Skip to content
← Back to job listings

Head of Group Information Security

Lindt & Sprüngli (International) AG · Kilchberg, Switzerland

IT - Network / Systems / DB AdminImported listingfull-timeabout 8 hours ago

About The Role

Your main responsibilities will include:

  • Provide leadership, direction, and advocacy to effectively manage the cybersecurity program.
  • Develop and implement the agreed cybersecurity strategy in alignment with the business and IT strategy.
  • Oversee staff, infrastructure, policy enforcement, and/or other resources.
  • Drive the development of policies & standards and advocate for change that will support new initiatives or required changes and enhancements.
  • Apply knowledge of risk assessment data of identified threats to decision-making processes.
  • Acquire and manage the necessary resources, including third party security service providers, to support security goals, and reduce overall organizational risk.
  • Advise senior management on risk levels and security posture.
  • Communicate the value of security throughout all levels of the organization's stakeholders.
  • Monitor threats, conduct investigations, support inquiries, and take preventive measures to improve business resilience.
  • Develop and provide security guidance for new and existing systems,
  • applications, and services; this includes weighing business needs, internal governance standards, and third-party compliance requirements.
  • Partner with subsidiary IT teams to establish and track regional and global priorities for security initiatives.
  • Provide regular reporting on security initiatives to the Head of Group IT and senior management.
  • Provide leadership regarding security for assets and data, both on-premises and cloud-based.
  • Evaluate emerging technologies and product categories to determine where they fill gaps, overlap with existing solutions, or extend capabilities.
  • Implement and maintain security systems, applications, and services that provide detection, preventions, containment and deterrence mechanisms to protect corporate data.
  • Lead the selection, testing, and deployment of new security solutions.
  • Document security requirements by evaluating business needs, internal governance standards, and third-party & customer compliance requirements.
  • Manage relationships with existing and future managed security service providers (MSSPs) that contribute to the portfolio of security services.
  • Manage and coordinate response to security incidents.
  • Facilitate compliance with audit, legal, regulatory, and customer contract requirements.
  • Analyse and evaluate security operations to identify risks or opportunities for improvement.

Your profile:

  • The position requires a Bachelor's degree and at least fifteen (15) years of related experience with a minimum of six (6) years of technical experience in one or
  • more of the following: computer and network security, cloud-based security
  • architecture, vulnerability testing, intrusion detection/prevention, security
  • monitoring and event correlation, or computer forensic analysis.
  • Relevant Information Security certifications (ex. CISSP, CCSP, GIAC, MCSE, CEH, CHFI, CISA, CISM, CRISC, etc.)
  • Highly-developed communications skills (written/verbal) and interpersonal savvy
  • Results/action-orientation; project management skills.
  • Organizational and political agility; developed negotiation and influence skills.
  • Unquestionable personal code of ethics, integrity, diversity and trust.
  • Able to successfully navigate within varying degrees of ambiguity in a fast-paced environment.
  • Prior experience working in a global, decentralized organization.
  • Extensive knowledge of cybersecurity principles.
  • Extensive knowledge of cyber threats and vulnerabilities.
  • Skill in de-conflicting cyber operations and activities.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing