Descrição do trabalho
Job Overview
Air Liquide Europe Business Services was created in 2019 in Lisbon, Portugal to provide financial services for Air Liquide entities.
- The geographical scope was extended to include entities located in Africa, Middle-East and India, and the operational scope was extended to include Finance, Human Resources and other departments.
- Main Responsibilities
- Support the Information Security Officer to uphold Governance, Risk Management, and Compliance standards across Digital & IT environments.
- Maintain the cybersecurity integrity of Air Liquide's IT and OT systems, as well as its sensitive data by ensuring adherence of Digital & IT operations to established Global security governance.
- Duties
- Ensure alignment with Global Cybersecurity Framework.
- Enforce Policies, Procedures, Guidelines, etc.
- Conducts Security Risk Assessments using Group Tools and Processes (Applications, Data & 3rd Parties).
- Review cybersecurity risks for Vendor, Suppliers, Contractors and other Third-Parties.
- Lead the process of critical digital asset compliance including stakeholder communications, reporting, review of evidence and maintaining compliance score.
- Identify privacy and other regulatory requirements including AI evaluations.
- Assess compliance with Global Cybersecurity Framework throughout the data and application lifecycle (CDA's, Global ERP systems).
- Cyber Crisis Management Response & Incidents.
- Assist in cyber crisis management response and/or cyber crisis simulations.
- Coordinates cybersecurity incident response with identified stakeholders to define and minimize impact.
- SUPPORTS Digital and IT Audits.
- Support internal and external audits by providing responses and evidence related to cybersecurity controls.
- Leads Penetration Testing Efforts (IT & OT).
- Act as Cybersecurity expert within the organization promoting cybersecurity concepts, issues and processes.
- Requirements
- Minimum 4 years of experience in Cyber Security, risk management, and/or compliance.
- Certifications in information security and/or cyber security like CISSP, CISM, CGRC.
- Demonstrate understanding of risk management, IT controls and related information security standards.
- Knowledge of security control frameworks and standards such as SOC2, ISO 27001, NIST, etc.
- Experience securing cloud-based environments.
- Experience with regulatory requirements - GDPR, PCI, Medical, FDA, DOT, etc.
- Excellent written and verbal communication skills.
- English C1.