Job Seeker Reactivate Your Account
Thank you, this account has been Deactivated.
Do you want to Reactivate your account?
No
Yes

Cyber Security Officer

HEINEKEN Myanmar Limited
Pabedan | Yangon
Verified This job has been verified by the company as a real job vacancy.
20 Jan 2023
Recruiter active 1 day ago The recruiter at this company was last active reviewing applications.
Sorry, Unable to Apply
x
55%
Please Upload CV Attachment, or update your JobNet Profile to at least 55% of completion.
Upload CV
Update Profile

Cyber Security Officer

HEINEKEN Myanmar Limited
Recruiter active 1 day ago The recruiter at this company was last active reviewing applications.
Myanmar - Yangon
Verified This job has been verified by the company as a real job vacancy.

Experience level

Experienced Non-Manager

Job Function

IT Hardware, Software

Job Industry

FMCG

Min Education Level

Bachelor Degree

Job Type

Full Time

Job Description

A Great Opportunity for ...

Job purpose:

  • Global Digital and Technology (D&T) has a worldwide responsibility for all IT processes, solutions and services. The aim is to further enhance HEINEKEN Global Functions by delivering common business driven solutions and services
  • The Global D&T Information Security Department is part of Global D&T and has the overall responsibility of assuring that HEINEKEN’s IT Risks are properly managed and information assets and IT is properly secured
  • The Global D&T Information Security Department delivers deep security and risk management expertise to enable the Product Teams, Global Functions and OpCos to form a proper 1st Line of Defense (LoD) by building the right capabilities into them (security by design) and supporting them when needed
  • The scope of the Global D&T Information Security Department, which includes the Cyber Defence & Operations (CDO), Security Competence Centre (SCC) and Security Chapters is to design, implement, monitor, respond and assist with recovery activities against cyberattacks
  • The Global Information Security Director is responsible for formulating the Information Security Strategy and orchestrating all the security activities within the Global D&T Information Security Department and relevant stakeholders. He is part of the D&T Leadership Team
  • The Cyber Security Officer (CSO) is responsible for the management and implementation of the global Cyber Security Strategy based on the NIST Cyber Security Framework, to reduce the risk of a Cybersecurity incident according to the risk appetite of HEINEKEN and the OpCo, as well as to raise wider OpCo Cybersecurity awareness

Key Responsibilities:
Security Operations
Implement global security strategies to maintain the continuity of systems and update these based on local threats

  • Responsible to manage updates related to OpCo Security Standards that are required due to local legislative requirements, in consultation with the relevant Regional Security & Risk Lead (S&RL) in line with HEINEKEN Security Strategy and supporting the HEINEKEN Business Strategy
  • Responsible for local security approvals regarding global services (e.g. HeiNet), in order to maintain the highest level of security for the information and IT assets of the company
  • Assist the global operational security team in the design of controls/ standards and procedures that have broad implications, requiring systems integration of one or more technical platforms
  • Perform Risk reviews using the risk management procedure for all new local programs/services to be deployed in the OpCo operational environment and veto programs which do not comply with HEINEKEN’s security standards

Monitor internal and external information security and cyber security policy compliance, review and assess information security audits

  • Performs, as per the prescribed frequency the Information Security Maturity Assessment (ISMA), and ensures that all related evidence is available in support of the assessment
  • Monitor and ensure the timely closure of tasks related to audit and internal control issues raised by e.g. Global Audit, Regional S&RLs, etc

Develops and manages the Information Security action plan to address identified risks and non-compliances

  • Gains approval from the relevant management team on that action plan and its related budget
  • Monitors and reports on the execution of that actions plan, reporting locally to the local management team and centrally to the Regional S&RL Team
  • Analyse and challenge derogation requests regarding the ISS/ISP that OpCos could have with a new solution or program, and communicate same to the global security operations and risk management teams for approval in order to protect the HEINEKEN security environment

Drive resolution of cyber security incident responses and address security vulnerabilities

  • Perform/guide/drive digital investigations upon the request of Local OpCo/HR or Legal teams in case of breaches of HEINEKEN’s Code of Business Conduct
  • If the OpCo faces any critical IT security incidents or breakout, he/she is responsible as the local security incident lead to resolve with the OpCo D&T Managers in consultation with the Cyber Defense Operations Team (CDO), IT Regional Directors and Service Line Managers
  • Identify and perform independent analysis to resolve complex first-time issues including the analysis of technical and economic feasibility of proposed security systems/
  • solutions. He/she is also responsible to assist the global security operations team for any IT technical audit (e.g., Ethical Hack) to any OpCo IT infrastructure or service that a 3rd Party offers to HEINEKEN with a valid and open contract to ensure that security policies are in place
  • Advises OpCo operations teams for security requirements (e.g., Patching, Anti-Virus, Vulnerability Management, etc)

Security Awareness

  • Drive training campaigns on cyber security awareness according to the global security awareness program and based on the local OpCo reality. Manage and train cyber security staff

Security Strategy

  • Responsible for identifying potential risks and recommendations on how to prevent and/or avoid that risk for inclusion in global operational security strategy
  • Collaborate with the regional S&RL to understand and develop further the controls and processes required to improve information security

Innovation

  • o Accelerates and Drives implementation of new Security strategies and standards from global D&T towards the HEINEKEN OpCos
  • o Research / participate in peer security forums (3rd parties and peers Companies) to identify opportunities to benchmark and continuously improve local implementation of standards and best practices from across IT or from the marketplace
  • o Provide security expertise across multiple technical platforms to various OpCo stakeholders in all phases of solutions development (Ideation, Design, build, test and deploy) and Operations

Operational Technology – Process Control Domain

  • Security Incident Management coordination
  • Control Self-Assessment coordination
  • Assist with the review and closure of Information Security Issues
  • Review execution of PCD security deliverables (patch compliance, AV, backups, etc.)
  • Support OpCo communications and roll out of security standards, procedures, etc
  • Engage and collaborate on best practices with other ISOs and PCD Security Leads with an emphasis on standardization and simplification

Open To

Male/Female

Job Requirements

  • Bachelor or Master degree in business information technology or a related field
  • Possesses relevant certifications, e.g. CISSP / CCSP / CISM / CISA / CRISC
  • 5+ years of working in the cyber security field and previous experience working as a cyber-security officer or manager.
  • Has worked with relevant market standards such as NIST, ISO 27001, COBIT and relevant laws and regulations such as privacy laws
  • Experience in handling security incidents
  • Proven ability to dynamically assess risks, threats & threat actors
  • Able to work in a cross functional environment; preferably a background in the FMCG industry
  • Sense of Business Urgency and safe-cautious mind to close critical gaps and reduce any security breach
  • Ability to explain complex technical processes to business stakeholders
  • Flexibility to adjust to multiple demands, shifting priorities, ambiguity, and rapid change
  • Ability to work and team with a multitude of different people and different cultures (as appropriate)
  • Display professionalism, customer service attitude, attention to detail and quality
  • Possess strong interpersonal skills, relationship management and negotiation skills, strong verbal, and written communication skills
  • Develop self and others through continuous learning, sharing best practices, knowledge, and expertise
  • Excellent management and leadership skills

What We Can Offer

Benefits

* Health Insurance
* Group Life Insurance
* Phone Bill Allowance
* Transportation Allowance
* Flexible working hours
* Annual Bonus

Highlights

* Fun working environment
* International standard working environment & culture
* Sat/Sun Off
* Brew a better world

Career Opportunities

* Personal Development Plan
* Develop Leadership Skills with high professional mentors, managers, and coaches
* Ongoing Training & Development Plan