Key Responsibilities
- Implement security risk management processes in a newly acquired entity to establish ongoing security risk oversight.
- Facilitate the integration of Dentsu's global technology and security policies, controls, and ISO 27001 standards within the acquired entity.
- Collaborate with stakeholders to identify, assess, monitor, and respond to security risks, adhering to the technology and security risk management framework.
- Maintain the risk register in the GRC platform, documenting treatment plans, tracking progress, and escalating issues.
- Deliver risk reports to stakeholders and relevant committees, such as the Dentsu International Markets Security Risk Committee.
- Lead working groups for security issue management to assess risks and develop treatment plans with stakeholders.
- Provide analysis on key risk areas to enhance security maturity and inform future investment decisions.
- Monitor the external security landscape and emerging trends to support risk management efforts.
- Promote the adoption and growth of technology and security risk management processes across Dentsu International Markets.
What We're Looking For
- 2-3 years of experience in technology and security governance and risk management in medium to large organizations.
- Broad understanding of all security domains, including people, process, and technology.
- Proven stakeholder engagement skills and strong communication abilities.
- Capability to articulate complex technical concepts to non-technical audiences.
- Self-motivated, proactive, and action-oriented with a focus on meeting deadlines.
- Collaborative approach to achieving shared objectives.
- Enthusiasm for professional development in governance, risk, compliance, or security.
- Experience with enterprise technology security compliance initiatives such as ISO 27001 (mandatory), NIST, CIS, PCI DSS, or Cyber Essentials.
- Familiarity with security, technology, and enterprise risk management frameworks (desirable).
- Experience using industry-leading GRC platforms (desirable).
- Proficiency in Microsoft Excel, PowerPoint, Forms, and Power BI (desirable).
- Possession of or progress towards an information security qualification (e.g., CISSP, CISM, CISA, CRISC) (desirable).