About the Role
The Information Security Risk Manager plays a pivotal role in JTI's efforts to identify, assess, and manage information security and IT risks. This position ensures that information security risks are clearly understood, effectively managed, and aligned with JTI's strategic objectives.
Responsibilities
- Conduct regular IT and information security risk assessments across systems, applications, networks, and third‑party vendors
- Identify cybersecurity threats, vulnerabilities, and areas of non‑compliance
- Monitor emerging IT and cyber risks based on evolving technologies and threat intelligence
- Develop and implement effective risk mitigation strategies
- Design and recommend security controls to protect IT infrastructure and sensitive information
- Partner with Digital & IT, Security, and business teams to embed controls into processes
- Define and maintain Key Risk Indicators (KRIs) and KPIs for IT and cyber risks
- Prepare clear risk reports and dashboards for senior leadership and key stakeholders
- Escalate critical risks and incidents in a timely manner
- Maintain and enhance the IT & Security Risk Management governance framework (policies, risk appetite, playbooks, operating cycle)
- Ensure compliance with industry standards (e.g. ISO 27001, NIST) and regulatory requirements (e.g. GDPR)
- Support internal and external audits and security assessments
- Act as a key liaison between IT, Security, Legal, Compliance, ERM, and business teams
- Promote a risk‑aware culture through training and awareness initiatives
- Contribute to incident response planning, resilience initiatives, and post‑incident investigations
Requirements
- Bachelor's degree in Cybersecurity, Information Technology, or a related field
- Master's degree is an advantage
- Professional certifications such as CISSP, CISM, or CRISC are highly desirable
- 5+ years of experience in information security, IT risk management, cybersecurity, or a related field
- Hands‑on experience with risk assessments, risk reporting, and security governance
- Experience working with security frameworks (e.g. NIST, COBIT)
- Knowledge of cloud security and modern IT environments
- Experience with risk automation platforms (e.g. ServiceNow GRC) is a strong plus
- Strong understanding of information security principles, technologies, and risk management methodologies
- Analytical mindset with excellent problem‑solving skills
- Ability to communicate complex security concepts to non‑technical stakeholders
- Strong collaboration and stakeholder management skills
- Fluent spoken and written English
At JTI, we strive to create a diverse and inclusive work environment. As an equal‑opportunity employer, we welcome applicants from all backgrounds. If you need any specific support, alternative formats, or have other access requirements, please let us know.