نطاق العمل
الغرض من الوظيفة
تتحمل إدارة التكنولوجيا والحلول الرقمية العالمية (D&T) مسؤولية عالمية عن جميع عمليات وحلول وخدمات تكنولوجيا المعلومات. والهدف هو تعزيز الوظائف العالمية لشركة هاينكن (HEINEKEN) من خلال تقديم حلول وخدمات مشتركة موجهة نحو الأعمال.
تعد إدارة أمن المعلومات العالمية جزءاً من إدارة التكنولوجيا والحلول الرقمية العالمية وتتحمل المسؤولية الشاملة عن ضمان إدارة مخاطر تكنولوجيا المعلومات في هاينكن بشكل صحيح وتأمين أصول المعلومات والتكنولوجيا بشكل مناسب.
تضم فرق أمن المعلومات العالمية كلاً من عمليات الدفاع السيبراني (CDO)، ومركز كفاءة الأمن (SCC)، وفصول الأمن (تخطيط موارد المؤسسات، وهندسة المؤسسات، وخصوصية البيانات، وما إلى ذلك) لتصميم وتنفيذ ومراقبة والاستجابة والمساعدة في أنشطة التعافي من الهجمات السيبرانية. إنهم يقدمون خبرة عميقة في الأمن وإدارة المخاطر لتمكين فرق المنتجات والوظائف العالمية من تشكيل خط دفاع أول (LoD) مناسب من خلال بناء القدرات الصحيحة في منتجاتهم (الأمن بالتصميم) ودعمهم.
يرأس مدير أمن المعلومات العالمي القسم وهو المسؤول عن استراتيجية أمن المعلومات العالمية وتنسيق جميع الأنشطة الأمنية داخل هذا القسم ومع أصحاب المصلحة المعنيين. وهو جزء من فريق القيادة التنفيذية للتكنولوجيا والحلول الرقمية العالمية.
مسؤول الأمن السيبراني (CSO) مسؤول عن إدارة وتنفيذ استراتيجية الأمن السيبراني العالمية بناءً على إطار عمل الأمن السيبراني الخاص بالمعهد الوطني للمعايير والتقنية (NIST)، لتقليل مخاطر وقوع حادث أمن سيبراني وفقاً لشهية المخاطر الخاصة بشركة هاينكن والوظيفة العالمية، بالإضافة إلى رفع مستوى الوعي بالأمن السيبراني على مستوى الوظيفة العالمية.
المسؤوليات الرئيسية
العمليات الأمنية: تنفيذ استراتيجيات أمنية عالمية للحفاظ على استمرارية الأنظمة وتحديثها بناءً على التهديدات المحلية. مسؤول عن إدارة التحديثات المتعلقة بمعايير أمن الوظائف العالمية المطلوبة بسبب المتطلبات التشريعية المحلية، بالتشاور مع أخصائي أمن المعلومات العالمي بما يتماشى مع استراتيجية أمن هاينكن ودعم استراتيجية أعمال هاينكن. مسؤول عن الموافقات الأمنية للوظائف العالمية فيما يتعلق بالخدمات العالمية (على سبيل المثال Hei Net)، وذلك للحفاظ على أعلى مستوى من الأمان لمعلومات وأصول تكنولوجيا المعلومات بالشركة. مساعدة قسم أمن المعلومات العالمي في تصميم الضوابط/المعايير والإجراءات التي لها آثار واسعة، والتي تتطلب تكامل الأنظمة لمنصة تقنية واحدة أو أكثر. إجراء مراجعات المخاطر باستخدام إجراء إدارة المخاطر لجميع برامج/خدمات الوظائف العالمية الجديدة التي سيتم نشرها في بيئة العمل التشغيلية للوظيفة العالمية، واستخدام حق النقض ضد البرامج التي لا تتوافق مع معايير أمن هاينكن. مراقبة الامتثال لسياسة أمن المعلومات والأمن السيبراني داخلياً وخارجياً، ومراجعة وتقييم عمليات تدقيق أمن المعلومات.
