This role runs JTLs information security management system end to end: the ISO/IEC 27001:2022 ISMS, the internal audit programme, the policy and standard framework, the cyber risk register, and security awareness across the company. The goal is to demonstrate, that JTL successfully has established processes to continuously improve its security capabilities.
This is a hands-on role in the security team without management responsibility.
ISMS ownership
- Run and maintain the ISO/IEC 27001:2022 management system: scope, Statement of Applicability, control ownership, management review
- Prepare for and defend certification, surveillance and recertification audits
- Keep the evidence base current and collectible, and make it repeatable rather than a scramble before each audit
Internal audit
- Plan and run the internal audit programme against the control set
- Write findings that are specific enough to act on, and drive them to closure with the control owners
- Provide factual assurance to the management team
Policy and standards
- Own the policy and standard framework: authorship, review cycle, approval, publication, versioning
Risk management
- Run the cyber risk register: assessment, treatment plans, acceptance decisions, review cadence
External assurance
- Act as the single point of contact for customer security assessments, questionnaires and due diligence
- Run the response cycle for our investor's portfolio-wide cyber assessment
- Manage third-party and vendor security assessments, and the security half of the vendor onboarding process
Awareness and training
- Design and run the security awareness programme, including role-based training
- Measure whether it changed anything, and change it when it did not
