Epicareer Might not Working Properly
Learn More

Information Protection and Security Officer

Salary undisclosed

Apply on

Availability Status

This job is expected to be in high demand and may close soon. We’ll remove this job ad once it's closed.


Original
Simplified

The Position

Coordinate Information Protection & Security services in alignment with global Information Protection & Security. Ensure cost efficient protection of Boehringer’s information assets and intellectual property by minimizing risks of disclosure and unauthorized use, including those measures necessary to detect, document, and counter such threats.


Duties & Responsibilities

  • Coordinate Information Protection & Security relevant topics within the respective location. Ensure a consistent and effective security approach according to the global IP & Security strategy. Ensure local alignment with architectural specifications and standards.
  • Drive further development and improvements of existing services and consolidation of services. Reduce duplicate processes for the same purpose. Identify security risks and propose remediation measures to minimize risk for Boehringer. Transfer local demands and mandatory requirements into regional and global processes.
  • Lead the design and execution of the IT security awareness program, ensuring that employees are well-informed about new threats and best practices for identifying and preventing security incidents. Work closely with business units and functions to understand and establish acceptable levels of risk, providing expert advice on risk management and control measures.
  • Implement and continuously improve awareness programs. Ensure compliance with internal and external regulations and frameworks. Conduct audits and minimize findings, using observations to improve compliance. Initiate and monitor measures and preventive actions.
  • Strong knowledge and adherence to external standards (ISO27001/002, NIST, CIS, KRITIS) and internal IT security regulations, including global and local information governance and data privacy requirements.
  • Support Information Protection & Security, including Information Protection & Security initiatives. This role drives consistency across the OPU and monitor the level of compliance.


Requirements

  • Computer science/IT degree or adequate professional IT Security skills. Experienced in cyber security, IT audit or IT risk management.
  • Fluent in respective local language and English.
  • Minimum 2 years of experience in IT Security/Risk Management
  • Cyber Security Professional Certification such as as CISSP, CISM, CISA or CSSP
  • Experienced in most areas of information technology including system life cycle development and risk analysis and management.
  • Technical knowledge of, and experience with IT security architecture and systems including best practices for information security (e.g., access control, encryption, endpoint security, intrusion detection, leakage prevention, and threat intelligence).
  • Work experience in regional or global team setup, passionate team player, demonstrates the ability to think out of the box. Consensus building behaviour and capabilities.
  • Ability to communicate information security-related concepts to a broad range of technical and non-technical staff. Strong learning agility.