Global Digital & Technology (D&T) has a worldwide responsibility for all
IT processes, solutions and services. The aim is to further enhance
HEINEKEN Global Functions by delivering common business driven
solutions and services.
The Global Information Security department is part of Global D&T and
has the overall responsibility of assuring that HEINEKEN’s IT Risks are
properly managed, and information assets & technology is properly
secured.
Job purpose :
The Global Information Security teams include Cyber Defense
Operations (CDO), Security Competence Centre (SCC) and Security
Chapters (ERP, Enterprise Architecture, Data Privacy, etc.) to design,
implement, monitor, respond and assist with recovery activities against
cyberattacks. They deliver deep security and risk management
expertise to enable Product Teams and Global Functions to form a
proper 1st Line of Defense (Lod) by building the right capabilities into
their products (security by design) and support them.
The Global Information Security Director is heading the department and
responsible for the Global Information Security Strategy and
orchestrating all security activities within this department and relevant
stakeholders. He is part of the Global D&T Executive Leadership Team.
The Cyber Security Officer (CSO) is responsible for the management
and implementation of the global Cyber Security Strategy based on the
NIST Cyber Security Framework, to reduce the risk of a Cybersecurity
incident according to the risk appetite of HEINEKEN and the Global
Function, as well as to raise wider Global Function Cybersecurity
awareness.
Key responsibilities :
update these based on local threats.
that are required due to local legislative requirements, in consultation with the
Global Information Security Specialist in line with HEINEKEN Security Strategy and
supporting the HEINEKEN Business Strategy.
HeiNet), to maintain the highest level of security for the information and IT assets of
the company.
standards and procedures that have broad implications, requiring systems
integration of one or more technical platforms.
Function programs / services to be deployed in the Global Function operational
environment and veto programs which do not comply with HEINEKEN’s security
standards.
compliance, review and assess information security audits.
Assessment (ISMA) and ensures that all related evidence is available in support of
the assessment.
issues raised by e.g. Global Audit, External Audit, etc.
risks and non-compliances.
related budget.
D&T Function management team and centrally to the Global Information Security
Team.
Functions could have with a new solution or program and communicate to the
Global Information Security Team and Design Authority for approval to protect the
HEINEKEN security environment.
vulnerabilities.
Legal teams in case of breaches of HEINEKEN’s Code of Business Conduct.
responsible for the Global Function security incident which led to resolve in
consultation with the Cyber Defense Operations Team (CDO), Global Function D&T
Directors and Global Function Line Managers.
including the analysis of technical and economic feasibility of proposed security
systems / solutions. He / she is also responsible for assisting the Global Information
Security department with any IT technical audit (e.g. Ethical Hack) to any Global
Function IT infrastructure or service that a 3rd Party offers to HEINEKEN with a valid
and open contract to ensure that security policies are in place.
Vulnerability Management, etc).
security awareness program and based on the reality of Global Function.
and / or avoid that risk within the Global Function.
develop further the controls and processes required to improve information
security.
from global D&T towards the HEINEKEN Global Functions
Function stakeholders in all phases of solutions development (Ideation, Design,
build, test and deploy) and Operations.
Budget responsibilities :
Assigned to Global Function D&T Manager
Qualifications : Bachelor’s or master’s degree in business information technology or a related field Possesses relevant certifications, e.g. CISSP / CCSP / CISM / CISA / CRISC Experience /
skills required :
Requirements
skills required :
Sense of Business Urgency and safe-cautious mind to close critical gaps and reduce any security breach.
Security Security • Cairo, Cairo Governorate, EG