About the job
Testronic is seeking a seasoned Director of Information Security to spearhead and enhance our comprehensive global security strategy, governance, and compliance initiatives.
As a key player in the entertainment industry, Testronic collaborates with prestigious companies handling highly sensitive pre-release gaming and media content. Safeguarding this data and sustaining the confidence of our clients is of utmost importance. In this pivotal role, you will ensure that our security protocols, policies, and operational processes are not only robust and effective but also in sync with regulatory standards and client expectations.
This position encompasses strategic security planning, governance, and operational management. You will be responsible for overseeing the organization’s information security program, managing ISO 27001 certification and security audits, and partnering closely with IT, business units, and clients to integrate security throughout all operations.
Key Responsibilities:
- Formulate and refine the company’s information security strategy and roadmap, consistently enhancing our security posture while aligning with business and client requirements.
- Lead the ISO 27001 certification program, managing internal and external audits and compliance efforts.
- Ensure adherence to internal policies, GDPR, and client-specific security obligations in all operational locations.
- Act as the steward of security policies and standards, ensuring they align with ISO 27001 and adapt to changing business needs.
- Oversee incident and vulnerability management, as well as SIEM monitoring, ensuring effective processes and controls are established.
- Coordinate penetration testing, vulnerability remediation, and internal security evaluations in collaboration with IT teams.
- Manage risk management processes, including maintaining risk registers and reporting to senior leadership.
- Assist with client security audits and assessments, providing transparency and assurance regarding our security measures.
- Serve as a security consultant for internal projects, ensuring security requirements are integrated into IT and business initiatives.
- Promote security awareness across the organization, aiding stakeholders in understanding and adhering to security protocols.
- Maintain documentation and evidence required for compliance, audits, and reporting.
- Establish and monitor security KPIs and KRIs to assess the effectiveness of the security program.
