk drivers, and the role focuses on developing group-wide governance, requirements, and frameworks for cyber and information security, with an emphasis on a systematic, end-to-end, risk-based approach.
The position sits in the staff function and reports to the security director. It is strategic and group-wide, supporting holistic governance, clear requirement setting, strong risk understanding, and relevant follow-up across the business. Working closely with technical and operational security environments, the CISO acts as a driver of common direction, requirements, and priorities—without replacing day-to-day security capabilities—while ensuring identity and access governance, vendor access and third-party dependencies are managed strategically.
Key responsibilities include setting the strategic direction for cyber and information security; developing and maintaining group-wide governance systems, requirements, and standards for information security including IT and OT security; establishing frameworks for cyber risk management, control, maturity, and prioritization of security measures; defining principles for security architecture, resilience, recovery, logging, detection, and response; and producing governance reporting and cyber reporting for leadership and relevant governance forums. The ideal candidate has relevant higher education in information security/cybersecurity, solid experience in strategic cyber and information security in larger or complex organizations, strong understanding of governance, internal control, risk management, and security leadership, and the ability to translate complex issues into clear requirements and decision support, with strong communication and relationship-building skills across technical, operational, governmental, and business stakeholders.