Information Security Manager

Overview

We are looking for an Information Security Manager to help strengthen security across a complex technology landscape and embed a security-first culture across the organisation. In this role, you will work closely with engineering, product, technology, and business teams to identify and manage security risks, ensure effective security controls, and support teams in delivering secure and resilient solutions.

As an experienced security professional with a strong technical background, you will act as a trusted security advisor to stakeholders across the organisation. You will provide expert guidance on security policies, standards, risk management, vulnerability management, incident response, and security assurance. You will also help integrate security into Agile development processes and ensure that security practices are consistently applied across AWS Cloud and on-premises environments.

You will collaborate with Security Architects, engineering teams, and other security specialists to address complex security challenges, improve security maturity, protect critical assets and data, and continuously strengthen the overall security posture.

About Nortal:

We’re Nortal. We think big and create cutting-edge digital solutions with a global reach. And with 25 years of experience, 2,700+ professional experts, and half a billion people worldwide impacted by our work, we believe we’ve got the numbers to back up that statement.

Our global teams have played a significant role in many Fortune 500 companies’ projects and systems and have been the driving force of digital transformation for governments, healthcare institutions, and leading enterprises worldwide. We combine best-in-class strategic consulting with software engineering, data, and design practices to bring our visions to life.

About TUI

TUI is a global business with over 70,000 people on board, a great history and challenging plans for building a digital future. TUI is the largest leisure, travel and tourism company globally, and it owns travel agencies, hotels, airlines, cruise ships and retail shops.

Responsibilities

  • Define and support the delivery of information security initiatives aligned with business priorities and the wider security strategy.
  • Act as a security partner and trusted advisor to technology and business stakeholders across the Domain.
  • Promote a security-first culture and embed secure ways of working across teams.
  • Provide expert guidance on security policies, standards, controls and best practices.
  • Identify, assess and manage information security risks, ensuring pragmatic and cost-effective mitigation.
  • Support the protection of TUI’s critical systems, applications, data and other information assets.
  • Ensure appropriate security assurance, testing and controls are in place across the technology landscape.
  • Work closely with engineering and delivery teams to embed security into Agile and software development processes.
  • Support security operations, including vulnerability management, patching and security monitoring.
  • Coordinate the effective management of security incidents and ensure lessons learned are translated into improvements.
  • Monitor and support remediation of audit findings and security control gaps.
  • Help reduce the organisation’s attack surface and proactively identify emerging security risks.
  • Report on the effectiveness of the security programme using agreed KPIs and drive continuous improvement.
  • Work across both AWS Cloud and on-premises environments, ensuring appropriate security controls are implemented and maintained.
  • Collaborate with security teams and stakeholders across TUI’s international organisation.

Qualifications

  • Proven experience leading or managing an information security capability within a large or complex organisation.
  • Strong technical understanding of information security, with previous experience in a technical security role.
  • Hands-on understanding of security within AWS Cloud environments.
  • Good knowledge of security within Agile software development and delivery processes.
  • Strong understanding of security operations and incident management across Cloud and on-premises environments.
  • Experience implementing or operating an Information Security Management System (ISMS) within a large organisation.
  • Good understanding of information security risk management, governance, controls and assurance.
  • Knowledge of international regulatory requirements, particularly data protection and privacy.
  • Familiarity with recognised security standards and frameworks such as ISO 27001, NIST, PCI DSS, OWASP and ITIL.
  • Strong understanding of vulnerability management, patching and security assurance.
  • Excellent stakeholder management and communication skills, with the ability to influence both technical and non-technical audiences.
  • Strong organisational and planning skills, with the ability to prioritise effectively and drive security initiatives to completion.
  • A pragmatic, commercial approach to security risk and decision-making.
  • Strong problem-solving skills and the ability to develop practical solutions to complex security challenges.
  • Ability to work effectively in an international, cross-functional environment.
  • A collaborative and proactive approach, with a focus on continuous improvement.

Certifications

The following certifications are desirable:

  • AWS Cloud Practitioner or equivalent AWS certification
  • ISO 27001 Lead Implementer
  • CISSP
  • CISM
  • CISA
  • CompTIA Security+
  • CISMP

*Following the applicable legal regulations, particularly Directive (EU) 2019/1937 of the European Parliament and of the Council on the protection of persons reporting breaches of Union law and its implementation into Polish law under the Act of December 4, 2021, on the Protection of Persons Reporting Breaches of Law (Journal of Laws 2021, item 2105), including Articles 4-6 governing whistleblower protection and reporting procedures, the company has implemented a Whistleblower Support Policy, ensuring anonymity, protection, and support for individuals reporting irregularities.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available