إجراء تقييم نضج أمن المعلومات (ISMA) وفقاً للوتيرة المحددة، وضمان توفر جميع الأدلة ذات الصلة لدعم التقييم. مراقبة وضمان الإغلاق في الوقت المناسب للمهام المتعلقة بقضايا التدقيق والرقابة الداخلية التي يثيرها على سبيل المثال التدقيق العالمي، والتدقيق الخارجي، وما إلى ذلك. تطوير وإدارة خطة عمل أمن المعلومات لمعالجة المخاطر المحددة وعدم الامتثال.
الحصول على موافقة من فريق الإدارة المعني على خطة العمل تلك وميزانيتها ذات الصلة. مراقبة تنفيذ خطة العمل تلك وتقديم تقارير بشأنها، وتقديم التقارير إلى فريق إدارة وظيفة التكنولوجيا والحلول الرقمية العالمية ومركزياً إلى فريق أمن المعلومات العالمي. تحليل وتحدي طلبات الاستثناء المتعلقة بسياسة أمن المعلومات (ISP)/سياسة الأمن التقني (TSP) التي قد تكون لدى الوظائف العالمية مع حل أو برنامج جديد، والتواصل مع فريق أمن المعلومات العالمي وسلطة التصميم للموافقة عليها من أجل حماية بيئة أمن هاينكن. قيادة حل استجابات حوادث الأمن السيبراني ومعالجة الثغرات الأمنية.
إجراء/توجيه/قيادة التحقيقات الرقمية بناءً على طلب الوظائف العالمية/الموارد البشرية أو الفرق القانونية في حالة حدوث انتهاكات لمدونة قواعد السلوك التجاري لشركة هاينكن. إذا واجهت الوظيفة العالمية أي حوادث أمنية حرجة في تكنولوجيا المعلومات أو اختراقات، فهو/هي مسؤول كقائد لحادث أمن الوظيفة العالمية للحل بالتشاور مع فريق عمليات الدفاع السيبراني (CDO)، ومديري التكنولوجيا والحلول الرقمية للوظائف العالمية ومديري خطوط الوظائف العالمية.
تحديد وإجراء تحليل مستقل لحل المشكلات المعقدة لأول مرة بما في ذلك تحليل الجدوى التقنية والاقتصادية لأنظمة/حلول الأمن المقترحة. وهو/هي مسؤول أيضاً عن مساعدة قسم أمن المعلومات العالمي في أي تدقيق تقني لتكنولوجيا المعلومات (على سبيل المثال القرصنة الأخلاقية) لأي بنية تحتية أو خدمة تكنولوجيا معلومات تابعة للوظيفة العالمية يقدمها طرف ثالث لشركة هاينكن بعقد ساري ومفتوح لضمان وضع سياسات الأمن موضع التنفيذ. تقديم المشورة لفرق الوظائف العالمية بشأن المتطلبات الأمنية (على سبيل المثال التصحيح، مكافحة الفيروسات، إدارة الثغرات، وما إلى ذلك). التوعية الأمنية: قيادة حملات تدريبية حول التوعية بالأمن السيبراني وفقاً لبرنامج التوعية الأمنية العالمي وبناءً على واقع الوظيفة العالمية. استراتيجية الأمن: مسؤول عن تحديد المخاطر المحتملة والتوصيات حول كيفية منع و/أو تجنب تلك المخاطر داخل الوظيفة العالمية. التعاون مع أخصائي أمن المعلومات العالمي لفهم وتطوير الضوابط والعمليات المطلوبة لتحسين أمن المعلومات بشكل أكبر. الابتكار: تسريع وقيادة تنفيذ استراتيجيات ومعايير أمنية جديدة من التكنولوجيا والحلول الرقمية العالمية نحو الوظائف العالمية لشركة هاينكن، وتوفير الخبرة الأمنية عبر منصات تقنية متعددة لمختلف أصحاب المصلحة في الوظائف العالمية في جميع مراحل تطوير الحلول (التفكير، التصميم، البناء، الاختبار والنشر) والعمليات.
