We are looking for a Cybersecurity Manager who will take on the role of CISO, provide organization-wide direction for our cybersecurity policy, and help safeguard the management of digital risks and our related reputation. In this strategic expert role, you combine policy insight with tangible impact. You work closely with ICT, data, executive management, and other partners, and report directly to the Director ICT, Data and Strategic Projects (CIO).
As a Cybersecurity Manager, you are responsible across the organization for developing, implementing, and monitoring cybersecurity and information security policies. Your focus is on governance, risk management, and awareness.
Responsibilities
Develop, update, and translate cybersecurity and information security policies into clear frameworks, standards, and guidelines
Work based on a recognized framework (such as NIST) and systematically monitor the organization’s cybersecurity maturity
Initiate and lead cyber-related initiatives and improvement programs based on market insights, risk analyses, incidents, audits, and strategic priorities
Manage the full risk management cycle from a reputational perspective, including identification, protection, prevention, response, and recovery
Oversee the incident response and crisis management framework for cybersecurity and information security incidents, and take on a coordinating role in incidents and data breaches
Identify, assess, and monitor cyber risks across the organization, with attention to continuity, compliance, and reputation
Collaborate with ICT, data, legal, and other departments on cyber-relevant processes (such as change and run), with a focus on governance and risk control
Act as a subject matter expert for internal and external audits, as well as cyber and risk-related aspects within vendor and contract management
Clearly report to and advise executive management on cyber risks, priorities, and developments
Ideal Profile
A strong strategic expert who can approach cybersecurity from an organization-wide perspective and translate complex topics into clear policies and decisions.
Requirements
A master’s degree, preferably in ICT or business-related fields, or an equivalent level through relevant and demonstrable experience
Extensive knowledge of ICT risk management and cybersecurity, with a solid understanding of IT infrastructures, networks, cloud, and data environments
Familiarity with risk management within IT and digital ecosystems, including third-party and vendor risks
In-depth knowledge of cybersecurity and risk management frameworks (such as NIST) and the ability to apply them pragmatically in an organizational context
Understanding of ICT service management and ITIL principles, particularly in relation to change and run processes
Knowledge of relevant regulations, such as the key principles of NIS2, and the ability to translate their impact into policy and governance
Ability to analyze and assess risks and provide clear, well-founded advice to management and executive leadership
Strong communication skills, both written and verbal, with the ability to facilitate collaboration and alignment