- Company Name
- Hyundai AutoEver America
- Job Title
- 10393 - Security Strategy and Risk Management HOD
- Job Description
-
**Job title**
Security Strategy and Risk Management Head of Department
**Role Summary**
Lead organization‑wide security strategy, integrated risk management, and governance. Own end‑to‑end risk assessment, compliance, third‑party risk, policy, training, budgeting, and workforce planning to align information security with business goals and regulatory requirements.
**Expectations**
- Deliver enterprise‑wide risk governance and compliance in alignment with NIST, ISO, SOC 2, PCI‑DSS, and other frameworks.
- Drive effective risk, compliance, and vendor risk programs and report insights to senior leadership.
- Translate security strategy into actionable plans, budgets, and measurable outcomes.
- Build and mentor a cross‑functional team covering risk, strategy, and planning.
**Key Responsibilities**
- Lead risk assessment, issue management, and exception handling for information security and operational risks.
- Maintain and evolve risk frameworks; produce data‑driven risk reports for leadership and governance bodies.
- Oversee compliance and audit programs; coordinate internal/external audits and certifications (ISO 27001, SOC 2, NIST, PCI‑DSS).
- Direct third‑party risk management: due diligence, monitoring, remediation, and alignment with procurement/legal.
- Govern creation and maintenance of security policies, standards, procedures; manage policy exceptions.
- Head security awareness and training; develop metrics and campaigns to gauge effectiveness.
- Partner with the CISO to develop the security roadmap; execute annual/multi‑year planning and capability improvements.
- Manage budgeting, forecasting, tracking, and cost optimization for the security organization.
- Plan resource allocation and workforce strategy, collaborating with HR and talent teams.
- Create dashboards for KPIs, KRIs, OKRs, and SLA performance; provide executive‑level reporting.
**Required Skills**
- Deep knowledge of risk management, GRC, and security frameworks (NIST, ISO 27001, SOC 2, PCI‑DSS).
- Audit and compliance program design, execution, and certification processes.
- Vendor/third‑party risk management.
- Policy development, governance, and exception handling.
- Security awareness program design and metrics.
- Strategic planning, program delivery, and performance measurement.
- Financial acumen: budgeting, forecasting, and cost optimization.
- Workforce and resource planning.
- Leadership, mentoring, and stakeholder engagement.
- Data analysis and reporting.
**Required Education & Certifications**
- Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Business Administration or related field (Master’s preferred).
- Relevant certifications: CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer (or equivalent).
- Minimum 10+ years of progressively responsible experience in security risk management, governance, compliance, or related roles.