مسؤوليات الميزانية
تخصيصها لمدير التكنولوجيا والحلول الرقمية للوظيفة العالمية.
عدد التقارير المباشرة
لا يوجد
ملف الوظيفة
المؤهلات
درجة البكالوريوس أو الماجستير في تكنولوجيا معلومات الأعمال أو مجال ذي صلة
حاصل على شهادات ذات صلة، على سبيل المثال CISSP / CCSP / CISM / CISA / CRISC
الخبرة / المهارات المطلوبة
5+ سنوات من العمل في مجال الأمن السيبراني وخبرة سابقة في العمل كمسؤول أو مدير أمن سيبراني. اللغة الفرنسية مطلوبة ومفضلة. عمل مع المعايير السوقية ذات الصلة مثل NIST وISO 27001 وCOBIT والقوانين واللوائح ذات الصلة مثل قوانين الخصوصية. خبرة في التعامل مع الحوادث الأمنية. قدرة مثبتة على تقييم المخاطر والتهديدات والجهات المهددة بشكل ديناميكي. قادر على العمل في بيئة متعددة الوظائف؛ يفضل خلفية في صناعة السلع الاستهلاكية سريعة التداول (FMCG). إحساس بضرورة العمل وعقلية حذرة وآمنة لسد الثغرات الحرجة وتقليل أي خرق أمني. القدرة على شرح العمليات التقنية المعقدة لأصحاب المصلحة في العمل. المرونة للتكيف مع المتطلبات المتعددة والأولويات المتغيرة والغموض والتغيير السريع. القدرة على العمل والتعاون مع مجموعة كبيرة من الأشخاص المختلفين والثقافات المختلفة (حسب الاقتضاء). إظهار الاحترافية، وموقف خدمة العملاء، والاهتمام بالتفاصيل والجودة. امتلاك مهارات قوية في التعامل مع الآخرين، وإدارة العلاقات ومهارات التفاوض، ومهارات تواصل شفهية وكتابية قوية. تطوير الذات والآخرين من خلال التعلم المستمر ومشاركة أفضل الممارسات والمعرفة والخبرة. مهارات إدارة وقيادة ممتازة.
اللغة (اللغات)
الإنجليزية بطلاقة #addjob
Scope of the job
Job Purpose
Global Digital & Technology (D&T) has a worldwide responsibility for all IT processes, solutions and services. The aim is to further enhance HEINEKEN Global Functions by delivering common business driven solutions and services.
The Global Information Security department is part of Global D&T and has the overall responsibility of assuring that HEINEKEN’s IT Risks are properly managed and information assets & technology is properly secured.
The Global Information Security teams include Cyber Defence Operations (CDO), Security Competence Centre (SCC) and Security Chapters (ERP, Enterprise Architecture, Data Privacy, etc) to design, implement, monitor, respond and assist with recovery activities against cyberattacks. They deliver deep security and risk management expertise to enable Product Teams and Global Functions to form a proper 1st Line of Defense (LoD) by building the right capabilities into their products (security by design) and support them.
The Global Information Security Director is heading the department and responsible for the Global Information Security Strategy and orchestrating all security activities within this department and relevant stakeholders. He is part of the Global D&T Executive Leadership Team.
The Cyber Security Officer (CSO) is responsible for the management and implementation of the global Cyber Security Strategy based on the NIST Cyber Security Framework, to reduce the risk of a Cybersecurity incident according to the risk appetite of HEINEKEN and the Global Function, as well as to raise wider Global Function Cybersecurity awareness.
