[online recruitment]
The TISO acts based on the direction of and the tasks assigned by the Divisional TISO. The TISO is assigned a set of Application Software Assets and associated Databases (IT aspects only), Infrastructure Software Assets, IT Services, Hardware Assets or IT Assets. Therefore, the TISO assumes ownership for these assets from an IT Security perspective. The TISO executes all tasks that are assigned to this role based on defined and approved rules and processes.
The TISO's responsibilities within the assigned Division or Function comprise:
- To accept the ownership and responsibility for the information security of the assigned IT Assets.
- To carry out the Information Security Risk and Compliance Assessments for the assigned IT Assets and processes.
- To remain fully trained and skilled by completing the required Information Security training provided by CSO or as requested by the Principal TISO or the Divisional TISO.
- To provide guidance to key role holders such as ITAOs and ISOs to develop a secure environment by evaluating the IT Security requirements as early as possible in the system development life cycle to select the applicable information security controls for implementation. To guide ITAOs on the implementation of compensating controls in case of deviations from the applicable information security controls.
- To approve the access control and user authorization setup of the assigned IT Assets. To execute and document periodical recertification of access rights in compliance with the DB Group Identity and Access Processes.
- To ensure that the necessary Information Security controls are implemented, influences IT risk & control-related policies/standards and provide feedback as subject matter expert. (Co-) Design implementation measures and oversee their implementation.
- To cooperate with key role holders such as ITAOs and ISOs to put monitoring capabilities for IT Assets in place. To review the output of the monitoring jointly with the key role holders such as ITAOs and ISOs to avoid degradation of the required security level.
- To analyse and review the configuration of IT Assets where required and to advise on the remediation of gaps according to the applicable Information Security policies.
- To contribute to the Information Security Incident Management Process in the case of a security breach for their IT Assets, if requested.
- To maintain the Information Security related documentation of assigned IT Assets in the DB Group IT Asset inventory.
Education
- Masters Degree from an accredited college or university (or equivalent Diploma) preferred
- CISM (Certified Information Security Manager) or CISSP (Certified Information Systems Security Professional) or CISA (Certified Information Systems Auditor)
- 6-Sigma Green Belt (Minimum) - Black Belt (Preferred)
Experience
- 5 years' experience (or comparable track record) in risk and compliance management
- 5 years expert knowledge in a minimum two and experience in all of the following fields: operational risk management, regulatory program management, information security, data protection, quality management (CMMI or ITIL or 6-Sigma) or IT development, Excellent analytical skills to evaluate problem, root cause and resolution
- Well proven influencing skills in a multi-cultural and globally matrixed organizations
- Experience in translation of very complex topics in clear and crisp messages/ visions
- Fluent in English (written/verbal)
Education
- Masters Degree from an accredited college or university (or equivalent Diploma) preferred
- CISSP (Certified Information Systems Security Professional) or equivalent
- CCSP - Certified Cloud Security Professional (preferred)
- Operating System Certification
- International projects for clients all over the world
- Competitive salary
- Individual development plan
- Managerial Targeted Training programs
- BRIDGE Mentoring Program
- Luxoft Training Center
- Language Classes
- Self-learning online library
- Global Relocation Program
- Internal Mobility (a chance to gain experience in varied projects and technologies)
- Professional communities for knowledge-sharing (Agile, Tech, Business)
- Group Life Insurance
- Travel Insurance
- Private Healthcare (dental care, unlimited consultations of specialist physicians)
- Medical costs reimbursement for employees
- Benefit Program (Cafeteria and Multisport Card)
- LuxGood Program (a wide range of health and well-being initiatives)
- After-hours groups (sport, trips, board games, cultural activities)
- Company and Team events
- BeLux - discount offers program (banking, car leasing, other)
- Convenient locations in modern offices
- International projects for clients all over the world
- Competitive salary
- Individual development plan
- Managerial Targeted Training programs
- BRIDGE Mentoring Program
- Luxoft Training Center
- Language Classes
- Self-learning online library
- Global Relocation Program
- Internal Mobility (a chance to gain experience in varied projects and technologies)
- Professional communities for knowledge-sharing (Agile, Tech, Business)
- Group Life Insurance
- Travel Insurance
- Private Healthcare (dental care, unlimited consultations of specialist physicians)
- Medical costs reimbursement for employees
- Benefit Program (Cafeteria and Multisport Card)
- LuxGood Program (a wide range of health and well-being initiatives)
- After-hours groups (sport, trips, board games, cultural activities)
- Company and Team events
- BeLux - discount offers program (banking, car leasing, other)
- Convenient locations in modern offices