About this role
About the Role
Why This Role Is Different
· Own security for a global organization
spanning multiple countries and business units.
· Direct access to executive leadership.
· Opportunity to build and mature the
security program.
· Significant autonomy and decision-making authority.
· Broad exposure across cloud platforms,
Microsoft 365, SaaS applications, identity, endpoint security, and
third-party risk.
· Opportunity to influence technology
strategy and security culture.
Key Responsibilities
· Act as the primary owner of cybersecurity
across the organization.
· Manage and govern our MDR provider and
security vendors.
· Coordinate and lead security incident
response activities.
· Maintain and manage the enterprise security
risk register.
· Conduct security reviews and internal
audits across global offices.
· Drive remediation of security risks,
vulnerabilities, and audit findings.
· Review new technologies, vendors, and
business initiatives from a security perspective.
· Support client due diligence requests,
security questionnaires, and audit activities.
· Develop and improve security policies,
standards, and governance processes.
· Lead security awareness and security
improvement initiatives.
· Provide regular risk updates and
recommendations to leadership.
Requirements
What We Are Looking For
· Strong sense of ownership and accountability.
· Passion for cybersecurity and continuous learning.
· Curiosity and an investigative mindset.
· Ability to challenge assumptions and
identify hidden risks.
· Excellent communication and stakeholder
management skills.
· Comfortable operating independently and
driving initiatives forward.
· Ability to balance security requirements
with practical business needs.
· Comfortable building processes, governance,
and structure where little currently exists.
Required Experience
· 5+ years of experience in cybersecurity,
information security, risk management, or related disciplines.
· Experience managing security vendors and
service providers.
· Experience coordinating security incidents
and remediation activities.
· Strong understanding of cloud security,
identity management, endpoint security, email security, and security operations.
· Experience supporting audits, assessments,
and compliance initiatives.
· Strong documentation, organizational, and
project management skills.
Preferred Qualifications
· CISSP, CISM, CRISC, Security+, ISO 27001,
or similar certifications.
· Experience within financial services,
professional services, or regulated industries.
· Experience working with MDR, SIEM,
vulnerability management, and security monitoring programs.
· Familiarity with ISO 27001, NIST, CIS
Controls, SOC 2, and GDPR.
What Success Looks Like
· Establish effective governance of security
vendors and MDR providers.
· Build and maintain an enterprise security
risk register.
· Improve visibility into security risks
across all offices.
· Strengthen incident response and security
governance processes.
· Reduce organizational security risk through
measurable improvements.
· Become the trusted security advisor to leadership.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?