Manager Cyber Security

gtweed

Lansdale (Montgomery County)

On-site

USD 150,000 - 230,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Greene, Tweed seeks a senior information security leader to drive a strategic, enterprise-wide program ensuring confidentiality, integrity, availability, and privacy of information assets. The role partners with Legal and Data Privacy to align with global regulations and to advance a robust, risk-based control framework across the organization.

You will oversee incident response, disaster recovery, and budgeting while collaborating with executive stakeholders to elevate security maturity and

Qualifications

  • Demonstrated experience in leadership roles in risk and information security.
  • Strong understanding of legal and regulatory requirements for data protection.

Responsibilities

  • Leads the information security function across the company to ensure consistent and high-quality information security management in support of the business goals
  • Determines the information security approach and operating model in consultation with stakeholders and aligned with risk management and compliance monitoring of non-digital risk areas
  • Manages the budget for the information security function
  • Develops, implements and monitors a strategic, comprehensive information security program to ensure confidentiality, integrity, availability, safety, privacy and recovery of information assets
  • Creates and manages a unified, risk-based control framework to integrate requirements from global laws, standards and regulations
  • Develops and maintains a document framework of up-to-date information security policies, standards and guidelines
  • Facilitates a metrics and reporting framework to measure the program's efficiency and effectiveness and communicates with executives and the board
  • Collaborates with the data privacy officer to ensure privacy requirements are included where applicable
  • Defines and facilitates processes for information security risk and regulatory assessments
  • Ensures security is embedded in project delivery with appropriate policies
  • Oversees external dependencies, including reviews of contracts and risk management alternatives
  • Manages and contains information security incidents to protect assets and reputation
  • Monitors external threat environment and advises on actions
  • Develops disaster recovery policies aligned with BCM goals
  • Coordinates incident response plans for critical services
  • Partner with Legal to ensure data protection strategy and compliance
  • Act as primary contact for data privacy matters including data breaches
  • Ensure DPAs with vendors meet standards and compliance
  • Compliance monitoring with relevant functions to identify and mitigate risks
  • Work with IT to ensure controls for data security
  • Data privacy impact assessments for new projects
  • Liaise with German DPO for Germany-specific requirements
  • Data Subject Access Requests handling and governance
  • Maintain repository of data protection materials

Skills

Information security leadership
Risk management
Regulatory compliance
Vendor risk management

Job description

At Greene, Tweed, you'll find the cutting-edge technology, world-class polymer expertise and endless advancement opportunities you'd expect from a multi-national industry leader. You'll find them all in an environment that embraces diversity in people and opinions, moves decision making to the point of impact, and celebrates your success.

If you enjoy continuous learning and are excited about working with and creating technological solutions, explore career opportunities with Greene, Tweed.

Essential Duties/Responsibilities
  • Leads the information security function across the company to ensure consistent and high-quality information security management in support of the business goals
  • Determines the information security approach and operating model in consultation with stakeholders and aligned with the risk management approach and compliance monitoring of non-digital risk areas
  • Manages the budget for the information security function
  • Develops, implements and monitors a strategic, comprehensive information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy and recovery of information assets owned, controlled or/and processed by the organization
  • Creates and manages a unified and flexible, risk-based control framework to integrate and normalize the wide variety and ever-changing requirements resulting from global laws, standards and regulations
  • Develops and maintains a document framework of continuously up-to-date information security policies, standards and guidelines
  • Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, and increases the maturity of the information security, and reviews it with stakeholders at the executive and board levels
  • Collaborates and liaises with the data privacy officer to ensure that data privacy requirements are included where applicable
  • Defines and facilitates the processes for information security risk and for legal and regulatory assessments, including the reporting and oversight of treatment efforts to address negative findings
  • Ensures that security is embedded in the project delivery process by providing the appropriate information security policies, practices and guidelines
  • Oversees technology dependencies outside of direct organizational control. This includes reviewing contracts and the creation of alternatives for managing risk
  • Manages and contains information security incidents and events to protect corporate IT assets, intellectual property, regulated data and the company's reputation
  • Monitors the external threat environment for emerging threats, and advises relevant stakeholders on the appropriate courses of action
  • Develops and oversees effective disaster recovery policies and standards to align with the enterprise business continuity management (BCM) program goals, with the realization that components supporting primary business processes may be outside the corporate perimeter
  • Coordinates the development of implementation of incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event; provides direction, support and in-house consulting in these areas
  • By partnering with Legal ensure compliance to Data Protection laws and regulations by contributing to the development and implementation of the data protection strategy that aligns with privacy goals and ensures compliance
  • Act as the primary point of contact for all Data privacy matters including a Data breach or other data incident to ensure these are swiftly addressed
  • In partnership with Legal, ensure Vendor and Third Party Risk Management: Ensure that DPAs (Data processing agreements) are in place with all vendors to ensure that they meet the organizations standards and compliance requirements
  • Compliance Monitoring: In conjunction with other relevant functions, act as a trusted partner in the reviewing and auditing of data protection practices within the organisation to identify, assess and mitigate risks and determine appropriate controls
  • Work with IT to ensure all appropriate controls are in place for the security of data
  • Privacy Impact Assessments: Conduct privacy impact assessments for all new projects, systems or processes that involve the processing of personal data
  • Liaise with the German Data Protection Officer to ensure compliance with requirements specific to Germany, any outcomes from the periodic Data privacy audit and in alignment with Works Council requirements
  • Data Access requests: Manage all DSARs: Manage and facilitate the process of Data Subject Access Requests in alignment with GDPR requirements
  • Maintain a repository of data protection materials for easy accessibility and monitoring
Required Minimum Qualifications
  • Demonstrated experience and success in a leadership roles in risk management, information security, and IT or OT security
  • Knowledge and understanding of relevant legal an
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Cyber Security
Manager Cyber Security

Greene Tweed • Lansdale

On-site
USD 180,000 - 240,000
Health insurance
Flexible spending accounts
Health savings account
+3
Global Cyber Security Leader & Privacy Risk Steward
Global Cyber Security Leader & Privacy Risk Steward

Greene, Tweed & Co Limited • Lansdale

On-site
USD 140,000 - 230,000
Health insurance
Flexible spending accounts
Health savings account
+3
Head of Information Security & Data Privacy
Head of Information Security & Data Privacy

gtweed • Lansdale

On-site
USD 150,000 - 230,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Manager of Information Technology
Manager of Information Technology

Confidential • Pittsburgh

Hybrid
USD 150,000 - 190,000
Cyber Security Manager
Cyber Security Manager

Insight Global • Daphne (AL)

On-site
USD 120,000 - 180,000
Cloud Security Engineer/Architect
Cloud Security Engineer/Architect

GCM Grosvenor • Chicago (IL)

Hybrid
USD 100,000 - 130,000
Global Head of Cyber Security & Privacy
Global Head of Cyber Security & Privacy

Greene Tweed • Lansdale

On-site
USD 180,000 - 240,000
Health insurance
Flexible spending accounts
Health savings account
+3
Group Director, Cyber Risk & Security Engineering
Group Director, Cyber Risk & Security Engineering

Brobston Group LLC • New York (NY)

On-site
USD 180,000 - 240,000