PURPOSE & IMPACT: This role is known for …
Responsible for managing and mitigating security risks, ensuring security posture aligns with regulatory obligations, and industry standards. Developing and maintaining an effective information security governance framework, by maintaining cybersecurity policies, standards and guidelines aligned to Nomad's enterprise risk management framework and overall strategy.
Manage, evaluate, and support the documentation, validation, assessment, and authorisation processes necessary to assure that existing and new systems, suppliers and processes meet the organisation's cybersecurity and risk requirements.
Working with internal and external stakeholders to conduct risk assessments and reporting to help identify related cybersecurity risks and determine appropriate controls.
We need someone who….
- Can communicate at all levels and with the ability to summarise and present complex concepts to senior leadership
- Is a confident presenter and communicator with an ability to explain complex topics clearly to a non-technical audience
- Is experienced in operating a risk management framework across multiple entities and territories, including risk appetite and impact / likelihood calibration
- Has familiarity with regulations and standards such as ISO27001, NIST CSF, NIS2, COBIT, ITIL, GDPR, and SOC2, including developing and maintaining frameworks, policies and guidance, and implementation and monitoring strategies
- Can work independently and as part of a team in a fast-paced dynamic environment
- Has programme and project management experience, including the ability to assess and assure the current state, establish and lead a resulting programme of enhancements
- Can collaborate with colleagues across multiple locations and time zones where required
- Has experience in implementing and executing the Third-Party Risk Management (TPRM) strategy and programme