Overview : WELCOME TO SITA We're the team that keeps airports moving, airlines flying smoothly, and borders open. Our tech and communication innovations are the secret behind the success of the world’s air travel industry. You'll find us at 95% of international hubs. We partner closely with over 2,500 transportation and government clients, each with their own unique needs and challenges. Our goal is to find fresh solutions and cutting-edge tech to make their operations run like clockwork. Want to be a part of something big? Are you ready to love your job? The adventure begins right here, with you, at SITA.
ABOUT THE ROLE & TEAM
Supporting the cyber security risk management Team Leader, the Senior Cybersecurity Risk Advisor will contribute to IT risk management practice within SITA EISO team by maintaining and enhancing the cybersecurity operational risk management framework. As part of the second Lines of Defense (2LoD), the Senior Cybersecurity Risk Advisor will support business front lines (1LoD) risks & controls self-assessment capability and provide objective review to business lines to develop acceptable risk treatment plans, monitor risk mitigation execution progress and reporting to steering committees.
WHAT YOU WILL DO
- Reviewing and improving the operational risk management framework to ensure that it is user-friendly and adds the maximum value for the organization and its management.
- Supporting the work of the governing body and senior managers in relation to operational risk (e.g., providing advice, guidance, expert opinion, etc.).
- Supporting the activities of the risk committee or equivalent, and monitoring the organization's operational risk profile and escalating any concerns about control weaknesses or exposures that exceed agreed appetite or tolerance limits.
- Working with risk owners to ensure that operational risk templates and procedures are implemented correctly (e.g., providing training, coaching, etc.).
- Maintain and improve the third-party risk management framework through its lifecycle, which includes the onboarding, ongoing monitoring, and offboarding requirements.
- Support the cybersecurity exception handling process, including the objective review of the risk owner progress to achieve compliance with SITA policies and standards.
- Support risk management KPIs / KRIs identification, trends analysis, and reporting.
- Document key findings, analysis, and recommendations in clear and concise reports for both technical and non-technical stakeholders.
- Navigate and work effectively across a complex, geographically dispersed organization.
Qualifications :
ABOUT YOUR SKILLS
- 5 to 10 years of information system / cybersecurity risk and control management experience, including risk identification, analysis, response, and remediation.
- Relevant certification desired: CISA, CISM, CISSP, CIA, CIPP, or related.
- Practical experience of assessing risks associated with third-party suppliers and reviewing assurance documents relating to security and IT controls provided by third parties (e.g., ISO 27001, SOC2 certifications, etc.).
- Practical experience of managing an IT exception handling process.
- Ability to influence and engage with risk owner and senior management.
- Ability to adapt quickly to changing priorities and demands.
- Demonstrate good learning attitude and attention to detail.
- Have good communication skills, team player and a continuous improvement mindset.
- Ability to communicate in a clear, concise, and persuasive manner to all levels of audience.
- University degree in computer science, management information system, business administration or a related field of study required.
NICE-TO-HAVE
- Experience in IT contract review is considered an asset.
- Working knowledge and/or hands-on experience with information security policy, procedures and standard development and improvement.
- Experience with GRC (Governance, Risk and Compliance) tools such as OneTrust, ServiceNow, Archer is considered an asset.
SITA’s workplace is all about diversity, many different countries and cultures are represented in our workforce. We collaborate in our impressive offices, embracing a hybrid work format. As part of our global benefits, we offer:
- Flex Week: Work from home up to 2 days/week (depending on your Team's needs).
- Flex Day: You may wish to flex your arrival time at the office to beat rush hours or leave earlier for personal commitments. We encourage open communication with your manager about your needs and routine.
- Flex-Location: Enjoy up to 30 workdays of benefits, anywhere in the world!
- Employee Wellbeing: Benefit from the Employee Assistance Program (EAP) provided by SITA, a yearly free service offering practical advice in various aspects of your life.
- Professional Development: Enhance your skills with our training platforms, inclusive of LinkedIn Learning!
- Competitive Benefits: Access competitive benefits tailored to the local market and your employment status.
SITA is an Equal Opportunity Employer and values a diverse workforce. In support of our Employment Equity Program, women, aboriginal people, members of visible minorities, and/or persons with disabilities are encouraged to apply and self-identify in the application process.
Security Architect • Barcelona, Kingdom Of Spain, ES