- Company Name
- Revlon
- Job Title
- Senior Manager Information Security
- Job Description
-
**Job title:** Senior Manager Information Security
**Role Summary:** Lead global security initiatives across IT, OT, and Digital environments to safeguard enterprise assets, ensure regulatory compliance, and embed security into all technology and business processes.
**Expactations:**
- Deliver a comprehensive security strategy and roadmap in line with organizational goals.
- Drive risk assessment, mitigation, and monitoring across all systems, applications, data, and third‑party relationships.
- Ensure continuous compliance with ISO 27001, IEC 62443, NIST CSF, and relevant local regulations.
- Embed security controls in network architecture, cloud deployments, and emerging technologies such as AI.
- Lead security awareness and training programs to elevate organizational security culture.
- Manage incident response and regional incident handling capabilities.
- Report security posture, risk exposure, and compliance status to senior leadership.
**Key Responsibilities:**
- Define, implement, and maintain IT/OT security policies, standards, and procedures.
- Coordinate vulnerability management, penetration testing, secure configuration, and patching.
- Oversee network segmentation, access control, and monitoring for IT and OT environments.
- Lead enterprise business continuity and disaster recovery planning and exercises.
- Collaborate with engineering, operations, and product teams to integrate security requirements into projects and platforms.
- Support secure AI and emerging technology adoption within governance frameworks.
- Provide regular risk, compliance, and incident reporting to CISO and executive leadership.
- Direct regional security incident management and post‑incident analysis.
**Required Skills:**
- Strategic security planning and execution in a global, fast‑paced setting.
- Deep knowledge of OT/ICS environments and associated risk controls.
- Proficiency in vulnerability assessment, penetration testing, and secure configuration.
- Experience with network and infrastructure security, cloud security (Azure, AWS), and identity & access management.
- Familiarity with AI security considerations and governance.
- Strong stakeholder influence, cross‑functional collaboration, and team leadership.
- Understanding of ISO 27001, IEC 62443, NIST CSF, risk management methodologies, and TOGAF/SABSA principles (plus).
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 10+ years of cybersecurity experience, including ≥5 years in management roles.
- Industry certifications: CISSP, CISM, ISO 27001 Lead Implementer, or comparable (e.g., CCSP, SCADA/ICS).