Chief Cyber Protection Specialist

Descrição do trabalho

Job Overview

Air Liquide Europe Business Services was created in 2019 in Lisbon, Portugal to provide financial services for Air Liquide entities.

  • The geographical scope was extended to include entities located in Africa, Middle-East and India, and the operational scope was extended to include Finance, Human Resources and other departments.
  • Main Responsibilities
  • Support the Information Security Officer to uphold Governance, Risk Management, and Compliance standards across Digital & IT environments.
  • Maintain the cybersecurity integrity of Air Liquide's IT and OT systems, as well as its sensitive data by ensuring adherence of Digital & IT operations to established Global security governance.
  • Duties
  • Ensure alignment with Global Cybersecurity Framework.
  • Enforce Policies, Procedures, Guidelines, etc.
  • Conducts Security Risk Assessments using Group Tools and Processes (Applications, Data & 3rd Parties).
  • Review cybersecurity risks for Vendor, Suppliers, Contractors and other Third-Parties.
  • Lead the process of critical digital asset compliance including stakeholder communications, reporting, review of evidence and maintaining compliance score.
  • Identify privacy and other regulatory requirements including AI evaluations.
  • Assess compliance with Global Cybersecurity Framework throughout the data and application lifecycle (CDA's, Global ERP systems).
  • Cyber Crisis Management Response & Incidents.
  • Assist in cyber crisis management response and/or cyber crisis simulations.
  • Coordinates cybersecurity incident response with identified stakeholders to define and minimize impact.
  • SUPPORTS Digital and IT Audits.
  • Support internal and external audits by providing responses and evidence related to cybersecurity controls.
  • Leads Penetration Testing Efforts (IT & OT).
  • Act as Cybersecurity expert within the organization promoting cybersecurity concepts, issues and processes.
  • Requirements
  • Minimum 4 years of experience in Cyber Security, risk management, and/or compliance.
  • Certifications in information security and/or cyber security like CISSP, CISM, CGRC.
  • Demonstrate understanding of risk management, IT controls and related information security standards.
  • Knowledge of security control frameworks and standards such as SOC2, ISO 27001, NIST, etc.
  • Experience securing cloud-based environments.
  • Experience with regulatory requirements - GDPR, PCI, Medical, FDA, DOT, etc.
  • Excellent written and verbal communication skills.
  • English C1.