Manager IT Product and R&D Security

Philip Morris International

Albarraque

Presencial

EUR 60 000 - 90 000

Tempo integral

Há 2 dias
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Resumo da oferta

Philip Morris International IT seeks an experienced Information Security professional to act as the single point of contact for risk reduction and governance across projects and BAU. You will collaborate with R&D to apply security expertise, support embedded device security, and drive security-by-design across the lifecycle.

The role requires strong communication, agile mindset, and cross-border collaboration.

Qualificações

  • 5+ years of experience in information security, IT risk management, or IT audit within a large organization.
  • Proven track record in secure systems development lifecycle across design, development, and maintenance.
  • Knowledge of typical application design patterns (web, mobile, APIs).
  • Understanding of cloud architectures (SaaS, IaaS, PaaS, FaaS) and their security implications.
  • Knowledge of IAM concepts (SSO, identity federation) and standards (SAML, OAuth 2.0, OpenID).
  • Familiarity with OWASP Top 10 and regulatory requirements (GDPR, data privacy).
  • Experience with electronics manufacturing and supply chain service providers.
  • Strong communication and ability to explain complex topics to non-technical people.
  • Agile/DevOps experience and cross-cultural collaboration.

Responsabilidades

  • Act as SPOC for Information Security to implement, report and follow up on risk reduction activities with projects and BAU.
  • Engages with business stakeholders from the R&D function on projects requiring Information Security expertise.
  • Support cybersecurity requirements for embedded devices across the design, development, and manufacturing lifecycle.
  • Engage with IT platform peers on security-by-design and privacy-by-design concepts and tools.
  • Perform governance on key security metrics for systems under responsibility.
  • Conduct software security assessments and approvals.
  • Evaluate new technologies (AI, ML, IoT) for security implications.
  • Lead general IT control activities and vendor risk governance.
  • Lead security clauses in contracts and ensure alignment with PMI standards.
  • Monitor adherence to contractual security obligations and escalate non-compliance.
  • Ensure timely remediation of findings from third-party assessments.
  • Participate in security awareness trainings and coaching.
  • Participate in cyber incidents from identification to eradication with SOC/IRM teams.
  • Perform risk assessments and vulnerability management for functional areas.
  • Drive cybersecurity resilience activities (backup, DR).
  • Drive security maturity assessments and audit participation.
  • Represent IT during internal or external audits.

Conhecimentos

Information Security
IT Risk Management
IT Audit
Security Governance
Cloud Security

Ferramentas

SAML
OAuth 2.0
OpenID
OWASP

Descrição da oferta de emprego

Be a part of a revolutionary change - find your future in our future

At PMI, we have chosen to do something incredible. We are transforming our business and building our future with one clear purpose - to deliver a smoke-free future. We are disrupting our company from the inside out. Our transformation is redefining every area of our business. From where and how we make and sell our products, to how we engage our consumers and society.

To support this vision, PMI is evolving into a science and technology-based, consumer-facing, multi-category company, and Information Technology (IT) is a vital partner in helping to lead the way. As we accelerate PMI's vision, we get to dream big, too.

With unique and transformative IT projects matching all levels of skill and ambition, we have taken on the spirit of a start-up, with the freedom to craft and define our digital future, but with the support and scope of a vast global business.

YOUR DAY TO DAY
  • Act as SPOC for Information Security to implement, report and follow up on risk reduction activities with projects and BAU; and work together with key stakeholders to oversee security improvement activities.
  • Engages with business stakeholders from the R&D function on projects and activities that require Information Security expertise and advice.
  • Support cybersecurity requirements for embedded devices across the design, development, and manufacturing lifecycle.
  • Engage with business and IT platform peers throughout system lifecycle on "security-by-design" and "privacy-by-design" concepts, methods, and tools.
  • Perform active governance on key security metrics for systems under his/her responsibility.
  • Conduct software security assessments and approvals.
  • Evaluate new technologies (e.g., AI, ML, IoT) for security implications.
  • Perform or take accountability for general IT control activities in scope of the solutions, including evaluating 3rd party cyber maturity and performing ongoing vendor risk governance.
  • Lead the creation and review of security clauses in contracts, ensuring alignment with PMI security standards and regulatory requirements, incl. TPISS.
  • Monitor adherence to contractual security obligations and elevate non compliance issues.
  • Ensure timely remediation of findings from third-party assessments and track progress to closure.
  • Take part in security awareness trainings and provide coaching, training, promote webinar attendance, or similar activities to raise the security awareness of the function.
  • Actively participate in cyber incidents impacting solutions under his/her responsibility, from identification to eradication, working closely with central/platform IT teams and InfoSec (e.g. SOC and IRM).
  • Perform risk assessments and vulnerability management activities for functional support areas. Manage, monitor, and report on the full lifecycle of risk management at the system or platform level, from identification to closure.
  • Drives cybersecurity resilience activities in the assigned functional domain (e.g. backup, restored, Disaster Recovery).
  • Drive continuous improvement through security maturity assessments.
  • Represent IT during internal or external audits.
Who We’re Looking For
  • Minimum 5-8 years of experience in an information security, IT risk management or IT audit function within a large organization.
  • Proven track record in supporting development teams throughout all phases of secure systems development life cycle (design, development, maintenance).
  • Good knowledge of typical application design patterns (e.g. web, mobile, thick client, APIs, etc.).
  • Good understanding of cloud computing architectures (e.g. SaaS, IaaS, PaaS, FaaS) and their corresponding characteristics in terms of information security.
  • Good understanding of modern technologies such as IoT, Machine learning, and automation.
  • Knowledge of basic identity and access management concepts (e.g. single-sign on, identity federation) and standards (e.g. SAML, OAuth 2.0, OpenID).
  • Familiarity with most common web application security issues (e.g. OWASP top 10).
  • General understanding of regulatory requirements (e.g. GxP, GDPR/Data Act, Chinese cyber and privacy laws) and their impact on systems.
  • Experience working with electronics manufacturing and supply chain service providers.
  • Strong communication skills and ability to explain technical topics to non-technical people.
  • Practical experience in Agile/DevOps organizations and cultures.
  • Teamwork and collaboration across cultures and geographies (Europe and Asia).
Preferred Requirements
  • Customer Service culture.
  • Basic understanding of consumer electronics and product security operations.
  • Experience supporting Product Development/Manufacturing/Testing/Labs environments.
WHY SHOULD YOU JOIN US?

At PMI IT, We Believe Success To Be Fuelled By Our Employees, Depended On Them Coming To Work Every Single Day With a Sense Of Purpose And An Appetite For Challenge. We Are a People First Organisation Committed To Empowering You To Take Risks, Grow And Explore. Here's What Sets Us Apart

  • We’re redefining the big picture of well-being and personal development. We seek the best professionals but recognize them as parents, caregivers, family, and community members. We look after each other and care for our people, so wherever you join us around the world, we’re committed to providing the type of benefits only a company like PMI can offer
  • Being the fastest learning IT organization in the world is core to our culture, so we invest significantly in developing our people. From mentoring to technical certifications, stretch roles, soft skills development, and executive education, we help our people develop the skills they need to do their best work and create their own unique impact.
  • At PMI IT, we believe diversity and inclusiveness are essential to every industry. We’re proud that our culture is built upon strong corporate values, a foundation of respect and belonging, and a commitment to diversity and inclusion that welcomes a variety of skill sets, backgrounds, and experiences.
  • We see digital technology as disruptive and possibilities as endless. Our teams work with innovative technologies such as Cloud, APIs, IoT and AI, supported by management practices and principles such as Agile, Design Thinking, and Product Management.

Every single IT member is part of our Transformation journey. Join us and pursue your ambitions - our staggering size and scale provide endless opportunities to progress.

Additional information
  • Relocation support is not available for this role.
  • Only CVs in English will be considered.
Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Sr. Manager Tech Software Engineering AI Factory
Sr. Manager Tech Software Engineering AI Factory

Philip Morris International • Albarraque

Presencial
EUR 90 000 - 150 000
Senior IT Security Analyst - Data & AI Platform
Senior IT Security Analyst - Data & AI Platform

Philip Morris International • Albarraque

Híbrido
EUR 70 000 - 100 000
Hybrid model of work
Life and Health insurance
Employee Pension Plan
Principal Tech Solution Architect Industrial IoT
Principal Tech Solution Architect Industrial IoT

Philip Morris International • Albarraque

Híbrido
EUR 90 000 - 130 000
Company car or car allowance
Private medical and dental care
Hybrid work model or fully remote
+3
Digital Product Owner - Tech Cloud Product
Digital Product Owner - Tech Cloud Product

Philip Morris International • Albarraque

Presencial
EUR 48 000 - 68 000
Sr. Manager Tech Software Engineer AI Factory
Sr. Manager Tech Software Engineer AI Factory

Philip Morris International • Lisboa

Presencial
EUR 26 000 - 100 000
Diversity and inclusion initiatives
Professional development programs
Mentorship opportunities
Sr Manager Tech Product Group Delivery Mgmt EUS
Sr Manager Tech Product Group Delivery Mgmt EUS

Philip Morris International • Albarraque

Híbrido
EUR 70 000 - 100 000
Life and Health insurance
Employee Pension Plan
Hybrid working model
+1
Ai-Driven M365 Platform Architect
Ai-Driven M365 Platform Architect

Philip Morris International • Viseu

Presencial
EUR 85 000 - 130 000
Matillion DPC / METL Administrator Engineer - Federated Data Platform
Matillion DPC / METL Administrator Engineer - Federated Data Platform

Philip Morris International • Albarraque

Presencial
EUR 55 000 - 75 000
Inclusive culture
Global opportunities to progress
Freedom to experiment and innovate
+1
Sr Manager Data Science
Sr Manager Data Science

Philip Morris International • Albarraque

Presencial
EUR 75 000 - 100 000
Inclusive and diverse culture
Opportunities for professional development
Freedom to innovate and experiment
Group Head of IT & Security
Group Head of IT & Security

QIMA • Lisboa

Presencial
EUR 120 000 - 180 000