Global Head of Information Security
The Global Head of Information Security ( IS ) is responsible for establishing and maintaining the enterprise-wide information security strategy, governance, and risk posture across the organisation's global operations. With 2,000 users spread across 14 countries, the Head of IS faces the complexity of diverse regulatory environments, cross-border data flows, and a broad threat landscape. This role requires a security-first leader who can translate technical risk into business impact and drive a culture of cybersecurity awareness at every level of the organization.
Key Objectives
Information Security Strategy & Governance
- Develop information security strategy, roadmap, and governance framework aligned to business objectives.
- Establish an Information Security Steering Committee with representation from all major business units.
- Define enterprise security policies, standards, and procedures applicable across operating countries.
- Lead annual security risk assessments and present findings with recommended remediation to the management team.
Cybersecurity Risk Management
- Identify, assess, and prioritize information security risks across the enterprise technology landscape.
- Implement & maintain an enterprise Risk Management Framework (ISO 27001, NIST or equivalent).
- Manage the organization's cyber risk register and ensure risk owners have appropriate mitigation plans.
- Oversee third-party and supply chain security risk assessments for critical vendors and partners.
Regulatory Compliance & Data Privacy
- Ensure compliance with applicable data protection regulations across organisation e.g. EU-GDPR, applicable local data security / privacy compliance
- Liaise with Legal and Compliance teams on regulatory changes, audit requirements, and cross-border data transfer mechanisms.
- Manage relationships with regulators, data protection authorities, and external auditors.
- Oversee data classification frameworks and ensure appropriate controls.
Security Operations & Incident Response
- Establish Security Operations Center (SOC) capabilities
- Maintain a comprehensive Incident Response Plan (IRP) and test it through regular tabletop and simulation exercises.
- Lead the organization's response to significant security incidents, breaches, and cyberattacks.
- Implement threat intelligence capabilities to proactively identify and mitigate emerging threats.
Security Architecture & Technology
- Define and govern enterprise security architecture principles, standards, and reference architectures.
- Oversee selection and deployment of security technologies (SIEM, EDR, IAM, DLP, CASB, Zero Trust architecture).
- Ensure security is embedded into software development lifecycles (DevSecOps) and cloud deployments.
- Champion Identity and Access Management (IAM) and Privileged Access Management (PAM) programs globally.
Security Culture & Awareness
- Design and deliver a global security awareness and training program tailored to employees across cultural contexts.
- Build a security-consHead of ITus culture by engaging employees at all levels from executives to frontline staff.
- Conduct regular phishing simulations and awareness campaigns with measurable improvement targets.
QUALIFICATIONS & EXPERIENCE
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related discipline (required).
- Master's degree in Cybersecurity, Information Assurance, or MBA with security focus strongly preferred.
- 12+ years of information security experience, with 5+ years in a senior security leadership role (GLOBAL HEAD OF INFORMATION SECURITY, VP, Director of Security).
- Demonstrated experience managing security programs in multinational organizations with complex regulatory environments.
- Certifications: CISSP, CISM, CRISC, CCSP, or equivalent (CISSP or CISM strongly preferred).
- Experience managing or overseeing a SOC and responding to major security incidents is essential.
Travel and other conditions
- Possible international travel expected (25-35%) for regional security reviews, audits, and regulatory engagements.
- On-call availability mandatory for security incidents, data breaches, and crisis response situations.
- Operates within a high-stakes, time-sensitive environment with significant personal accountability.
About Modaxo
Modaxo brings together businesses focused on providing the technologies that move the world’s people each and every day. Working both together and independently, our businesses are focused on one thing - delivering software and technology solutions that help connect people with the places they need to go for work, family, and everyday life. No other organization brings together so many different businesses, competencies, and experiences under one global banner to focus exclusively on People Transportation. With people who are truly passionate about what they do, Modaxo understands the impact mobility has on the fabric of daily life. We thrive on delivering dependable solutions that meet the real-life needs of our customers in the communities where we live and serve.
#J-18808-Ljbffr