Key Responsibilities
Security Operations Implement global security strategies to maintain the continuity of systems and update these based on local threats. Responsible to manage updates related to Global Function Security Standards that are required due to local legislative requirements, in consultation with the Global Information Security Specialist in line with HEINEKEN Security Strategy and supporting the HEINEKEN Business Strategy. Responsible for Global Function security approvals regarding global services (e.g. Hei Net), in order to maintain the highest level of security for the information and IT assets of the company. Assist the Global Information Security department in the design of controls/ standards and procedures that have broad implications, requiring systems integration of one or more technical platforms. Perform Risk reviews using the risk management procedure for all new Global Function programs/services to be deployed in the Global Function operational environment and veto programs which do not comply with HEINEKEN’s security standards. Monitor internal and external information security and cyber security policy compliance, review and assess information security audits.
Performs, as per the prescribed frequency the Information Security Maturity Assessment (ISMA), and ensures that all related evidence is available in support of the assessment. Monitor and ensure the timely closure of tasks related to audit and internal control issues raised by e.g. Global Audit, External Audit, etc. Develops and manages the Information Security action plan to address identified risks and non-compliances.
Gains approval from the relevant management team on that action plan and its related budget. Monitors and reports on the execution of that actions plan, reporting to the Global D&T Function management team and centrally to the Global Information Security Team. Analyse and challenge derogation requests regarding the ISP/TSP that Global Functions could have with a new solution or program, and communicate to the Global Information Security Team and Design Authority for approval in order to protect the HEINEKEN security environment. Drive resolution of cyber security incident responses and address security vulnerabilities.
Perform/guide/drive digital investigations upon the request of Global Function/HR or Legal teams in case of breaches of HEINEKEN’s Code of Business Conduct. If the Global Function faces any critical IT security incidents or breakout, he/she is responsible as the Global Function security incident lead to resolve in consultation with the Cyber Defense Operations Team (CDO), Global Function D&T Directors and Global Function Line Managers.
Identify and perform independent analysis to resolve complex first-time issues including the analysis of technical and economic feasibility of proposed security systems/ solutions. He/she is also responsible to assist the Global Information Security department for any IT technical audit (e.g. Ethical Hack) to any Global Function IT infrastructure or service that a 3rd Party offers to HEINEKEN with a valid and open contract to ensure that security policies are in place. Advises Global Function teams for security requirements (e.g. Patching, Anti-Virus, Vulnerability Management, etc). Security Awareness Drive training campaigns on cyber security awareness according to the global security awareness program and based on the Global Function reality. Security Strategy Responsible for identifying potential risks and recommendations on how to prevent and/or avoid that risk within the Global Function. Collaborate with the Global Information Security Specialist to understand and develop further the controls and processes required to improve information security. Innovation Accelerates and Drives implementation of new Security strategies and standards from global D&T towards the HEINEKEN Global Functions Provide security expertise across multiple technical platforms to various Global Function stakeholders in all phases of solutions development (Ideation, Design, build, test and deploy) and Operations.
Budget Responsibilities
Assigned to Global Function D&T Manager.
Number Of Direct Reports
None
Position profile
Qualifications
Bachelor or Master degree in business information technology or a related field
Possesses relevant certifications, e.g. CISSP / CCSP / CISM / CISA / CRISC
Experience / Skills Required
5+ years of working in the cyber security field and previous experience working as a cyber-security officer or manager. French is a must and preferable. Has worked with relevant market standards such as NIST, ISO 27001, COBIT and relevant laws and regulations such as privacy laws. Experience in handling security incidents. Proven ability to dynamically assess risks, threats & threat actors. Able to work in a cross functional environment; preferably a background in the FMCG industry. Sense of Business Urgency and safe-cautious mind to close critical gaps and reduce any security breach. Ability to explain complex technical processes to business stakeholders. Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change. Ability to work and team with a multitude of different people and different cultures (as appropriate). Display professionalism, customer service attitude, attention to detail and quality. Possess strong interpersonal skills, relationship management and negotiation skills, strong verbal, and written communication skills. Develop self and others through continuous learning, sharing best practices, knowledge, and expertise. Excellent management and leadership skills.
Language(s)
Fluent English #addjob